1. The short version

The plain-language architecture explanation lives on the security and privacy page. This document is the binding one. Where the two differ, the stricter statement governs our behavior.

2. Who we are

Savory is a native macOS and iOS app operated by Gregg Hawkins, 415 Gartrell Street SE Unit 2, Atlanta, GA 30312, United States. For the purposes of the GDPR and UK GDPR, we are the controller of the personal data described here. For the purposes of US state privacy laws, we are the business.

Privacy questions, rights requests, and complaints go to privacy@savory.ai. General support is support@savory.ai.

This policy covers three things: the Savory applications for macOS and iOS, this website at savory.ai, and the Savory account service that signs you in, sends account email, meters your subscription, and forwards summary requests to an AI provider on your behalf.

3. What Savory processes on your device

Nearly everything Savory knows about your meetings is created and kept locally, at ~/Library/Application Support/Savory/ on the Mac and inside the app container on iOS. The macOS permission prompt states the audio rule in the same words the app does: "Savory listens to your microphone to transcribe meetings on your device. Audio is never saved."

At-rest protection for local storage comes from the operating system: FileVault on macOS, and system data protection on iOS.

4. What leaves your device, and when

Savory is deliberate about network use. Every outbound flow is listed here.

Two things follow from that list. Transcription works with the network off, because no part of it needs a server. And a meeting you never summarize stays a meeting you never summarized: the text of it goes nowhere.

5. Google user data

Savory asks for five Google scopes. Three identify you at sign-in, and two are the calendar scopes that make the product work.

Where Google data goes. Your Google OAuth tokens are stored in the system Keychain on your device, marked non-syncing, and are never transmitted to Savory servers. Calendar events are stored in local caches on your device. Attendee names and email addresses from those events become People records, which sync through your own private iCloud database when sync is available. Google Calendar content is never sent to Savory's servers and is never included in a summary request except where it appears in the transcript of a meeting you chose to summarize, after the scrub described in section 6. We advertise Savory, and no Google user data is any part of that: see section 18.

Removing our access. Disconnect the account in Savory under Settings, which deletes the stored tokens and purges that source's cached events, or revoke access at myaccount.google.com/permissions. Meetings you already recorded keep the event details captured at the time, because those belong to the meeting, not to the calendar connection.

6. What our servers hold

The Savory account service exists so that an account is portable between your devices and so that a subscription can be metered. Identity moves to the server. Content never does.

What the account service never holds: audio, transcripts, summaries, notes, action items, people, calendar content, voiceprints, card or bank details, and your calendar or provider tokens. When a summary request passes through the service, the scrubbed text is forwarded to the provider and not persisted, and the logger structurally refuses to write prompt, transcript, or response fields at any nesting depth.

7. Why we process it, and on what legal basis

  • To provide the service you asked for (contract): creating and authenticating your account, syncing your own data through your own iCloud account, connecting a calendar, generating a summary you requested, and metering a subscription.
  • With your consent: sending a transcript for summarization, storing a voiceprint, and receiving product-update email. You can withdraw any of these at any time, in the app or through the unsubscribe link, without affecting anything you did before.
  • For our legitimate interests: keeping accounts secure, detecting token theft, rate-limiting abuse, understanding aggregate product and revenue performance from records that carry no personal identifiers, and defending legal claims.
  • To comply with law: keeping financial records of purchases and responding to lawful requests.

8. Who else processes your information

We use a small number of providers, each for one job.

We may also disclose information if we are legally required to, or to establish or defend legal claims. If the business is ever transferred, this policy travels with it and you will be told before anything changes.

We do not sell personal information for money, and no data broker appears in the list above. The advertising tags on this website do meet the definition of sharing for cross-context behavioral advertising under US state privacy laws, and in some states the definition of a sale even with no money involved. We say so plainly rather than argue the label, and section 18 is where you turn it off. The apps themselves carry no advertising identifier, no ad SDK, and no analytics SDK.

