#1. Who is responsible for your data
Savesta is an Android application operated by an independent developer based in India ("Savesta", "we", "us", "our"). For the purposes of the EU and UK General Data Protection Regulation ("GDPR" / "UK GDPR"), we are the data controller for the personal data described in this policy.
For all privacy inquiries, data-subject requests, or concerns about our data practices, contact our designated privacy lead at contact.savesta@gmail.com. We respond within 30 days.
Savesta is not affiliated with, endorsed by, or sponsored by Instagram, Facebook, WhatsApp, Threads, Meta Platforms Inc., TikTok, ByteDance, Reddit, Pinterest, LinkedIn, X (Twitter), or any other platform whose links you may use with Savesta.
#2. The short version
- We do not ask you to create an account with us.
- We do not sell your personal data.
- Files you download stay on your device. We do not receive a copy and we cannot read them.
- A limited set of technical data — crash reports, device model and OS, an advertising identifier, and an installation identifier — is sent to Google services such as Google Play Services, AdMob, Google Analytics for Firebase, and Firebase Crashlytics so we can run the app, fix crashes, and show ads. Detail in Section 4.
- Advertising shown in the app is delivered through a Google advertising service and a small set of third-party advertising partners. Those partners may build advertising profiles across multiple apps. Under California's CPRA this is considered "sharing" of personal information; we disclose it here and on the Google Play Data Safety form.
- You can email us at contact.savesta@gmail.com at any time to access, correct, or delete the data we hold about you, or to opt out of ad personalization. We act within 30 days.
- Phone numbers entered in the WhatsApp direct-message tool are used only to open WhatsApp on your device. We do not store those numbers and we do not send them to our servers.
#3. Scope, definitions, and what we do not collect
"Personal data" or "personal information" means any information relating to an identified or identifiable person, including online identifiers such as an advertising ID or device ID. "Processing" means any operation performed on that data (collection, storage, use, sharing, deletion, etc.).
Savesta does not knowingly collect any of the following: financial or payment information, government-issued identifiers, biometric data, health or genetic data, precise device location (GPS), contacts, calendar, microphone audio, camera imagery, or SMS messages. If any of these categories are ever introduced, this policy will be updated.
We also do not create Savesta user accounts, maintain a server-side profile of you, or store phone numbers and messages entered into the WhatsApp direct-message tool.
#4. What we collect, why, and on what legal basis
4.1 Information you actively provide
Email correspondence. If you write to us, we process the contents of your message so we can reply.
WhatsApp direct-message details. If you enter a phone number or message in the WhatsApp direct-message tool, that information is used only on your device to open WhatsApp. We do not store it or send it to our servers.
Legal basis (GDPR Art. 6): legitimate interest in responding to your inquiries and providing user-requested app features.
4.2 Information collected automatically by service providers
The app embeds a small set of operational services from Google, including Google Play Services, AdMob, Google Analytics for Firebase, and Firebase Crashlytics. Each collects information directly from your device for its own purposes and is bound by its own privacy policy in addition to ours.
Google Analytics for Firebase
- Data: your device's standard advertising identifier, an anonymous installation identifier, your IP address (used to approximate region and then discarded by the service), device model and operating system, app version, and the names of features and screens you use.
- Purpose: understanding which features are actually used so we can decide what to improve.
- Legal basis: legitimate interest in improving our product where permitted by law.
Firebase Crashlytics
- Data: an anonymous installation identifier, device model and operating system, app version, the crash information (call stack and error message), and the state of the app at the time of failure (such as whether it was in the foreground). Crash reports may include technical context needed to diagnose a failure, but they do not include files you save through the app.
- Purpose: diagnosing crashes and failures so we can fix them.
- Legal basis: legitimate interest in fixing bugs. You may object at any time by emailing us (Section 10).
AdMob advertising
- Data: your device's standard advertising identifier, IP address (used to approximate country and language), device type and operating system, app version, and ad impression and tap events.
