Privacy Policy
Effective Date: June 17, 2026 Last Updated: October 1, 2026
Saive ("we," "us," or "our") is registered in Ontario, Canada. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Saive web application, apps, browser extensions, MCP server, AI assistant plugins, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Information You Provide
- Account information. When you sign up, we collect your email address and display name. Authentication is handled by our identity provider (Clerk), which may also receive information from Google if you choose to sign in via Google OAuth.
- Saved content. When you save a bookmark, we store the URL, page title, and the article body text extracted from the page by our browser extension. You may also add personal notes and highlights to your saves.
- Profile information. If you opt in to a public profile, we collect your chosen display name, username slug, bio, and optional avatar.
- Communications. If you contact us (e.g., via a contact form), we collect the content of that message and your email address.
Information We Generate
- AI-derived metadata. We use AI services to generate summaries, tags, concept labels, and reading-time estimates from the content you save. We also generate vector embeddings for search.
- Cross-file insights. We derive emergent concepts ("Map of Content" files) across your saves to surface patterns in your reading.
Information Collected Automatically
- Usage analytics. On our marketing site, we use Vercel Analytics, which does not use cookies or track individuals across sites. In the web app, we use PostHog to record product events: pages you view, buttons you click, page performance measurements, and actions such as saving or searching. These events are linked to your account and include your IP address. We use them to understand how people use Saive and to find problems, never for advertising. We do not record your sessions.
- Error reports. When something breaks, Sentry receives a technical report of the error. We remove saved content from these reports before they are sent.
- Authentication cookies. We use strictly necessary session cookies to keep you signed in. We do not use advertising, retargeting, or third-party tracking cookies.
- Log data. Our hosting infrastructure may collect standard server logs (IP address, browser type, request timestamps) for security and debugging purposes.
- Connected assistant records. When you connect an AI assistant to Saive (see section 3), we record which assistant connected, the name it reports, and when it first and last connected.
2. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Process your saved content through our AI pipeline to generate summaries, tags, concepts, and search embeddings
- Display your public profile and public saves, if you opt in
- Let the AI assistants you connect read your library and save to it on your behalf
- Measure which assistants people connect, so we can see how people find and use Saive
- Respond to your inquiries and support requests
- Understand how people use the Service, so we can improve it
- Detect, prevent, and address technical issues and abuse
- Comply with legal obligations
We do not use your information for advertising, profiling for ad targeting, or selling to third parties.
3. How We Share Your Information
Service Providers
We share information with third-party service providers solely to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication and session management | Email, auth identifiers |
| Anthropic | AI summarization and tagging | Article text (for processing only) |
| Voyage AI | Search embedding generation | Article text (for processing only) |
| Cloudflare (R2) | Vault file storage | Saved content (encrypted at rest) |
| Neon | Database (derived index) | Metadata, embeddings, account data |
| Vercel | Web hosting; marketing analytics | Server logs; anonymous page-view counts |
| Resend | Transactional email | Email address, message content |
| PostHog | Product analytics (web app only) | Product events, account ID, IP address |
| Sentry | Error monitoring | Error reports, with saved content removed |
| Railway | Background processing of saves | Saved URLs and article text (for processing only) |
These providers process data on our behalf under contractual obligations and do not use your data for their own purposes.
AI Assistants You Connect
You can connect an AI assistant, such as ChatGPT, Codex, or Claude, to your Saive account through our MCP server and its sign-in screen. Once you approve the connection, that assistant can read your saves, notes, highlights, and saved article text, and can save new links to your library when you ask it to. Saive sends content to the assistant only in response to requests the assistant makes on your behalf.
The assistant's provider (for example, OpenAI or Anthropic) handles what it receives under its own terms and privacy policy, not this one. These providers are not our service providers: you choose and authorize them, and they act for you.
Saves an assistant makes follow the same rules as your own. They are private by default, and a save filed into a shared folder becomes visible to that folder's audience.
You can end a connection at any time by removing Saive from the assistant. Deleting your Saive account ends every connection and deletes our connection records.
Shared Content Layer
When multiple users save the same URL, AI-generated metadata (summary, tags, concepts) may be reused to avoid redundant processing. This sharing is anonymous — no article body text crosses user boundaries, and no user is identified to another user through this mechanism. Aggregate counts (e.g., "N users saved this") are only displayed when N ≥ 5 to prevent re-identification.
