Draft — not yet effective.

This revision is being prepared for launch. Unconfirmed details remain marked; it does not establish new processing permissions or change an existing agreement.

Savia Privacy Policy

Revision: 29 September 2026 · Effective date: [Effective date]

[Legal entity name], doing business as Stack64, operates Savia and this website. This policy explains the information we collect, why we use it, who receives it, and your choices. Contact support@stack64.com or write to [Business mailing address]. Read our separate Consumer Health Data Privacy Policy for health-data categories, disclosures, and state-law rights.

This draft describes the planned release. Features may differ by version and availability. A description does not enable a feature or authorize processing; the effective notice, consent, and feature permissions must accompany the release before the processing begins.

1. Main commitments

We use your information to provide the requested or enabled Savia features, maintain accounts and security, handle requests, and meet legal duties. We do not sell personal information, use health information for targeted advertising, or use ordinary production health content to train models or as benchmark inputs. A future optional improvement or research program requires a separate notice and affirmative authorization before participation; accepting this policy is not participation.

Savia provides wellness information and support, not clinical care or emergency monitoring. Health information you put in a consumer app is not necessarily protected by HIPAA merely because it is about health. Applicable consumer-health and other privacy laws may protect it. Our description of intended use is not a determination of medical-device status.

2. Information, sources, and purposes

3. How features process information

Gemini receives the messages and relevant context used for a requested or enabled task, which can include records, photos, profile facts, saved findings, and app logs. Background research may choose a question about a goal only under its permission and topic controls. An analysis program may process task information in an isolated AWS environment with internet access disabled for that program. Saved research records are distinct from temporary execution state.

For research photos, Savia removes supported embedded metadata such as location before transmission. Visible names, faces, labels, or other details in the image may remain. Camera permission for a generated app does not itself authorize use of its photos in research. Possible-condition reports follow their separate switch.

Search services receive queries derived from the question and relevant context, potentially including what was learned from a photo. Savia instructs its AI to use general terms and omit identifying details and copied private text, and does not attach private photos, messages, or records to search requests. Generated queries can nevertheless contain unintended personal details, and their topics can reveal health interests. This risk disclosure is not permission to disclose information outside the applicable consent and safeguards. Research lookups can be disabled in Settings.

Push text may include your first name but excludes health details. Delivery services receive that text and a device delivery identifier. A lock-screen notification may reveal that you use Savia. Notification delivery is not guaranteed. Urgent notices have separate controls and may bypass Savia's ordinary quiet hours and daily limit.

4. Providers and other recipients

Providers receive the information needed for the relevant function. Processor use is subject to applicable instructions and contractual safeguards. A provider may also act independently for specified service-security, account, legal, or operational data under its own terms; we do not claim every provider activity occurs solely on our behalf.

Provider or recipient Function and information
Google Gemini, paid service AI replies, extraction, research, and personalization using the task context described above. Under the paid-service terms we use, prompts and responses are not used to train Google's models. Safety, abuse-prevention, temporary caching, and legally required retention may still occur.
Supabase Account-linked database records, files, research records, permissions, and job state for storage and service operation.
Clerk; Apple or Google sign-in when selected Email, identity/session and security information for authentication. Connecting an identity provider does not grant access to all its other data.
LangChain / LangGraph / LangSmith Agent execution state where hosted on these services and technical run-performance metadata. Performance traces are configured to exclude messages and health content; temporary execution context is separate.
Amazon Web Services Task data for background processing and isolated research-program execution. Application logs are designed to contain codes and counts rather than health content.
Tavily and National Library of Medicine / PubMed Web and literature search queries and associated technical request information. Query-generation limits and risks are explained above.
Open-Meteo Rounded area and town-search text for place lookup and environmental conditions. This feature supplies environmental conditions to Gemini rather than the saved place or coordinates; location you separately enter in a message or upload is not removed by that rule.
Expo and the applicable Apple or Google push service Notification content and delivery tokens for push delivery.
Deepgram Recordings for optional dictation. Savia opts those requests out of Deepgram's model-improvement program.
AgentMail, recipient email services, and recipients you authorize Addresses, the content you authorize, delivery metadata, and any disclosed continuing sharing access. Recipients may retain or forward delivered copies.
Sentry and PostHog Optional crash and usage diagnostics when you enable Share diagnostics; configured to exclude health content, messages, documents, and typed text and use a pseudonymous identifier. Diagnostics start off.
Cloudflare Website delivery and security, including request and network metadata. The static legal site has no app health-record store or advertising scripts.
Authorized support personnel and support-mail provider Your request and necessary account/technical details to investigate and respond. [Confirm support-mail provider and its retention.]