9. AI providers, and what happens to a summary request

Summaries are off until you turn them on, either globally or for one meeting. When you ask for one, the transcript is rendered as text, then scrubbed: email addresses, phone numbers, card-shaped number runs, and internal identifiers are replaced with redaction markers before anything is sent, and the assembled prompt is checked a second time for any address that slipped through.

Be precise about what the scrub does not cover. It targets identifiers, not meaning. Spoken names and the substance of your discussion are what a summary is made from, so they are sent, under your explicit consent.

The request goes from your device to the Savory account service, which forwards it to Google or OpenAI under our own API key and records only metering data. This is the same route whichever way you installed Savory.

Neither we nor our providers use your content to train models. The paid API terms under which we and you use Gemini and OpenAI exclude API inputs and outputs from model training. A provider may retain a request briefly for abuse monitoring under its own terms.

10. How long anything is kept

11. Deleting your data

Signing out removes nothing. Deletion is its own explicit act, and there are two of them.

  • Delete all data clears the account's content on that device and hard-purges any stored voiceprints. It is confirmed with biometrics, and the deletion propagates to your other devices through sync. The account itself stays.
  • Delete your account is gated by both biometrics and a re-authentication against the server. It removes the server record first, then your iCloud zone, the on-disk storage, the Keychain tokens, and the local rows, in an order that leaves nothing orphaned if it is interrupted. If you signed in with Apple, we spend the stored Apple refresh token to revoke that grant. A closing record is emailed to your former address.

What survives, deliberately: the PII-free audit row that records the deletion, and the financial records described above with the identity link severed. Nothing that survives can be traced back to you by us.

Because your content is on your device, export is a first-class action rather than a request queue: notes and transcripts export to plain files at any time.

12. Your rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. You also have the right to complain to your supervisory authority.

If you are a resident of California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you have the right to know what we collect and why, to access and delete it, to correct it, to receive a portable copy, and to opt out of sale, sharing for cross-context behavioral advertising, and profiling. We do not sell personal information for money, and we do not profile you in any way that produces legal or similarly significant effects. We do share website activity with advertising platforms for cross-context behavioral advertising, which those laws treat as sharing and some treat as a sale, and section 18 gives you three ways to stop it, one of which is the Global Privacy Control signal we honor automatically. Meeting content, account records, and Google user data are never part of that sharing. We do not process sensitive personal information to infer characteristics, and we do not use or disclose it beyond the purposes described here. We will not discriminate against you for exercising any right.

Most rights are self-service: your content is on your device, export produces plain files, and deletion is a button. For anything you cannot do yourself, write to privacy@savory.ai from the address on the account. We will verify that the account is yours, answer within 30 days, and tell you if we need longer. If we refuse a request you may appeal by replying to our decision, and we will answer the appeal within 45 days.

13. Recording, consent, and other people

Recording laws vary by place and context, and some require the consent of every participant. You are responsible for obtaining any consent the law requires where you record. Savory is built to help you act deliberately rather than by accident: every session passes a consent gate before capture begins, a denial prevents capture rather than discarding it afterwards, you can mark people who should never be recorded, and every applied decision is written to an audit log that records the decision and no meeting content.

Voice recognition deserves its own paragraph, because a voiceprint is biometric information. It is off by default. If you turn it on, the voiceprint is created and stored on that device, is excluded from sync by a structural rule rather than a setting, is never transmitted to us or to any provider, and is hard-purged when you delete your data. We never collect, receive, or possess it. Anonymous speaker separation, which labels voices as speaker one and speaker two within a single meeting, persists no biometric at all.

These are engineering facts, not legal advice. If you record in a regulated setting, check your own obligations.

14. Children

Savory is not directed to children. You must be at least 16 to use Savory, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@savory.ai and we will delete it.

15. Security

Secrets live in the system Keychain, marked non-syncing, so a token cannot follow you to a device you did not authorize it on. Passwords are hashed with Argon2id and never stored or logged in the clear. Refresh tokens rotate, and reusing a replaced token revokes the whole sign-in family as a theft signal. Traffic to our service and to every provider runs over TLS. Server logs refuse fields that would carry a password, token, code, email address, or message body, at any nesting depth. There is no third-party analytics or crash SDK in the app. And the guarantee at the center of the product is enforced by a build gate: an automated audit runs on every change and fails the build if a path that writes audio to disk appears.

