SAVENTRA

Privacy Policy

Last updated: 13 July 2026 · Effective: Immediately

1. Our Privacy Promise

Saventra is private by design. You can use Saventra in two ways:

  • Without an account — your financial data lives only on your device, encrypted with AES-256-GCM and a key derived from your master password. In this mode your financial data never reaches our servers.
  • With an account — your workspace is additionally backed up to our servers in encrypted form (AES-256-GCM, protected by a key unique to your account and wrapped by AWS Key Management Service), so you can recover it after a password reset and pick up on any device.

We operate zero analytics, zero tracking, and zero telemetry. There are no advertising SDKs and no data brokers in our supply chain. We never sell your data or use it for advertising. You can export or permanently delete your data — including your whole account — at any time, directly from the app.

2. Who We Are

Data Controller: Saventra (sole proprietorship, United Kingdom)

Contact: saventrai@protonmail.com

3. What Data We Collect

3.1 Account data (only if you create an account)

  • Email address — used to sign you in, verify your account, and send security codes (password reset, email verification).
  • Password — stored only as a secure hash by our identity provider (Amazon Cognito, AWS London region). We never see or store your plaintext password.

3.2 Your financial data (encrypted)

  • Income, budget allocations, and category names you create
  • Transaction amounts, notes, and dates
  • Debt balances, interest rates, and payment history
  • Subscription names, costs, and billing cycles
  • Goal targets, deadlines, and contribution history
  • Payslip data extracted from PDFs you import (parsed locally in your browser)
  • Your name and age (optional, only if provided)

Without an account, this data stays on your device and we never receive it. With an account, it is stored encrypted with AES-256-GCM, in transit and at rest, protected by a data key unique to your account that is wrapped by AWS Key Management Service (KMS). It is decrypted only in response to your authenticated requests, and every key use is logged.

3.3 Billing data (only if you subscribe to Pro)

  • Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers.
  • We store only your plan, subscription status, and a Stripe customer reference, so the app knows which features you have paid for.

3.4 AI features (only when you use them)

The optional AI companion and coaching features can read a summary of your workspace (for example income, budget, debts, and runway figures) to give answers grounded in your real numbers. When you send a message to the AI, that message and the workspace summary are transmitted to the AI model provider:

  • If you connect your own API key, your browser sends the data directly to the provider you chose (OpenAI, Anthropic, or Google).
  • If you use Saventra's managed AI (Pro), the data is routed through our server to Google Gemini using our key; we do not store your conversations server-side.

AI providers process this data under their own API terms. If you never use the AI features, none of your data is sent to any AI provider.

3.5 Other data we collect

  • Server access logs — standard CDN/API logs from Cloudflare and Amazon Web Services (IP address, user agent, timestamp, requested URL). Retained for a maximum of 30 days for security monitoring, not for analytics or profiling.
  • In-app feedback — if you submit the Help & Feedback form, we store your message and account email so we can respond.
  • Email correspondence — if you contact us, we retain the thread for support purposes.

3.6 Data we NEVER collect

  • Bank account numbers, sort codes, routing numbers, or bank login credentials
  • Credit/debit card numbers (these go directly to Stripe)
  • Government-issued identification numbers
  • Real-time location data
  • Device fingerprinting data
  • Browsing history outside saventra.app

4. How We Use Your Data

  • Account data: to authenticate you and secure your account.
  • Encrypted vault backups: only to sync and restore your own workspace on your request.
  • Billing data: only to provide the subscription you paid for.
  • Server logs: only for security monitoring (abuse prevention, DDoS detection) and debugging; deleted after 30 days.
  • Feedback and support emails: only to respond to you.

We do not use your financial data for any purpose other than serving it back to you.

5. Legal Basis for Processing (UK GDPR / EU GDPR)

  • Account, vault backup, and billing data: Performance of a contract (Article 6(1)(b)) — providing the service you signed up for.
  • AI features: Consent (Article 6(1)(a)) — data is sent only when you actively use the feature.
  • Server logs: Legitimate interest (Article 6(1)(f)) — security and abuse prevention.
  • Local-only data on your device: not processed by us and outside the scope of our processing.

