Back to Savvy

Privacy policy

Last updated 6 September 2026

Who is responsible

Alamas Labs, Inc., a Delaware corporation in the United States, operates savvycopilot.com and is responsible for the website processing described here. Contact hello@savvycopilot.com with privacy questions or requests.

This notice covers the public website and explains the current open-source desktop app, where you connect your own providers. It does not describe a future managed subscription service.

Website hosting and security

Cloudflare delivers this website and protects it from abuse. Requests include your IP address, the requested URL, browser information, and connection details. Cloudflare processes this information to serve pages, maintain reliability, and detect malicious traffic. We rely on our legitimate interest in operating a secure, working website for this processing.

Cloudflare operates internationally, so processing can take place outside your country, including outside the European Economic Area. Its data processing terms describe the safeguards that apply to international transfers, including standard contractual clauses. See Cloudflare's privacy policy and its data processing terms.

Website analytics

With your permission, we use our Umami installation at analytics.jamalavedra.com to understand how people find and use this website. It records page visits, referring URLs, visit times, browser and device information, language, and approximate location. Page URLs can include query parameters. Please do not put private information in links to this site.

Umami's tracking script does not use cookies. Umami processes IP addresses and browser information to derive location and generate session identifiers. Umami does not store raw IP addresses in its analytics records, but generating session identifiers still involves processing connection information. Hosting infrastructure can process connection data separately.

This website does not supply names, email addresses, or account identifiers to Umami. The installed snippet does not enable session replay or heatmaps. Website analytics does not collect your desktop app's documents, meeting audio, or transcripts.

We rely on consent for optional analytics. It stays off until you choose Allow analytics. Use the Privacy preferences control on any page to reject analytics or withdraw your consent. This browser stores your choice locally for up to one year. Clearing browser storage removes it. Withdrawing consent stops future collection; it does not undo earlier lawful processing or automatically delete existing records.

We do not run advertising trackers or sell your personal information. Our self-hosted analytics service and its hosting infrastructure process the visit data described above. We operate from the United States and use infrastructure that may process data in other countries. Where required for transfers from the EEA or UK, we use appropriate safeguards, including standard contractual clauses. Contact us for information about those safeguards.

How long we keep information

We retain analytics while it remains useful for website reporting and improvement. Analytics records have no fixed expiry. We delete them manually. Our hosting providers handle connection and security records according to their applicable service terms and policies. The desktop app has a separate local retention rule, explained below.

Desktop app and your providers

The current desktop app reads source files from folders you choose and stores extracted text, indexes, briefs, recordings, and transcripts on your Mac. It leaves the source files unchanged. At startup, Savvy deletes local recordings and transcripts older than 30 days. This startup cleanup does not delete copies held by providers or backups.

Savvy streams audio to your Deepgram or AssemblyAI account for transcription. There is no offline transcription mode. For recommendations, Savvy sends selected document excerpts, the whole brief, and recent transcript turns to your signed-in Codex or Claude Code CLI's provider. These services process information under your account and their own terms. Review those terms and settings before using confidential material or recording other people.

Savvy stores transcription API keys in macOS Keychain. The website's analytics service does not receive these keys. Removing a client in the app removes its derived local data without deleting the original source folder.

Contact and external links

If you contact us, we process the information you send to respond to your request. Our legal basis is our legitimate interest in responding to enquiries, or compliance with a legal obligation when handling data-protection requests. We keep correspondence in our business mailbox. If an enquiry does not lead to an engagement, we retain it for up to 24 months after the last contact. We keep client correspondence for the engagement and afterward as needed to meet legal and accounting obligations.

GitHub hosts downloads, source code, and issue reports. If you follow those links, GitHub processes your visit under its own privacy notice. Issues in the public repository are public, so do not include personal information, recordings, API keys, or confidential documents in an issue.

Your rights

Depending on the law that applies, you can request access, correction, deletion, restriction, or portability of personal data we hold about you. You can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing.

Contact hello@savvycopilot.com to make a request. We may need enough information to verify and locate the relevant records. We cannot access or erase files that remain only on your Mac or data held in your own provider accounts.

You can complain to your local data protection authority. In Spain, this is the Spanish Data Protection Agency.

Changes to this notice

We will update this page when our processing changes and show the effective date here. We will explain material changes before the new processing begins.