Transparency
Putting an AI in front of your customers is a matter of trust, so this page explains in plain English what the privacy policy says in legal terms: what information SaviaIA uses, who else sees it, how long it's kept and what we don't do. If anything here contradicts the policy, the policy prevails — and please tell us, because it means we've made a mistake.
Where your assistant's knowledge comes from
From your information, and nowhere else. There's no general knowledge base behind it filling in the gaps.
The public content of your website. It's read by a crawler that identifies itself as SaviaIA-Crawler and respects robots.txt. If a firewall blocks us, we don't work around it: we ask the site owner for express authorisation and we log it.
The documents you upload: PDF, DOCX, TXT or MD. Only the extracted text is stored, never the original file.
The answers you add by hand when you see that the assistant didn't know something.
There are no connectors to Drive, Notion, a CRM or any external knowledge base.
PDFs found while crawling your public website are not ingested on their own. Uploading them is your decision.
What happens when it doesn't know something
It says so and hands over to a person, using the contact details you've configured. This is a system instruction, not a sales promise: we'd rather it said "I don't know" too often than fill the gap with something plausible.
Before going live, a person reviews the company profile and the visual identity. The automated process doesn't activate anything on its own.
You can see every conversation, every lead captured and which questions went unanswered.
Your customer knows they're talking to an AI
The assistant states what it is. From 2 August 2026, Article 50 of the European Artificial Intelligence Regulation requires people to be informed that they are interacting with an AI system, unless it is obvious. SaviaIA complies by default and we offer no option to hide it.
It doesn't impersonate a named person or pretend to be an employee.
When it's time to hand over to a human, it says so and does it.
What is stored about the people who talk to the assistant
Just what you need to read the conversation and reply to whoever left their contact details. Nothing else.
The full messages of the conversation, with their token count.
The contact details the person provides: name, email, phone.
A hash of the IP address and the user agent. The IP is not stored in the clear.
Marketing consent, with its date, where it is requested.
There is no account or password for visitors to the assistant: the URL is public.
Who else sees this data
No provider on this list is optional for the service you have signed up for, and none of them use your data to train their own models. If that changes tomorrow, this table changes.
| Provider | What for | What it receives |
|---|---|---|
| Anthropic | The model that writes the chat replies | Your content and the conversation messages |
| Google (Gemini) | Extracting the company profile when setting up the assistant | The crawled content of your website |
| Google (OAuth and Calendar) | Signing in with Google and booking appointments | Your email; and calendar events if you connect the integration |
| Stripe | Subscription billing | Your billing and payment details |
| Telnyx | Phone channel | Call audio and metadata |
| Meta (WhatsApp Cloud API) | WhatsApp channel | Messages and phone number |
| Email provider | Transactional emails | Recipient and email content |
What we don't do
This list matters as much as the one above, and we keep it even when it doesn't help us commercially.
We don't sell or share your data with anyone, nor the data of the people who talk to your assistant.
We don't use your content to train models, either ours or third parties'.
There's no black box: you can export your conversations and your contacts, and delete them for real.
The list of domains where your widget can run is hygiene, not security: the header that controls it is trivial to spoof. We don't sell it to you as access control.
Any plan caps other than monthly conversations are commercial commitments, not limits the system enforces today.
We don't have a mobile app, or a dedicated subdomain per customer.
Timelines and figures, unrounded
Embeddings and voice-note transcription
Processed on our own servers. No data goes to a third party for this.
Channel events (WhatsApp, email)
Deleted after 180 days.
Conversations and messages
Today they are not deleted automatically. They are deleted when you ask, and they are really deleted. We would rather say it plainly than promise a timeframe we don't yet apply.
Documents you upload
Kept until you delete them.
Everything belonging to an assistant
Deleted in cascade when the assistant is deleted.
Your rights
Export and deletion are implemented and available from your panel — not an email address you write to and then wait.
The legal detail
This page is an honest summary, not the legally binding document. What binds are the privacy policy, the terms and conditions, the cookie policy and the legal notice.
Is something missing here?
If you can't find a figure or something isn't clear, write to us and we'll add it. A transparency page with gaps defeats its own purpose.
Contact