Privacy & Data
Clear data boundaries. What SavirOS accesses, what it does not, how AI processes your data, and how to export or delete everything.
What SavirOS Accesses
| Data Source | What We Read | What We Store |
|---|---|---|
| Google Calendar | Event titles, times, attendees, video links | Event metadata for display and prep briefs |
| Outlook Calendar | Event titles, times, attendees, Teams links | Event metadata for display and prep briefs |
| Gmail | Email threads with meeting attendees | Extracted context only, not full emails |
| Otter.ai / Fireflies | Meeting transcripts | Summaries, action items, and key topics |
| LinkedIn (public) | Public profile data | Name, role, company, profile summary |
What SavirOS Does NOT Access
- We never see your password (OAuth tokens only)
- We cannot create, modify, or delete calendar events
- We do not read emails outside of meeting attendee threads
- We do not access your contacts, files, photos, or other account data
- We cannot send emails on your behalf without your action
- We do not share data between users
Data Boundaries by Component
| Component | Can Read | Can Write |
|---|---|---|
| You | Everything in your account | Notes, contacts, settings, data export |
| Calendar Engine | Your connected calendars (with permission) | Event metadata to your SavirOS account only |
| SavirAI | Your relationship data and meeting history | Draft content (requires your approval), status updates |
These boundaries are enforced at the API level.
AI Data Processing Boundaries
SavirAI uses large language models to generate prep briefs, summaries, and draft communications. Important boundaries:
No AI training
Your data is never used to train AI models β ours or anyone else's.
Processing via OpenAI
Queries are sent to OpenAI's API with a data processing agreement. OpenAI does not retain your data for training.
Not a professional advisor
SavirAI helps you manage relationships, not provide legal, financial, or business advice.
You are responsible
Always review AI-drafted content before sending. You own the actions taken.
SavirAI Action Safety
When SavirAI takes actions on your behalf:
- β’Actions require approval by default (unless you enable auto-execute)
- β’Every action is logged in your audit trail
- β’You can mark contacts as βsensitiveβ for extra confirmation
- β’Brief undo window after execution
- β’Rate limits prevent runaway actions
Data Storage & Security
Encryption
AES-256 encryption at rest. TLS 1.3 for all data in transit.
Infrastructure
Data stored in Google Cloud (Firebase/Firestore). See our Security page for details.
Access control
Your data is isolated to your account. Other users cannot see your contacts, notes, or relationship data.
Data Export
Pro and Team users can export all their data at any time:
Go to Settings
Click "Export Data"
Choose what to export: contacts, meeting history, notes, promises
Download as JSON or CSV
Account Deletion
When you delete your account, all data is permanently removed:
- β’All contacts and relationship records
- β’All meeting notes and transcripts
- β’All SavirAI conversations and actions
- β’All integration tokens
- β’All usage, credits, and billing data
- β’Authentication credentials
Immediate and irreversible. No soft delete. No retention period.
We recommend exporting your data before deleting your account. Go to Settings β Account β Delete Account.