Legal
Privacy Notice
Last updated: 2 September 2026
1. Who is responsible for your data
Savor is operated by Savor. For the purposes of UK and EU data-protection law (UK GDPR and GDPR), Savor is the data controller of the personal data described in this notice. Contact: support@savor.app.
2. What we collect and why
- Account data — name, email address and login credentials (password hash, or your Google account identifier if you sign in with Google). Purpose: creating and securing your account. Legal basis: performance of our contract with you.
- Taste and kitchen data — your onboarding answers (cuisines and styles you love/sometimes/never eat), time preferences, fridge and pantry items, briefs you type, recipes generated for you, your star ratings, shopping lists, meal plans and the AI-written taste summary. Purpose: providing the personalised Service. Legal basis: performance of our contract. Dietary preferences you volunteer may reveal religious or health information; we process these only with your consent, which you give by entering them and can withdraw by deleting them.
- Subscription data — your plan, subscription status, billing period dates and the reseller's customer and subscription identifiers. We do not receive or store your full card details. Purpose: unlocking the features you have paid for. Legal basis: performance of our contract.
- Support messages — anything you send us by email. Purpose: customer support. Legal basis: legitimate interests.
- Usage, device and technical data — IP address, browser and device type, pages viewed, feature usage, error reports and timestamps. Purpose: security and fraud prevention, keeping the Service reliable, and improving the product. Legal basis: legitimate interests.
- Marketing preferences — whether you have agreed to product emails. Purpose: marketing. Legal basis: consent, which you can withdraw at any time.
We do not sell your personal data and we do not use it to train third-party AI models.
3. AI processing
To generate recipes, plans and taste summaries we send your taste profile, fridge contents and briefs to AI model providers acting as our processors. This data is used solely to produce your results.
4. Who we share data with
- Service providers / sub-processors — cloud hosting, database and authentication providers, AI model providers, email delivery, error monitoring and analytics tooling, all bound by data-processing agreements.
- Merchant of Record — Paddle.com — Paddle handles the sale of our subscriptions, checkout, payment processing, subscription management, tax compliance, invoicing and refunds. Paddle acts as an independent controller for the checkout data it collects; see Paddle's privacy policy.
- Professional advisers — legal, accounting and insurance advisers where necessary.
- Authorities — where required by law, court order or to protect rights, safety and security.
- A successor — if the business is sold or merged, on the same terms as this notice.
5. International transfers
We are based in the United Kingdom. Some of our providers process data in the EEA and the United States. Where data leaves the UK or EEA we rely on the UK International Data Transfer Agreement / Addendum, EU Standard Contractual Clauses, or an adequacy decision (including the UK–US and EU–US Data Privacy Framework), together with additional safeguards where appropriate.
6. How long we keep data
- Account, taste and kitchen data: for as long as your account is open, then deleted or anonymised within 30 days of closure.
- Subscription and invoicing records: up to 7 years, to meet tax and accounting obligations.
- Support emails: up to 2 years after the matter is closed.
- Technical logs: typically 30–90 days.
When data is no longer needed for these purposes it is securely deleted or anonymised.
7. Your rights
Under UK GDPR and GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data rectified;
- have your data erased ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests and any direct marketing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting earlier processing;
- complain to a supervisory authority — in the UK the Information Commissioner's Office (ico.org.uk), or the authority in your EU member state.
To exercise any right email support@savor.app. We respond within one month (extendable by two further months for complex requests, in which case we will tell you). Many settings — taste preferences, fridge items, ratings and account deletion — can also be changed directly in your Profile.
8. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit (TLS) and at rest, row-level access controls so each account can only reach its own data, least-privilege access for administrators, and regular review of our providers. No system is perfectly secure; if we become aware of a breach affecting you we will notify you and the regulator as required by law.
9. Cookies and local storage
Savor uses only essential cookies and browser storage: a session token that keeps you signed in and, when you open checkout, cookies set by Paddle to run the payment form and prevent fraud. We do not currently use analytics or marketing cookies. If that changes we will ask for your consent first and let you manage your preferences in the app. You can clear or block cookies in your browser settings, though you will need to sign in again.
10. Children
Savor is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this notice
We may update this notice from time to time. Material changes will be announced in the app or by email before they take effect.