- Purpose: selecting and measuring the ads shown in the app, which is how the app stays free.
- Legal basis: legitimate interest in funding a free app where allowed by law. You can opt out of personalized advertising via Android Settings > Privacy > Ads where your Android version provides that control.
- Reference: policies.google.com/technologies/ads.
Advertising partners
Some ad requests may be routed to advertising partners selected through our primary advertising service. These partners may use the data they receive to select, deliver, and measure ads. Depending on your location, this may be treated as "sharing" of personal information for advertising purposes even though we do not sell personal data for money. You can object by emailing us (Section 10) or by resetting your Advertising ID in Android Settings.
Google Play Services, Play Integrity, and website anti-abuse
- Data: a one-time anti-abuse check provided by your device's Play Services that confirms the request comes from a genuine, unmodified copy of the app on a genuine device. We receive a verdict, not personal information. On the website, we also use Cloudflare Turnstile to verify that download requests are not automated abuse; Cloudflare may process device, browser, network, and challenge-response information for that purpose.
- Purpose: protecting our service from automated abuse and fraudulent traffic.
- Legal basis: legitimate interest in security and fraud prevention.
Third-party service policies
These providers maintain their own privacy terms and controls:
- Google Privacy Policy for Google Play Services and related Google products: policies.google.com/privacy.
- AdMob advertising privacy information: policies.google.com/technologies/ads.
- Firebase privacy and security information for Google Analytics for Firebase and Firebase Crashlytics: firebase.google.com/support/privacy.
- Cloudflare privacy information for Turnstile and website security: cloudflare.com/privacypolicy.
4.3 Links and content you process through the app
When you paste a link, the app on your device contacts the public servers of the platform that hosts the content (for example, instagram.com). The remote platform receives the same request information any web browser would send — primarily your IP address, device user-agent, and the link you pasted. We are not a party to that exchange; the remote platform's own privacy practices apply to it.
If a supported link needs server-side or third-party resolution, the public link you pasted may be sent to a resolver service or to an API we operate. We use that link to return downloadable media information and not to build a profile about you.
Our website downloader also sends the pasted link and a Cloudflare Turnstile token to our API so we can resolve the media and prevent automated abuse.
4.4 Files you save
Files you save are written directly to your device's public Downloads folder using Android's standard media-storage system. We do not receive copies. The "Saved" list inside the app is a local index stored on your device and is deleted when you uninstall.
4.5 WhatsApp tools
The Status Saver feature reads files only from the folder you explicitly grant access to through Android's storage permission dialog. We do not access WhatsApp messages, contacts, media outside that folder, or any other WhatsApp data.
The "send direct message" tool composes a standard WhatsApp deep link and hands it to the WhatsApp app on your device. The phone number and any message you type are used solely for navigation to WhatsApp, processed entirely on your device, and passed directly to WhatsApp's own software. We do not store, log, or share the phone number or message, and they never reach our servers.
#5. EEA, UK, and Swiss users — consent and choices
The current app version does not include an in-app Google-certified consent prompt or a dedicated in-app privacy-options screen. If we add an in-app consent flow later, we will update this section.
Until then, users in the European Economic Area, the United Kingdom, and Switzerland should use device-level and Google-level controls to manage ad personalization:
- Reset or delete your Android Advertising ID from Android Settings > Privacy > Ads.
- Turn off ad personalization where your Android version and Google account settings provide that control.
- Email us at contact.savesta@gmail.com if you want to object to personalized advertising or ask what data we can delete or request deletion for.
This policy does not claim that you can change ad consent inside Savesta today. You may still see contextual, non-personalized, or limited ads.
#6. How long we keep your data
- Analytics events: retained by the analytics provider according to its settings and published policies.
- Crash reports: retained by the crash-reporting provider according to its settings and published policies.
- Advertising measurement data: retained by the ad service according to its published policy.
- Files you save through the app: entirely on your device. Retained as long as you keep them.
