V2 Labs Limited · Savewise
Privacy Policy
Last updated: October 9, 2026
This policy explains how V2 Labs Limited (“V2 Labs”, “we”, “us”) handles personal data when you use Savewise, our personal savings wallet. It applies to the Savewise website, mobile app, and Gmail connection.
1. Controller and contact
V2 Labs Limited is the data controller for Savewise. Our registered address is Apelli 14, 1080 Nicosia, Cyprus. Our authorized representative is Viktor Holter. For privacy questions or requests, email hello@playwinnly.com.
2. Information we access
Account information
Supabase Auth processes your sign-in information, including your email address and account identifier. Savewise uses an internal account identifier to keep each person's wallet data separate.
Wallet information
Savewise stores offers that you enter or import. Offer fields can include brand, title, merchant, promo code, discount value, currency, start and expiry dates, eligibility, conditions, source, and status. Savewise also stores actions such as favorite, hidden, and used.
Google account and Gmail information
When you connect Gmail, you authorize the Gmail read-only scope https://www.googleapis.com/auth/gmail.readonly. Google provides the Gmail account address, granted scope, token expiry, and history data needed to sync. Savewise does not ask for your Google password or one-time passcodes.
The initial search covers up to the previous 12 months. Later syncs use Gmail history to find new messages. Savewise first checks message metadata and a short Gmail snippet. It fetches plain-text content only for messages that match offer-related filters. It does not download or extract attachments.
For each checked message, Savewise can store its message ID, thread ID, sender, subject, received date, message processing status, and a content hash. An extracted offer can include a source excerpt of up to 1,000 characters. A candidate plain-text body can contain up to 20,000 characters.
Technical information
Our hosting providers may process standard service data such as request times, IP addresses, device or browser details, and error events. Savewise application logs are designed not to include Gmail message bodies or OAuth token values.
3. How we use Google user data
We use Gmail data only to provide user-facing Savewise features that you request. These features include finding discount-related messages, extracting offer details, preserving each offer's source and conditions, and keeping your wallet current.
For an eligible candidate message, Savewise sends the sender, subject, received date, and plain-text body to OpenRouter to return structured offer details. The application sends this data only for that extraction. It does not use Google user data for advertising, credit decisions, data brokerage, or training generalized or non-personalized AI/ML models.
OpenRouter requests require data-collection denial and zero-data-retention routing. The application fails closed when it cannot use an eligible route. We have not processed real inbox content in the current test setup.
V2 Labs Limited's use and transfer of information received from Google APIs is limited to providing the user-facing Savewise features that you request and follows the Google API Services User Data Policy, including its Limited Use requirements.
4. Information stored by Savewise
Savewise does not store complete email bodies in its database. It stores the email metadata, content hash, short source excerpt, and extracted offer details described above. Candidate email text is processed for extraction and is not written to the Savewise database.
Savewise encrypts Gmail access and refresh tokens with AES-256-GCM before it stores them. The database also stores account, offer, source, notification, and sync-job records needed to provide the wallet.
5. How we use other information
We use account information to authenticate you and secure your account. We use wallet information to display, search, sort, and manage offers. We use technical information to operate, maintain, and protect Savewise, and to investigate service errors.
6. Who receives information
We share information only with service providers that help us provide or secure Savewise:
- Google: authenticates your Gmail connection and provides Gmail API access.
- Supabase: provides account authentication and the Savewise database.
- Render: hosts the Savewise API.
- Vercel: hosts this website and forwards the Google authorization response to the API callback. The callback code does not log the Google authorization code or state.
- OpenRouter: processes candidate email text only when extraction is enabled, to return structured offer details.
We do not sell Google user data or disclose it for advertising. We do not share it with data brokers or information resellers. Providers may process service data under their own terms and in locations outside the European Economic Area. The Savewise database is configured in the EU Central region, and the API is hosted in Frankfurt.
7. Retention and deletion
- OAuth tokens: kept while Gmail is connected. When you disconnect Gmail, Savewise attempts to revoke the refresh token, clears stored tokens, and stops queued sync jobs.
- Imported email metadata and offers: kept until you delete imported Gmail data or delete your Savewise account. Disconnecting Gmail alone does not delete existing imported offers or source details.
- Manual offers: kept until you delete them or delete your account.
- Candidate email text: not stored in the Savewise database. It is sent in the extraction request described above and discarded by the application after processing.
To delete imported Gmail data, first disconnect Gmail and then use the delete-imported-data control. Savewise deletes Gmail source records, email metadata, sync jobs, and offers that have no other source. An offer that also has another source remains with that source. Account deletion removes your Supabase Auth account and associated Savewise records.
Hosting providers may retain operational logs and backups under their own retention policies. V2 Labs Limited does not control those provider retention periods.
8. Security
Savewise uses HTTPS for hosted network connections, one-time OAuth state values, user-scoped database operations, and AES-256-GCM encryption for Gmail tokens. No online service can guarantee absolute security. Keep your Google account secure and review its connected-app access.
9. Your choices and rights
You can disconnect Gmail, delete imported Gmail data, delete individual offers, or delete your Savewise account in the app. You can also revoke Savewise's access from your Google Account settings.
Depending on your location and applicable law, you may have the right to request access, correction, erasure, restriction, or portability of your personal data, or to object to some processing. Contact hello@playwinnly.com. You may also lodge a complaint with your local data protection authority.
10. Website storage and policy changes
The Savewise landing page has no signup form, analytics script, or advertising script. Hosting providers may collect basic operational request logs. We will update this policy when our data practices change and will notify users when the law requires it.