We may disclose the minimum information required by a valid legal obligation, or permitted by an applicable legal exception to address a serious safety or security issue. This does not create a routine monitoring or emergency-response service. A lawful business transfer may involve relevant records subject to continuing privacy obligations. For consumer health data, consent and the specific statutory rules still apply; a broad business, safety, or legal-purpose label does not itself authorize disclosure. We do not provide health data to employers, insurers, or clinicians for their own use unless you direct it or a specific legal obligation requires it.

[Before publication: verify active vendors, processor contracts and independent roles, support vendor, hosting configuration, and any affiliate recipients. Identify actual affiliates in the consumer-health notice; do not treat this list as completed diligence.]

5. Your choices and corrections

You can manage source connections, optional diagnostics, research lookups, background work, photos, condition reports, automatic actions, adaptation, memory, area sharing, camera permissions, and notifications through the controls available for your version. Savia's panel is accessible from Settings. Turning off one feature does not silently turn off a separately controlled feature; review the setting's scope.

Conversation-memory notes exclude health conditions, medication, reproductive or mental health, religion, and another person's health. This exclusion applies to that memory feature, not information you separately provide in messages, uploads, About me, logs, or reports. You can inspect, correct, or remove notes, profile facts, and saved findings using their controls, and reset adaptation. Removing a finding or note does not automatically erase its source or earlier reports. Request deletion if you want those removed too.

Corrections may be recorded as revisions so their source and history remain understandable. Revoking evidence stops future reliance through the relevant controls; it is not the same as deleting every copy. Turning area sharing off removes the saved area and stops new area-based requests, but does not erase past conversation references or immediately purge provider logs.

6. Access, withdrawal, deletion, and appeals

Use the in-app export and deletion controls or contact support@stack64.com with "Privacy request" and the action you want. You may request access, correction, deletion of health data without closing your account, withdrawal of applicable collection or sharing consent, or information about recipients. Do not put health records, identity documents, or passwords in the initial email. We authenticate requests with information reasonably necessary, using an existing account where appropriate; you do not have to create a new account.

A self-service export may omit originals above its 40 MB limit. That limit does not restrict statutory access rights: contact us for omitted material or another required access format. Export links expire after seven days; protect the files and links you receive.

Withdraw through the app's consent control or contact us. Withdrawal stops new collection, analysis, and provider requests dependent on that consent, including queued work that has not started. It cannot recall requests already sent. History remains subject to deletion and retention rules. Features that require a withdrawn permission may stop functioning; we do not unlawfully discriminate against you for exercising rights.

For account deletion, use Settings › Delete account. The app provides a seven-day cancellation period during which account work is paused. After that period, deletion begins; seven days is not a promise that every copy has been erased. Applicable legal deadlines take priority over this grace period. Deletion covers applicable original and derived records and is propagated to providers as required. Independent recipients of copies you previously shared may have their own lawful obligations; we still send deletion notices where law requires.

Request decisions include reasons for any refusal and appeal instructions. Reply to support@stack64.com with "Privacy appeal" and the request reference. We review appeals without requiring a new account. The Consumer Health Data Privacy Policy gives Washington and Nevada procedures and deadlines. Other applicable laws may supply additional rights, including authorized-agent requests, portability, restrictions, or complaints. We apply the law that protects your request; this policy does not waive it.

