Privacy Policy
Last Updated: October 2026
1. Introduction
Savedly is a personal memory tool: you save links, notes, images, documents, and voice memos, and it reads, organizes, and helps you find them again. This is open source software — the code is public, and you can run your own copy. The hosted service has a free plan and optional paid plans. This policy explains what information we collect, how it's used, and what choices you have.
Your saved content belongs to you. We don't sell it, we don't use it to train AI models, and we don't show you ads.
2. Information we collect
- Saved memories: the URLs, text, files, and voice recordings you explicitly choose to save, plus the AI-generated summaries, tags, and enrichment computed from them (see Section 3).
- Account info: your name, email, and avatar as provided by Google or GitHub when you sign in with them. We never see or store your Google or GitHub password. What we receive from Google is described in Section 4.
- Calendar access: if you connect Google Calendar, access to your calendar events (see Section 4).
- Payments: if you buy a paid plan, Dodo Payments (our merchant of record) collects your payment details — card, UPI or other method — and we never see or store them. We keep only the customer and subscription identifiers Dodo gives us and the status of your plan.
- Usage metadata: device/browser info, IP address, and basic activity logs (e.g. login timestamps), used for security and to keep the service running reliably.
- Content you share with others: if you create a share link or invite someone to a memory or collection, the information needed to fulfill that (e.g. the invitee's email) is stored until you revoke it.
3. How AI processing works
On the hosted service, AI features (summaries, tags, image analysis, semantic search, the Ask assistant) run on AI provider accounts we operate. When something needs AI, the relevant piece of your content (what you save, or the question you ask along with the saved content it draws on) is sent to that provider to be processed, and the result (the summary, tags, or answer) is written back into your account. We don't keep the provider's response beyond that.
If you self-host Savedly, your install sends this content to the AI provider you or your admin configure instead, and none of it reaches us.
We do not use your saved content, your questions, or your AI provider responses to train any model — ours or anyone else's.
4. Google user data
This section covers the information Savedly receives from Google when you sign in with Google or connect Google Calendar. Both are optional: you can sign in another way, and you can use Savedly without connecting a calendar.
What we access
- When you sign in with Google: your name, email address, profile picture and Google account ID. We request only the
openid,emailandprofilepermissions. - When you connect Google Calendar: the events on your calendar, through the
calendar.eventspermission. This lets Savedly view, create, change and delete events. We don't request access to your calendar settings, your other calendars' sharing settings, your contacts, your Gmail or your Drive.
How we use it
- Your name, email and picture are used to create your account, sign you in, show your profile inside the app, and send you emails about your account, such as a welcome message or a sharing invitation.
- Your calendar events are used to show your upcoming events on the Calendar page next to the events from your saved items, to add an event to your Google Calendar when you choose to, and to update or delete an event when you edit or remove it in Savedly.
- If you ask the Ask assistant about your schedule (for example, “what's on this week?”), the title and time of the relevant events are read so it can answer you.
We use Google user data only to provide these features to you. We don't use it for advertising, we don't sell it, and we don't use it to build profiles of you.
Who we share it with
We don't sell Google user data or share it with advertisers or data brokers. It is disclosed only in these cases:
- Service providers that run Savedly for us: our cloud hosting and database providers store your account information on our behalf, and our email delivery provider receives your email address so we can send you account emails. They process it only on our instructions.
- Our AI provider, only when you ask: when you ask the Ask assistant about your schedule, the titles and times of the events needed to answer are sent to the AI provider that processes your question, together with the question. This happens only as a direct result of your request.
- Google: when you add, change or delete an event, we send that change to Google Calendar, since that is the action you asked for.
- When the law requires it: if we are legally compelled to disclose information, or to protect against fraud or abuse.
We don't use Google user data, including data from Google Workspace APIs such as Google Calendar, to develop, improve or train generalized or non-personalized AI or machine-learning models. It is sent to our AI provider through its API only to answer your question, under terms that don't permit the provider to train its models on it.
How we protect it
- All traffic between your browser, our servers and Google is encrypted in transit with HTTPS (TLS).
- The access and refresh tokens Google gives us for your calendar are encrypted with AES-256-GCM before they are stored, using a key kept separately from the database.
- Your session is held in cookies that scripts on the page can't read, and every request for your data is checked against your account, so one person can't reach another's.
- Access to our production systems is limited to the people who operate the service.
- The source code is public, so how this data is handled can be checked directly.
How long we keep it, and how to delete it
- Calendar events are not copied into our database. We read them from Google when you open the Calendar page or ask about your schedule. For an event you add to Google Calendar from Savedly, we keep only its Google event ID and link, so we can update or remove that event later.
- Calendar tokens are kept until you disconnect Google Calendar from the Integrations page. Disconnecting deletes them from our database and asks Google to revoke them.
- Your name, email and picture are kept for as long as you have an account.
- Deleting your account (Settings → Privacy & Data) removes your profile, your saved content and any calendar connection. You can delete immediately, or deactivate with a 30-day period in which signing in again cancels the deletion.
- You can also remove Savedly's access at any time from your Google Account, under Security → Third-party apps and services.
Google API Services User Data Policy
Savedly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Where your data is stored
- Files and attachments (images, documents, voice recordings) are stored in Cloudflare R2 object storage.
- Everything else — memory records, tags, collections, account data, encrypted AI keys — lives in our primary database.
- Vault: memories you move into the Vault are gated behind a PIN you set (hashed, never stored in plain text) and hidden from every normal view. This is access control, not end-to-end encryption of the content itself — worth knowing plainly rather than implying more than it is.
6. Cookies and sessions
We use a small number of functional cookies to keep you signed in and to verify access to password-protected or Vault-gated content — nothing used for advertising or cross-site tracking.
7. Your rights and controls
- Export a complete copy of everything you've saved, at any time, from Settings → Privacy & Data.
- Delete individual memories (moved to Trash, permanently removed after 15 days) or delete your entire account and everything tied to it.
- Remove or rotate any AI provider key you've connected at any time — deleting a key immediately stops it from being used.
- Revoke a share link or a specific person's access to something you've shared, at any time.
8. Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page. Since the source code is public, the actual data handling described here can always be verified directly against it.
9. Contact
Questions about this policy or your data can be sent through the contact page.