Privacy Policy
Last updated: June 25, 2026
1. Introduction
Savi Security, Inc. ("the Company," "we," "us," or "our") operates the website saivsecurity.com and the Savi Security mobile application (collectively, the "Service"). The Company is based at 1401 Lawrence Street, Suite 1600, Denver, CO 80202 and can be reached at [email protected].
Savi Security is an AI anti-fraud app that detects phone and text scams. The Service listens for the behavioral and acoustic patterns that characterize fraudulent calls and SMS messages, and warns you in real time before money moves. Because the product works by analyzing call audio and message content, we want to be direct about what that means for your data: analysis happens on your device, and we do not sell, broker, or share your call or message content with advertisers or data companies. This policy explains how that works, what limited data does leave your device, and what choices you have.
This policy applies to information we collect through the Service and through direct communications with us.
2. Information We Collect
2.1 Account and Contact Information
When you create a Savi Security account or contact us, we collect information you submit directly:
- Name and email address when you register or subscribe to updates;
- Password (stored as a one-way hash; we never see the plaintext);
- The content of any messages you send us through contact forms or email.
2.2 App Usage and Detection Data
Savi's core function is on-device detection. Call audio is processed locally; recordings are not uploaded. What does leave the device is limited operational data:
- Detection events: when the app flags a potential scam, it logs the event type (call vs. SMS) and a risk-score summary -- not the call audio, caller ID, or message text;
- Pattern match signatures: an anonymized indicator of which fraud-pattern family triggered the alert (for example, "government-impersonation" or "gift-card-demand"), used to improve pattern accuracy;
- App diagnostics: crash reports and performance metrics (device class, OS version, app version), which do not include call or message content.
SMS phishing detection evaluates message patterns locally. Message text is not transmitted to our servers.
2.3 Information Collected Automatically on the Website
When you visit saivsecurity.com, we automatically collect limited technical data:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5 and our Cookie Policy).
2.4 Children's Data
The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it promptly.
3. How We Use Information
We use the information we collect to:
- Provide and operate the Savi Security app and website;
- Authenticate your account and deliver your chosen subscription tier;
- Improve scam-detection accuracy by analyzing anonymized pattern-match events;
- Send service-related communications (account confirmation, subscription receipts, important security notices);
- Respond to your support inquiries and contact-form submissions;
- Detect, investigate, and prevent fraud or abuse of the Service;
- Comply with applicable legal obligations.
We do not use your call audio, message content, or detection logs to target you with advertising. We do not operate an advertising platform, and we have no advertising relationships that would involve your personal data. We do not sell personal information for monetary value.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (for example, hosting infrastructure, transactional email delivery, anonymized analytics) under contractual terms that prohibit them from using your data for their own purposes;
- Authorities, when required by law or compelled by valid legal process, or to protect the rights, safety, or property of the Company or others;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy remaining in effect for your data.
We do not sell personal information to third parties. We do not share personal information with data brokers or advertising networks. Your call data and message content are never part of any third-party arrangement.
5. Cookies and Tracking
We use cookies and similar technologies to operate the website, maintain your session, and measure usage in aggregate. We do not use advertising cookies or cross-site tracking technologies. For full details and how to manage your preferences, see our Cookie Policy.
6. Data Retention
Account information is retained while your account is active and for up to 24 months after account closure, unless you request deletion sooner. Anonymized detection event logs are retained for up to 18 months to support pattern-accuracy improvement, then aggregated or deleted. App diagnostic logs are retained for 90 days. Website server access logs are retained 90 days, then aggregated. Contact-form submissions and email correspondence are retained for up to 36 months to support follow-up, then deleted unless a longer period is required by law.
7. Security
We use administrative, technical, and physical safeguards to protect personal information, including TLS encryption in transit, restricted-access databases, and least-privilege access controls for personnel. On-device processing means call audio and message text never reach our servers. No system is perfectly secure; we cannot guarantee absolute security, and we encourage you to use a strong password and keep your device software current.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access to, correction of, and deletion of your personal information, as well as the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. Colorado Residents (Colorado Privacy Act)
Because the Company is headquartered in Denver and many of our users are Colorado residents, we address your rights under the Colorado Privacy Act ("CPA") directly. If you are a Colorado resident, you have the following rights with respect to personal data we control.
9.1 Your CPA Rights
- Right of Access: confirm whether we are processing your personal data and obtain a copy.
- Right to Correction: correct inaccuracies in your personal data, considering the nature and purposes of processing.
- Right to Deletion: request deletion of personal data we hold about you.
- Right to Data Portability: obtain a portable copy where technically feasible (up to twice per year).
- Right to Opt Out: opt out of (a) targeted advertising, (b) sale of personal data, and (c) profiling that produces legal or similarly significant effects. As noted throughout this policy, we do not engage in targeted advertising or sell personal data, so these opt-out rights largely confirm our existing practice.
9.2 Universal Opt-Out Mechanism
We honor browser-transmitted universal opt-out signals, including the Global Privacy Control ("GPC"), as a request to opt out of sale and targeted advertising. Configuring GPC in your browser is sufficient -- no separate request is required. The Savi Security app does not use targeted advertising, so GPC signals from a mobile browser apply primarily to your use of the saivsecurity.com website.
9.3 How to Exercise Your Rights
Submit a request by emailing [email protected] with your name and the right you wish to exercise. We respond within 45 days; one 45-day extension is available where reasonably necessary, and we will notify you if we need it.
9.4 Appeal
If we deny your request, you may appeal by replying to our denial email with the subject line "CPA Appeal." If we maintain the denial after reconsideration, you may contact the Colorado Attorney General at coag.gov.
9.5 California Visitors
If you are a California resident, you may also exercise rights under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA/CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time to reflect changes in the Service or applicable law. Material changes will be reflected by a new "Last updated" date at the top of this page. If changes are significant, we will provide a more prominent notice.
11. Contact
Questions, requests, or complaints about this policy or our data practices can be sent to:
Savi Security, Inc.1401 Lawrence Street, Suite 1600
Denver, CO 80202
Email: [email protected]
Phone: +1 (303) 553-7214