Data Stewardship

Our promises about your data

SavvX exists because your transactions can be optimized into thousands of dollars of unclaimed credit-card rewards. To do that, we need to see them. These are the promises we make in exchange.

01

We never sell your data.

Not to advertisers, not to credit-card issuers, not to data brokers, not to insurance companies, not to anyone. Our only revenue is your subscription fee. We have no commercial relationship with the card issuers we recommend, and no financial interest in steering you to one card over another. The recommendation engine optimizes for YOUR rewards math, not for our affiliate payout — because there is none.
02

We use your data only to optimize your wallet.

Transactions feed the engine. Card-account data feeds the engine. Loyalty balances feed the engine. The output is recommendations, coaching, and missed-opportunity alerts — for YOU. We do not build advertising profiles, target you with offers, sell aggregate insights to third parties, or use your patterns to train external AI models.
03

You can download or delete everything, anytime.

Self-service. Account → Manage Your Data exports a JSON of everything we hold, or expunges it permanently. Deletion revokes Plaid tokens, removes your transactions, drops your subscription, and erases your personal data — immediate and irreversible. No support ticket, no friction, no retention dark patterns.
04

We're transparent about AI.

SavvX uses AI in specific places to help us categorize merchants and extract card data. Our Responsible AI page lists exactly where AI sees your data and where it does not. Short version: AI helps the engine; AI never personalizes ads or trains external models on your spending.
05

We don't train Anthropic models on your data.

Anthropic's Claude is used as the underlying LLM for parts of our pipeline (merchant categorization, scraper extraction). Anthropic's enterprise terms include a no-training opt-out which we have enabled. Your conversations with SavvX coaching, your transactions, and your card data are not used to train Claude, ChatGPT, or any other foundation model.
06

We disclose breaches within 72 hours.

If we ever experience a security incident that affects your data, you'll know within 72 hours of our detection — by email and SMS. The disclosure will be plain-language: what happened, what was exposed, what you should do. No legalese delay tactics. The 72-hour standard is the one Europe (GDPR) and California (CCPA) require; we apply it globally to every SavvX user.
07

We give clear explanations, not corporate-speak.

These principles, our Privacy Policy, our Security Center, and our Terms of Service are written in plain English. If something is unclear, email support@savvx.com and we'll rewrite the section. We'd rather change our docs than let you wonder what we meant.

What you won't find here

No "we may use your data for legitimate business interests as determined by us" carve-outs. No third-party marketing partnership disclosures buried in section 14. No data-broker reseller chains. No "subject to change without notice" hedge on the no-data-sale promise — that one is the business model, not a courtesy.