Savy Privacy Policy
Effective Date: August 20, 2026 (Updated September 2026) • Privacy First
Welcome to Savy (a product by Myshic, accessible at myshic.com and savy.myshic.com).
Savy is built from the ground up on a strict privacy-first architecture. Our mission is to empower users with transparent internet quota savings, community-driven network accountability, and real-time connectivity intelligence — without collecting personal browsing activity or selling user information.
Our Core Commitment: We do not track the websites you visit, we do not log your browsing history, we never persist raw GPS coordinates on disk, and we never sell, rent, or monetize your personal data.
1. Scope of This Policy
This Privacy Policy applies to all applications, services, and platforms under the Savy and Myshic ecosystem, including:
- Savy Web Dashboard (savy.myshic.com) — Broadband intelligence, global speed tests, and regional connectivity maps.
- Savy Browser Extension (Chrome Web Store / Chromium) — Local bandwidth optimizer, ad/tracker blocker, and WebRTC leak protector.
- Savy Desktop Application — Native connection monitor and local network diagnostics.
- Myshic Portal & Integrations (myshic.com) — Account management and community infrastructure tools.
2. What We Do NOT Collect
To protect user privacy and prevent mass surveillance, Savy operates under strict technical guardrails:
- No Browsing History: Savy never logs, tracks, or transmits the domains, URLs, or web pages you visit.
- No Search Queries or Form Data: We never capture keystrokes, form inputs, or search queries.
- No Raw GPS Persistence: Raw latitude and longitude coordinates are never saved to disk, never written to databases, and never exposed publicly.
- No Public Raw IP Exposure: Raw IP addresses are never displayed on public dashboards, never shown on maps, and never exposed in public API views.
- No Data Monetization or Profiling: We do not sell, rent, or trade your data to third-party data brokers, marketers, or advertisers.
3. Google User Data & OAuth 2.0 Policy (Google Trust & Safety Compliance)
Savy offers optional account authentication via Google Sign-In (OAuth 2.0), managed securely through Supabase Authentication. When you choose to sign in with Google:
A. Information We Access
We request only basic, non-sensitive identity scopes (openid, email, profile): your name, email address, profile avatar URL, and unique Google user identifier.
B. How We Use Google User Data
Information obtained via Google OAuth is used strictly to:
- Authenticate your Savy account.
- Maintain your secure login session across devices.
- Associate your personal speed test history and quota saving preferences in your private MY SAVY dashboard.
C. Storage & Protection
Google account identifiers and profile metadata are stored in an encrypted database infrastructure (Supabase Auth). All network communication is enforced over TLS 1.3 / HTTPS. We never access your Google password or private Google Workspace files.
D. Google API Services Limited Use Disclosure
Google Limited Use Compliance: Savy’s use and transfer to any other app of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
- We do not transfer Google user data to external parties, except as necessary to provide or improve Savy's user-facing functionality.
- We do not use or transfer Google user data for serving advertisements, including personalized or retargeted advertising.
- We do not allow humans to read Google user data unless we have your affirmative consent, or as required for security investigations or applicable law.
4. Data Handled by Savy Services
A. Savy Browser Extension (Local Storage)
The Savy browser extension executes bandwidth savings algorithms (prefetch blocking, image optimization, and WebRTC leak protection) locally on your device. Savings metrics (e.g. megabytes saved, requests blocked) are stored locally in chrome.storage.local. This data remains on your device and is never transmitted unless you explicitly opt in to aggregate reporting.
B. Speed Test Telemetry (Opt-In & Anonymous)
When you run a speed test on savy.myshic.com with telemetry enabled:
- Metrics Recorded: Download speed (Mbps), upload speed (Mbps), latency (ping in ms), jitter (ms), and optional connection medium (Wi-Fi, Ethernet, Cellular).
- Geographic Placement: Coarse administrative district name, standard administrative boundary identifier (e.g., ADM3 administrative codes such as EG211701 or regional municipality codes like TR-34), and country code (ISO).
- Session Identifier: A salted cryptographic hash (
session_hash) used to compute rolling averages and deduplicate consecutive tests without exposing device identity.
- Submitter IP Address & Retention: Raw IP addresses (
submitter_ip on speed tests and client_ip on outage reports) are collected server-side strictly for rate-limiting (10 tests/hour for anonymous, 30/hour for authenticated users within a 1-hour lookback window) and anti-abuse verification. Raw IPs are stored in protected operational tables, are never exposed publicly or in client dashboards/APIs, and are automatically purged to NULL on a rolling 30-day window by an automated daily database job (pg_cron running daily at 03:00 UTC).
C. Outage & Incident Reports
Users can submit community connection alerts (e.g. total blackout, packet loss, high latency) for their local Internet Service Provider (ISP). Reports contain the ISP name, issue category, timestamp, coarse district/city, client IP (for anti-abuse rate-limiting, never published, purged after 30 days), and community upvote confirmations.
5. Geofencing, GPS Verification & Location Privacy
To ensure benchmark accuracy while preserving physical location privacy:
- When you initiate location verification via mobile GPS or phone QR sync, coordinates (latitude, longitude, and accuracy radius) are transmitted over an encrypted TLS connection directly to our verification edge function.
- Our servers perform point-in-polygon ray-casting against official administrative boundary polygons to determine the verified district P-code and enforce anti-spoofing distance checks against the IP routing range.
- Once verified, raw latitude and longitude coordinates are immediately purged from server memory.
- No raw latitude or longitude columns exist in our database (
speed_tests, outage_reports, and verification_sessions store only the resolved administrative district identifier and country code, e.g. standard UN OCHA P-codes).
6. Data Retention and Account Deletion
We retain user account records and associated telemetry only as long as necessary to provide services and maintain aggregated network intelligence:
- Self-Service Account Deletion: You have the absolute right to delete your account and personal data at any time. Savy provides an immediate, self-service account deletion flow directly inside Settings (under Security & Auth > Danger Zone), requiring double confirmation by typing your email or "DELETE".
- Atomic Purge Execution: Deletion executes an atomic database procedure (
delete_user_account()) that instantly and permanently purges your authentication record, credentials, OAuth links, linked identities, hardware trust tokens, and private settings. Any multi-device household you own is transferred to the next active member (or deleted if you are the sole member).
- Preservation of Community Telemetry: Community telemetry contributions (
speed_tests, outage_reports, isp_override_reports) are permanently anonymized with their user_id set to NULL, preserving public community benchmarks without any connection to your identity.
- Backup Retention Window: Live database rows are purged immediately upon confirmation. Pre-existing database snapshots and backups retain records only until they age out on a rolling schedule (7 to 30 days depending on infrastructure tier).
- Fallback Email Option: Users may also request account and data deletion by emailing us at privacy@myshic.com or savyeg.myshic@gmail.com as a fallback contact method, processed within 30 days.
7. Third-Party Infrastructure Providers
We partner with infrastructure providers who adhere to strict data protection standards:
- Supabase: Encrypted PostgreSQL database hosting, authentication, and secure edge functions.
- Cloudflare & Fastly: Edge network delivery, DDoS mitigation, and latency measurement endpoints.
- CARTO & OpenStreetMap: Map tile delivery for geographic visualizations.
8. Children's Privacy (COPPA Compliance)
Savy is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us immediately for prompt deletion.
9. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect technical enhancements or legal standards. When modifications are made, the "Effective Date" at the top of this document will be updated. We encourage users to review this policy periodically.