SaVi Privacy Policy
SaVi is a fitness, training, and hiking-preparation app in public beta. This policy explains what SaVi collects, why it is used, where it goes, and the choices available to you.
Effective and last updated: July 15, 2026
Data SaVi handles
Account and profile
SaVi processes your email address, authentication user ID, display name, handle, profile preferences, and optional profile photo. Optional profile and training facts can include date of birth, sex, height, experience level, and available equipment. Apple or Google may provide identity information you choose to share when you use their sign-in services. SaVi does not receive your Apple or Google password.
When you choose Google Sign-In, Google's SDK may process a phone number, account and device identifiers, general location inferred from an IP address, and other account or usage data for authentication, fraud prevention, and service analytics.
If you use social features, SaVi stores your in-app connections, friendships, invitations, and profile-sharing choices. SaVi does not read or upload your phone's address book.
Health, fitness, and training
SaVi stores information you enter or create, such as workouts, exercises, sets, repetitions, weights, cardio sessions, readiness answers, sleep and soreness notes, nutrition and water logs, goals, body weight, body fat, measurements, progress check-ins, and related notes.
If you authorize Apple Health, SaVi reads only the categories you approve, which can include steps, workouts, heart rate, active energy, sleep, and Activity rings. Authorized summaries and workout records may be saved in SaVi and synchronized to your account. If you separately authorize write access, SaVi can write completed workouts, body measurements, and logged nutrition (dietary energy, protein, carbohydrates, and fat) back to Apple Health.
Food-search terms are sent to Open Food Facts and, through SaVi's authenticated backend, USDA FoodData Central. SaVi caches a normalized search term and its USDA result for about seven days so repeated searches do not consume the shared service quota. An hourly cleanup removes entries after the seven-day cache window.
Precise location
When you start a walk, run, ruck, or hike and grant foreground permission, SaVi uses GPS fixes in memory to calculate live distance and elevation. If you also turn on Record Route, SaVi saves the route's precise GPS points on your device and can synchronize them to your account. SaVi does not request always-on location or use location for advertising or unrelated background tracking.
Photos and other content
SaVi can store profile photos, progress and check-in photos, feedback screenshots, workout comments and reactions, direct and group messages, journal and daily notes, custom exercise or equipment notes, and other content you provide. People you intentionally connect or share with can see content made available to them in-app.
Meal and gym-machine photos selected for AI analysis are sent through SaVi's backend to an AI service for processing. SaVi does not intentionally retain those scan images after the request unless you separately save the image using another SaVi feature. The AI provider processes the request under its own data handling terms. Under Anthropic's standard API terms, inputs and outputs are normally deleted from its backend within 30 days, with exceptions for legal, security, or usage-policy enforcement and any separately agreed retention terms.
The optional AI coach receives the messages you send and the training or health summary needed to answer. Conversation history is kept on your device. Proposed coach actions are not executed on the server; the app validates them and asks you to confirm before changing data.
Support, diagnostics, and notifications
If you send feedback or a bug report, SaVi stores the description, category, optional screenshots, and—when diagnostics remain enabled—app version, device model, operating-system version, locale, current app screen, recent redacted log entries, and recent errors. When you open a report from Coach, SaVi also attaches up to the last eight Coach messages (capped at 4,000 characters) so the developer can understand that exchange; this Coach context is included even if optional diagnostics are off. Reports are linked to your account so the developer can investigate.
If you report a user, message, workout comment, workout post, or workout photo, SaVi stores the selected safety reason, the reported account and content reference, a short copy of relevant text when applicable, and limited screen context so the report can be reviewed. Blocking is private: the blocked account is not told who blocked it. Moderation and abuse-prevention records may be kept long enough to investigate, enforce the terms, prevent repeat abuse, and retain a limited audit trail, including after an account identifier is removed.
SaVi uses Sentry for crash, app-session, and performance diagnostics. The SDK assigns a pseudonymous installation identifier to those records. SaVi may attach pseudonymous account, profile, or record identifiers needed to associate a failure with app state. SaVi does not intentionally send your email or username to Sentry, and it redacts common email and credential patterns before events leave the app. As with ordinary internet requests, Sentry may still receive network information such as an IP address.
If you enable push notifications, SaVi stores an app-specific Apple Push Notification service (APNs) device token, details needed for delivery, notification preferences, and time-zone information. SaVi's backend sends notifications directly through APNs. These records are used only to deliver SaVi notifications and manage their timing.
Where data is processed
SaVi is local-first: much of your data is stored in an on-device SQLite database or other protected app storage. When you sign in and synchronization is enabled, account data is backed up to Supabase-hosted authentication, database, storage, and Edge Function services.
SaVi uses these providers only to operate the app:
- Supabase for authentication, sync, file storage, and server functions;
- Expo Application Services for signed application updates and release delivery;
- Apple and Google for sign-in when selected;
- Apple HealthKit for health data you authorize;
- Apple Push Notification service (APNs) for push delivery;
- Sentry for crash and performance diagnostics;
- Anthropic for optional AI coach and photo-analysis features;
- Open Food Facts and USDA FoodData Central for food search;
- Apple MapKit to render saved routes on iOS (and Google Maps if an Android build is offered). The map provider receives the viewed map area needed to render map imagery; and
- Resend to deliver developer notification emails about support reports.
Providers may process data in locations described in their own terms and privacy notices. SaVi does not give them data for advertising or cross-app tracking.
How data is used and disclosed
SaVi uses data to provide requested features, personalize training and coaching, keep devices synchronized, protect accounts, deliver notifications, diagnose failures, answer support requests, and improve reliability. Data may be disclosed:
- to the processors above, only as needed to provide their service;
- to people with whom you intentionally message, connect, or share;
- to the SaVi developer when investigating a report or operating the service; or
- when required by law, to protect users, or to secure the service.
SaVi does not sell personal data, serve third-party advertising, or use data for tracking across other companies' apps or websites.
Retention, security, and deletion
SaVi keeps account data while your account is active and as needed to provide the service. Support and security records may be retained long enough to resolve an issue, prevent abuse, and maintain an audit trail. SaVi uses access controls, encrypted transport, row-level database policies, and platform security controls, but no system can be guaranteed perfectly secure.
You can permanently delete your account from Settings → Account → Delete account. The deletion flow removes the live authentication account, account-owned synced records and stored files, and this device's SaVi account data. Limited copies can remain temporarily in provider backups or security logs until those systems age them out. Content another person has independently exported or copied cannot be recalled.
The in-app CSV export covers device-resident training data such as sessions, baselines, and readiness information. It is not currently a complete export of server-only content such as messages, support reports, or stored media.
You can change Apple Health, location, camera, photo-library, and notification permissions in iOS Settings. Turning off a permission stops new access but does not automatically delete information you previously saved.
Children
SaVi is not directed to children under 13, and the developer does not knowingly collect personal data from a child under 13. Contact the developer if you believe a child provided data so it can be reviewed and removed.
Changes and contact
This policy may change as SaVi changes. The effective date above will be updated, and material changes will be communicated through the app, beta program, or App Store listing as appropriate.
For a privacy request, use Report a bug or idea inside SaVi and identify it as a privacy request, or email menyhay13@gmail.com. If you cannot access the app, you can also reply to a SaVi TestFlight invitation or support message. See the support page for account and permission steps.