Savion
Privacy notice
Last updated 26 August 2026.
This notice describes how Savion (the service at law.savion.app) handles personal data. It is written to match what the product actually does, not a generic template. It is not legal advice.
Who is responsible
Savion is the controller for personal data processed through this website and the related mobile app. Questions: vahit@savion.app.
What we collect
Account: email address, password hash (held by our auth provider), and the session that keeps you signed in.
Onboarding: the jurisdiction you mostly work with, a rough description of who you are (individual, in-house, firm, and so on), optional organisation name, optional note on what you want to use Savion for, confirmation that you are 18 or older, and which terms version you accepted.
Questions you ask the agents, documents you attach, generated documents, conversation history, and ratings you leave on answers. That is the product. We cannot answer a legal question without processing the question.
Billing: Stripe (web) and Apple (app) see payment identifiers, plan and pack purchases. We store the subscription and credit state needed to run the account, not your full card number.
Guest invites and operational logs: enough to send an invite, rate-limit abuse, and debug outages. Logs are written so they do not keep message bodies, prompts, cookies or authorization headers.
Cookies and similar storage
Signed-out public pages set no cookies. After you log in, a first-party HTTP-only session cookie (Supabase) is required to keep you signed in. During sign-up and password reset the browser also holds a short-lived PKCE verifier so the confirmation link can complete. Those are strictly necessary for a service you asked for. We do not use advertising, retargeting or analytics cookies, and there is no cookie banner because there is nothing non-essential to ask about.
Theme (light/dark) is stored in localStorage on your device as savion-theme. It never leaves the browser.
How we measure the public site
Public pages may send the path you viewed and whether you clicked through to create an account. The server counts those events by UTC day and path, then discards the request. We do not store your IP address, user-agent, or a visitor identifier for this purpose, and we do not set a cookie to recognise you later. Bots are ignored. If your browser sends Do Not Track or Global Privacy Control, the count is not sent.
This is aggregated audience measurement so we can see whether the landing page and the question pages are used — not a profile of you. Google Search Console, if we connect it, is Google's own search data about our URLs; it does not run on the page.
Who else sees the data
To run the service we use processors: Supabase (database and authentication), the model providers the agents call (which may include Anthropic, Google, OpenAI and MiniMax), Tavily for web research on some agents, LangSmith for optional tracing of agent runs when that is enabled, Stripe and Apple for payments, Resend for transactional email, and our hosting and Redis infrastructure. A legal question and its attachments can therefore be processed by those providers in order to produce an answer. We do not sell your data and we do not run advertising networks on this site.
Why we process it (GDPR)
Performing the contract: creating an account, answering questions, billing, and keeping you signed in.
Legitimate interests: keeping the service secure, aggregated public-page measurement as described above, and understanding product cost.
Legal obligation: tax and accounting records for payments.
Consent: only where we actually ask for it (the onboarding tick is acceptance of the terms and the AI disclaimer, not a marketing opt-in). You can refuse analytics at the browser (DNT / GPC) without losing the product.
How long we keep it
Account, conversations and billing records last as long as the account is open, then as long as we still need them for disputes, security or law. Aggregated page counts have no personal data in them and can be kept as statistics. You can ask us to delete an account and its conversations by emailing vahit@savion.app.
Your rights
If the GDPR applies to you, you can ask for access, correction, deletion, restriction, portability, and to object to processing based on legitimate interests. You can also complain to your supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
Children
Savion is for people 18 or older. We do not knowingly collect data from children.