Last updated: February 12, 2026
Vircode, Inc. (“Savva,” “we,” “us”) respects your privacy. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we keep it, and the choices and rights you have.
Savva operates various websites (including those located at www.savva.ai) for communicating with the public regarding our company and the Savva app‑based health and fitness platform (the “Platform”). The Platform allows you to connect the Platform’s mobile app running on your device to (i) a health and fitness application (such as Apple Health or Google Fit) also running on your device and/or (ii) one or more Electronic Health Record (“EHR”) systems of your healthcare providers. Data from these sources (“Health Data”) is used by the Platform to provide you with organizational features and insights regarding the data. To increase the privacy of your data, you must actively opt into each connection, and any connected Health Data remains on your device. The Platform was intentionally designed such that there is no need for the Health Data to be sent to Savva for the normal operation of the Platform. You get the benefit of Health and Fitness insights about your data right on your device and you are in control of your Health Data. The only time that your Health Data may be sent to Savva is if you actively opt into an advanced feature that expressly requires such a transmission or you make a support request that inherently requires transmission of a segment of data to resolve the particular support query. In either case, you will be fully aware of what Health Data is leaving your device. Our various websites never collect or process your Health Data.
Specific details are provided below in this Policy. If you do not agree with this Policy, please do not use the Platform or our websites.
Savva collects and processes the following categories of data:
| Data Category | Examples of What We Collect | Purposes of Use | To Which Vendor Processors Do We Disclose Such Data1 |
|---|---|---|---|
| Personal Identifiers | App instance ID; device registration ID (unique to your device, not linked to name or email); IP address; user agent; device model/OS; time zone/locale; coarse location (from IP); push notification tokens (if enabled) | Provide & secure the service; diagnostics; fraud/security; legal compliance; send push notifications for subscribed features | Hosting & infrastructure; security/monitoring; support tools |
| Internet and Network Activity | Pages/screens viewed; event/diagnostic telemetry | Functionality, performance, debugging; aggregate analytics | Hosting & infrastructure; analytics tooling; error monitoring |
| Geolocation (general) | Country/region inferred from IP | Localization; fraud/security | Hosting & infrastructure; security/monitoring |
| Non‑Health Data User Content & Communications | Customer support messages sent by you to us; forms you submit (neither include Health Data unless you actively attach it)2 | Customer support; service notices | Support tooling; ticketing |
| Sensitive Personal Information (Health Data) | Apple Health, Google Fit and/or EHR Health Data you choose to connect | Deliver requested features; on‑device insights; no advertising/profiling based on Health Data | If you opt in to cloud‑based AI inference: your selected third‑party AI provider (see §12); hosting/support processors under DPA |
| Cloud AI Inference (optional) | Fitness and medical records you choose to send for AI analysis; usage/billing logs | Provide AI‑powered insights via third‑party inference providers you select; billing | Your selected AI inference provider only |
| Payment & Billing Data | Transaction records; subscription type and period; billing timestamps; payment method type (we do not store full card numbers); in‑app purchase identifiers; AI inference usage logs for billing | Billing; accounting; tax compliance; fraud prevention; dispute resolution | Apple/Google (as merchant of record for in‑app purchases); hosting infrastructure for billing logs |
| Data Category | Retention |
|---|---|
| Personal Identifiers | IP & diagnostics logs: ~30 days; security logs: ≤12 months; metadata related to your giving consent is retained indefinitely for compliance purposes |
| Internet and Network Activity | Diagnostics data: ~30 days; aggregated analytics ≤13 months |
| Geolocation (general) | IP logs: ~30 days |
| Non‑Health Data User Content & Communications | As needed for support and legal/compliance requirements |
| Sensitive Personal Information (Health Data) | We do not store or have access to Health Data; it is kept on your device. You can remove the app from your device at any time. |
| Payment & Billing Data | Up to 10 years from the date of transaction, as required by applicable tax and accounting regulations. This retention continues after account deletion or consent withdrawal. |
1 Disclosures to vendor processors occur as necessary to the functioning of the Platform or our websites and such disclosure is limited to that purpose. We do not sell or share data with third parties.