- Email correspondence with us: retained for up to 24 months from the last message in the thread, then deleted, unless the correspondence relates to an active legal claim.
- Data-deletion requests: when you ask us to delete data we hold, we aim to act within 30 days.
#8. International transfers
Our service providers operate infrastructure in multiple countries, including the United States and the European Union. By using the app, your data may be transferred outside your country of residence.
Where privacy law requires safeguards for international transfers, we rely on the safeguards made available by our service providers, such as their data-processing terms, transfer addenda, or other lawful transfer mechanisms.
#9. Children
Savesta is not directed to children, and we do not knowingly collect personal information from children whose use is restricted by their local children's privacy law.
- United States (COPPA): we do not knowingly collect personal information from children under 13.
- European Economic Area and UK (GDPR-K): users under 16 (or under the lower age set by your EU member state, but never below 13) should not use the app without verifiable parental consent.
- India (DPDPA 2023): processing of personal data of children may require parental consent. Savesta does not require accounts, so we cannot independently verify a user's age at install time. If we learn that we hold personal data from a child without the required consent, we will delete it.
If you are a parent or guardian and believe a child is using the app, email contact.savesta@gmail.com. We will review the request and delete any data we hold about the installation within a reasonable time.
#10. Your rights
Depending on where you live, you may have some or all of the following rights:
- Access — ask us what data we hold about you.
- Correction — ask us to fix inaccurate data.
- Deletion — ask us to delete data we hold about you ("right to erasure" / "right to be forgotten").
- Restriction — ask us to stop processing your data while a dispute is resolved.
- Portability — ask for a copy of your data in a machine-readable format.
- Objection — object to processing that is based on legitimate interest, including direct marketing.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time (this does not affect prior processing).
- Opt out of "sale" or "sharing" (CCPA / CPRA) — although we do not sell data, mediation may qualify as "sharing"; you may opt out as described in Section 7.
To exercise any of these rights, email contact.savesta@gmail.com with enough detail to identify what you are asking about. We aim to respond within 30 days, or sooner if local law requires it.
You also have the right to complain to a supervisory authority:
- EEA users: your country's national data protection authority (list at edpb.europa.eu).
- UK users: the Information Commissioner's Office (ico.org.uk).
- California users: the California Privacy Protection Agency (cppa.ca.gov).
#11. Security
We protect your data using industry-standard measures:
- All network traffic between the app, the website, and our service is encrypted in transit.
- Our service uses anti-abuse checks provided by your device's Play Services to confirm that requests come from genuine, unmodified copies of the app.
- Access to operational data is limited to the operator and protected with multi-factor authentication.
No system is perfectly secure. If we become aware of a personal data breach, we will take appropriate steps required by applicable law. If you believe you have found a vulnerability, please disclose it responsibly to contact.savesta@gmail.com with the subject line "Security report".
#13. Automated decision-making
We do not use your personal data for any automated decision-making, profiling, or eligibility scoring that produces legal effects concerning you or similarly significantly affects you. Ad-mediation routing is operational only and does not produce legal effects.
#14. Copyright and your use of the app
Savesta is a tool you control. You are responsible for what you download with it. By using the app you confirm that you have the right to download the content you process. For copyright concerns about content downloaded through the app, or about the app and website themselves, see our Copyright / DMCA page for the takedown process.
#15. Business changes
If the Savesta app or website is ever transferred, sold, or merged into another organisation, personal data we hold may be transferred as part of that transaction, subject to this policy or a successor policy. We will update this page if such a change happens.
#16. Changes to this policy
We may update this policy when the app changes or when the law changes. The "Last updated" date at the top of this page is bumped whenever we make a material change. If the change is significant (for example, adding a new category of data or a new processor), we will update this page and may notify users through the app or website when appropriate.
Previous versions of this policy are available on request via email.
#17. Contact
For privacy questions, data requests, or to withdraw consent: contact.savesta@gmail.com.
For copyright concerns, please use the dedicated Copyright / DMCA page.
General terms of use are in our Terms of Use.