Public Profiles and Saves
If you create a public profile and mark individual saves as public, the following becomes visible to anyone: your display name, username, save title, source domain, save date, and original URL. Article bodies, AI summaries, and personal notes are never exposed on public saves.
Legal Requirements
We may disclose your information if required by law, legal process, or governmental request, or to protect the rights, safety, or property of Saive, our users, or the public.
4. Data Storage and Security
- Vault storage. Your saves are stored as Markdown files in Cloudflare R2 object storage, isolated by your user ID as a key prefix. No other user can access your vault files.
- Encryption. Data is encrypted in transit (TLS) and at rest (Cloudflare R2 server-side encryption).
- Index. A PostgreSQL database serves as a derived search index. It is reconstructible from your vault files and does not contain data that doesn't originate from them.
- Access controls. R2 is accessed server-side only. You never receive raw storage credentials; content is served through application-issued signed URLs.
We implement reasonable administrative, technical, and physical safeguards. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
5. Data Retention
- Active accounts. We retain your data for as long as your account is active.
- Account deletion. When you delete your account, we delete all vault files under your user ID prefix and all associated rows in our database. Shared content records (AI metadata keyed to a URL, not attributable to any individual user) may be retained.
- Backups. Deleted data may persist in encrypted backups for up to 30 days before being purged.
6. Your Rights
All Users
You may at any time:
- Access your data by exporting your vault (your saves are portable Markdown files)
- Correct your data by editing your saves or account information
- Delete your account and all associated data
- Withdraw public visibility on any save or your profile
European Economic Area, UK, and Switzerland (GDPR)
If you are in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation:
- Legal basis. We process your data on the basis of: (a) contract performance (providing the Service you signed up for), (b) legitimate interest (security, abuse prevention, product improvement), and (c) consent (where applicable, e.g., marketing communications).
- Right to access. Request a copy of the personal data we hold about you.
- Right to rectification. Request correction of inaccurate data.
- Right to erasure. Request deletion of your personal data.
- Right to restriction. Request that we limit processing of your data.
- Right to data portability. Receive your data in a structured, machine-readable format. Your vault is already stored as portable Markdown files, which you can export at any time.
- Right to object. Object to processing based on legitimate interest.
- Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint. You may file a complaint with your local data protection authority.
Data transfers. Your data is processed in North America (Canada and the United States). We rely on Standard Contractual Clauses and our service providers' data processing agreements to ensure adequate protection for international transfers.
California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act provides you with specific rights:
- Right to know. You may request the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to delete. You may request deletion of your personal information.
- Right to correct. You may request correction of inaccurate personal information.
- Right to opt out of sale/sharing. We do not sell your personal information or share it for cross-context behavioral advertising.
- Right to non-discrimination. We will not discriminate against you for exercising your CCPA rights.
To exercise any of these rights, contact us at support@saive.my.
Canada (PIPEDA)
As a Canadian organization, we comply with the Personal Information Protection and Electronic Documents Act. You have the right to access, correct, and challenge the accuracy of personal information we hold about you. Contact our privacy officer at support@saive.my.
7. Cookies
We use two kinds of cookies:
- Session cookie (set by Clerk): Maintains your authenticated session. Expires when you sign out or after the session timeout. Cannot be disabled without breaking sign-in functionality.
- Analytics identifier (set by PostHog, in the web app only): A cookie and a browser storage entry holding a random ID, so PostHog can group the events from one browser. We do not use it for advertising or to follow you across other sites.
We do not use advertising cookies, tracking pixels, or fingerprinting technologies.
8. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at support@saive.my and we will promptly delete it.
9. Publisher and Copyright
Saive's browser extension captures web content from pages you have personally accessed and are authorized to view. We respect publisher rights. Publishers who wish to request removal of cached content may contact support@saive.my.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we will provide notice via email or an in-app notification.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights:
Email: support@saive.my Mail: Saive 2727 Steeles Ave West Unit 103-906 Toronto, Ontario M3J 3G9 Canada
This privacy policy is provided for informational purposes. You should consult a qualified legal professional to ensure it meets all applicable legal requirements for your specific circumstances.