2 Currently, the main features related to Health Data do not have data disclosed to vendor processors since such data remains on your device. If you attach Health Data to a support request or user submission form, such data may be disclosed to support tooling and ticketing vendors. If we offer any feature that will involve the transfer of your Health Data from your device to Savva we will do so only with specific opt‑in consent from you (in such a case, such data may be disclosed to hosting/support processors solely for the purpose of delivering the feature and under appropriate contractual data processing agreements).
We disclose Personal Information as set forth and the tables above and with the following conditions.
We delete or de‑identify data in our possession when it is no longer needed.
Where the law applies (e.g., EU/UK GDPR; CA/CO/CT/DE/FL/IA/IN/KY/MD/MN/MT/NE/NH/NJ/OR/RI/TN/TX/UT/VA), you may have some or all of the following rights related to your data:
1 You can request that we delete your personal data. We will comply with such request, except where retention is required by applicable law (e.g., payment and billing records retained under tax and accounting regulations for up to 10 years from the date of transaction). Because your Health Data is stored on your mobile device, you must also delete the mobile app from your device to remove that data. Upon such a request to delete your data, your "account" with us will be deleted within forty‑five (45) days.
2 With respect to your Health Data, the only copy utilized by the Platform is located on your mobile device and is already in a portable format usable by you.
3 We do not sell or share your data or do impactful profiling.
4 With respect to your Health Data, you can withdraw consent at any time by deleting the mobile app. We do not currently use non‑essential SDKs with our mobile app or website. If we do in the future, you will be provided a functionality to withdraw your consent.
The Platform does not make automated decisions with legal or similarly significant effects: We do not make decisions about you based solely on automated processing (including profiling) that produce legal or similarly significant effects (Art. 22 GDPR).
How to exercise your rights: Email [email protected] (or use any in‑app/web form we provide). We reserve the right to confirm your request using information sufficient to verify your (or your agent’s) identity where applicable and/or required by law.
Timing: We respond within legal timelines (e.g., 45 days, extendable once if reasonably necessary; appeals answered within 60 days or sooner if required).
Regulators: GDPR users can also complain to a local Data Protection Authority; we’ll share links on request. You also have the right to lodge a complaint with your EU/EEA Data Protection Authority or the UK Information Commissioner’s Office (ICO).
Important Note: Our mobile application requires health and EHR data access for basic functionality; removing your consent to Savva to store and process data within the application on your device will require deletion of the application itself.
We use administrative, technical, and physical safeguards appropriate to the data we process (encryption in transit/at rest, least‑privilege access, monitoring). No system is 100% secure. If a security incident affects you, we’ll notify you and regulators as required by law.
You acknowledge that your Health Data that is utilized by the Platform is maintained on your mobile device. Beyond Savva’s measures taken in design of its mobile app (e.g., encrypting your data stored on your device), Savva cannot control the physical security of your mobile device. You are solely responsible for your mobile device and to whom you give access (including giving access to the Savva mobile app).
Our Platform is not intended for individuals under 18. If you think a child gave us information, contact [email protected] so we can delete it.
If you connect a third-party system (e.g. EHR), your data with that system is governed by their privacy policy. When authentication routes through Savva, we do not receive your FHIR resources unless you explicitly direct us to (e.g., export/share).
If you opt in to cloud-based AI inference, your fitness and medical records will be sent to the third-party AI inference provider you select in the app. Available providers are: OpenAI, Google Cloud, Alibaba Cloud, Moonshot AI, Anthropic, Mistral AI, and x.ai. Your data will only be sent to the provider you choose. Our server facilitates this transfer but does not save your chat history or medical information. We do save and log usage on our server for billing purposes. Each provider’s processing of your data is governed by their respective privacy policy.
We may update this Policy. If changes are material, we’ll let you know as the law requires. Using the Platform after changes take effect means you accept the updated Policy.
Questions or requests: [email protected]
Address: 4581 WESTON RD, PMB#141, WESTON, FL 33331