7. Retention

We retain information only as reasonably necessary for its disclosed purpose and lawful obligations, taking account of sensitivity, feature use, deletion requests, security needs, and applicable deadlines. Keeping an account open is not a reason for indefinite retention. We restrict any legally retained exception to its specific purpose, retain the minimum necessary, and delete it when the basis ends.

Record Retention approach
Health evidence, messages, files, goals, findings, and research records While needed for the requested longitudinal service, subject to your controls and the applicable retention/deletion schedule. A research record can outlast a single execution. [Set actual category review periods, inactivity rules, and active-system deletion completion times.]
Temporary agent execution state Deleted after the run and no later than 24 hours. This is not the retention period for saved research records, conversations, or provider safety logs. Verify the configured execution stores before launch.
Savia's dictation recording copy Deleted after transcription, at most 15 minutes to allow a retry. Transcribed text follows the record in which it is saved; provider copies follow the verified provider schedule.
Prepared export archive Available for seven days, then deleted from the export store. Downloads already taken are not recalled.
Consent, sharing, and rights-request evidence Only the minimal version, choice, timestamp, and request/response evidence necessary to demonstrate permissions and comply with law. [Set justified retention periods; do not retain underlying health content merely as legal evidence.]
Support, diagnostics, website/security logs, backups, and provider copies [Publish actual provider-specific periods and backup expiry/deletion process. Include Google, Deepgram, search, email, hosting, and diagnostic retention; verify enforcement.]

Deletion requests include covered derived information and provider copies, not only the visible account row. Backups are access-restricted and used for recovery, with deletion reapplied if restored, subject to applicable law. Statutory backup exceptions are limits on delay, not our routine retention schedule. The consumer-health notice states the applicable Washington and Nevada limits; shorter applicable requirements prevail.

8. Security and incident handling

We use authentication, access controls, encrypted transport, restricted storage access, and logging controls designed to protect information. Authorized personnel receive access appropriate to their function, including necessary support and incident investigation. No system can guarantee absolute security. Keep download and sharing links private; possession of a valid link may permit access within its scope until expiry or revocation.

If an incident triggers a legal notification duty, we will provide the notices required by applicable law. Consumer-health breach notification rules may apply even where HIPAA does not. This is not a guarantee that every incident is immediately detected or that every report is a legally notifiable breach.

9. Processing locations and availability

Information may be processed in the United States and other countries where our providers and their authorized subcontractors operate. We do not promise exclusive U.S. residency. For example, paid Gemini terms permit certain processing or temporary storage across Google's operating locations. International processing must use safeguards required by applicable law.

[Confirm actual storage regions, provider processing locations and transfer safeguards before publication.]

The initial launch is intended for adults in the United States. Before offering Savia in a particular Latin American country, we will provide the local notices, language, permissions, rights mechanisms, and transfer safeguards it requires. No UK launch is announced here.

10. Adults only

Savia is intended for people 18 and older. We do not knowingly collect information from children through an account intended for them. If you believe a child has provided information contrary to this policy, contact support@stack64.com so we can investigate and take appropriate steps.

11. Changes to this policy

This policy and our services can change. We will publish the revised version and effective date and give clear notice of material changes through the app, account email, or another appropriate channel before the change applies, as required by law. Previous effective versions are available on request. New categories, purposes, recipients, or materially different uses of previously collected information require additional notice and affirmative consent where applicable before processing begins. Continued use of Savia or a general right to change the service does not substitute for required consent or retroactively remove your rights.

Our Consumer Health Data Privacy Policy is a separate notice with health-data categories, recipients, and rights.

12. Contact

Privacy requests and questions: support@stack64.com. Operator: [Legal entity name], doing business as Stack64, [Business mailing address]. Health-data rights are explained in our separate Consumer Health Data Privacy Policy.