No system is perfect. If you find a vulnerability, write to support@savory.ai with the subject line Security, and we will work with you.

16. Where your information is processed

Savory is operated from the United States, and the providers in section 8 process data in the United States and in other countries where they operate. If you use Savory from outside the United States, your information is transferred there. Where a transfer of personal data out of the European Economic Area, the United Kingdom, or Switzerland requires a safeguard, we rely on the standard contractual clauses in our agreements with those providers.

17. Cookies and this website

savory.ai uses cookies, pixels, and similar technologies, in three kinds, and the difference between them is the whole point of this section.

  • Strictly necessary. What the site needs to serve pages and stay secure. Your light or dark theme choice is remembered here too, in a browser session value rather than a cookie, and it never leaves your browser.
  • Analytics. Google Analytics 4, deployed through Google Tag Manager, tells us which pages people read, where they arrived from, and whether a visit ended in a download or a sign-up.
  • Advertising. Conversion and audience tags from the platforms we advertise on, so we can tell which campaigns work and show Savory to people who visited without signing up.

What those tags collect is ordinary website data: pages viewed on savory.ai, an approximate location derived from your IP address, your device and browser, the site or ad that referred you, links clicked, and whether a visit turned into a download or a sign-up. What they never receive is in section 18, and the list is short because the boundary is structural: they run on this website, and this website holds none of your Savory data.

The hosting platform keeps ordinary web request logs. If you email us, we use your message to reply to you and for nothing else, and we never add you to a mailing list from it.

18. Advertising, and your choices

We advertise Savory, and we measure whether the advertising works. All of that happens on this marketing website and nowhere else. Analytics run on Google Analytics 4 through Google Tag Manager; the conversion and audience tags belong to the platforms we buy ads on: Google Ads, Microsoft Advertising, LinkedIn Ads, TikTok Ads, Meta for Facebook and Instagram, X Ads, and Apple Ads.

Under US state privacy laws, running those tags is sharing personal information for cross-context behavioral advertising, and in several states it meets the definition of a sale even though no money changes hands. We describe it that way rather than argue the label. What we do not do is take payment for personal information, and what those platforms get is the website activity described in section 17.

Your privacy choices

Any one of these stops the advertising and analytics tags. You do not need to do more than one.

  • The footer link. "Your privacy choices", in the footer of every page, is our "Do Not Sell or Share My Personal Information" link, and it brings you here.
  • A universal opt-out signal. We honor a legally recognized universal opt-out signal, including Global Privacy Control. If your browser sends one, we treat it as an opt-out of sharing for targeted advertising for that browser, and nothing further is required of you.
  • Consent, if you are in the EEA, the UK, or Switzerland. Nothing beyond the strictly necessary loads until you allow it, and you can withdraw that permission at any time, with the same effect as never having given it.
  • The platforms and your browser. Google Ads Settings, the industry opt-outs at optout.aboutads.info and optout.networkadvertising.org, your device advertising controls, and ordinary cookie blocking all work here, because these are ordinary web tags.
  • Ask us. Write to privacy@savory.ai and we will apply the opt-out for you. An authorized agent may do it on your behalf.

Opting out of advertising changes nothing about the app. Savory works identically either way, and there is no version of Savory that shows you ads.

19. Changes to this policy

If we change how Savory handles your information, we will update this page, change the version and effective date above, and describe the change in the changelog. Material changes are also announced in the app. Continuing to use Savory after a change means the updated policy applies to you.

  • Version 1.1, September 5, 2026. The published Savory privacy policy, covering the apps, this website, the account service, Google user data, and advertising. This version adds Stripe as the merchant of record for Savory Pro in the version downloaded from savory.ai, and records that summary requests from every version pass through the account service under our own key.