6. Data Sharing & Processors

We do not share, sell, rent, or trade your personal data. We use the following processors to run the service:

  • Amazon Web Services (AWS) — hosting and infrastructure (S3, CloudFront, Cognito, Lambda, DynamoDB, KMS), primarily in the London region (eu-west-2). AWS cannot read your encrypted vault contents in any usable form outside the logged, per-request KMS decryption described above.
  • Cloudflare — DNS and network proxy in front of our site. Cloudflare sees standard connection metadata (IP address, requested URL) to route and protect traffic; it never has access to your vault contents.
  • Stripe — payment processing for Pro subscriptions. Stripe's own privacy policy applies to payment data.
  • AI model providers (Google, and OpenAI or Anthropic if you connect your own key) — only when you actively use AI features, as described in section 3.4.
  • Google Fonts — our pages load two typefaces from Google's servers; Google receives your IP address as part of serving the font files. No cookies are set.
  • Legal obligation — if required by a valid UK court order or law enforcement request with proper legal authority, we may disclose the data we hold. We will notify you before disclosure where legally permitted.

7. Data Retention

  • Local data on your device: retained until you delete it — you control this entirely.
  • Cloud vault backups: retained while your account exists. When you delete your account, your vault is erased immediately; residual encrypted storage versions are automatically purged within 30 days.
  • Account data: deleted when you delete your account.
  • Billing records: retained as required by UK tax and accounting law (typically 6 years), limited to transaction records — never your financial workspace.
  • Server logs: retained for 30 days, then automatically purged.
  • Support emails: retained for 12 months after resolution, then deleted.

8. Your Rights (UK GDPR / EU GDPR)

You have the following rights regarding any personal data we hold about you:

  • Right of access (Article 15) — request a copy of your data
  • Right to rectification (Article 16) — correct inaccurate data
  • Right to erasure (Article 17) — delete your data
  • Right to restriction (Article 18) — limit how we process your data
  • Right to data portability (Article 20) — receive your data in a structured format
  • Right to object (Article 21) — object to processing based on legitimate interest
  • Right to withdraw consent (Article 7) — where processing is based on consent

You can exercise the most important rights yourself, instantly, inside the app:

  • Export — download your data as CSV, spreadsheet, or PDF from the Reports and Workbook views, or as an encrypted backup file.
  • Delete your account — Settings → Account & Security → Delete Account. This erases your cloud vault and permanently deletes your account.

For anything else, email saventrai@protonmail.com and we will respond within 30 days as required by law. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

9. Data Security

  • AES-256-GCM encryption — your data is encrypted in transit (TLS) and at rest, on device and in the cloud
  • AWS KMS envelope encryption — a unique per-account data key, wrapped by AWS Key Management Service; every decryption is tied to your authenticated request and logged
  • PBKDF2 key derivation — local vaults derive their key from your master password with 310,000 iterations; the password and key never leave your device
  • Content Security Policy — strict CSP headers to prevent cross-site scripting
  • No analytics or tracking scripts — there is nothing to leak

10. International Transfers

Your account data and encrypted vault backups are stored in the United Kingdom (AWS London region, eu-west-2). Cloudflare routes traffic through its global network, and Stripe and AI model providers may process data outside the UK; where they do, transfers are protected by Standard Contractual Clauses or the UK International Data Transfer Agreement under their respective data processing agreements.

11. Children's Privacy

Saventra is not directed at children under 16. We do not knowingly collect personal data from children. If you are a parent and believe your child has provided us with personal data, please contact us.

12. Changes to This Policy

We will post any changes to this policy on this page. Significant changes will be notified via the app. The "Last updated" date at the top indicates when this policy was last revised.

13. Contact

For privacy-related inquiries, data subject requests, or security concerns:

Email: saventrai@protonmail.com

Security vulnerability disclosure: security.txt

UK ICO: You may also contact the Information Commissioner's Office at ico.org.uk or 0303 123 1113.

Back to Saventra