Privacy Policy
Salvio Health
Effective Date: June 7, 2026
Last Updated: June 7, 2026
This Privacy Policy describes how Salvio Health ("Salvio," "we," "us") collects, uses, and protects information when you use the Salvio API, documentation, dashboards, and related services (the "Service").
1. What We Collect
Account Information
When you create a Salvio account, we collect your email address, name, and organization name. If you subscribe to a paid plan, our payment processor collects billing information. We do not store credit card numbers on our servers.
API Usage Data
We log each API request for rate limiting, billing, debugging, and service improvement. Usage logs include: the endpoint called, HTTP method, response status code, response time, timestamp, and your API key identifier (not the full key). We do not log the content of API request parameters or response bodies.
Analytics
We use privacy-respecting analytics (no third-party trackers) on our website and documentation to understand page traffic. We do not collect or store personally identifiable information through analytics.
2. What We Do NOT Collect
We do not collect, store, or process any end-user health information. Salvio is a product data API. We return information about OTC products (ingredients, labels, equivalents). We do not receive or store:
- Patient names, health conditions, symptoms, or diagnoses
- Prescription information or medication histories
- Insurance or claims data
- Any Protected Health Information (PHI) as defined by HIPAA
If you send health-related information in API request parameters (e.g., a symptom query in the ingredient analysis endpoint), that information is processed in memory to generate the response and is not stored in our logs or databases.
3. Data Sources
Salvio product data is derived from publicly available U.S. government databases:
- OpenFDA NDC Directory — Product registry maintained by the U.S. Food and Drug Administration. Public domain.
- OpenFDA Drug Label API — FDA drug labeling data. Public domain.
- RxNorm — Clinical drug vocabulary maintained by the National Library of Medicine. Public domain.
We may also incorporate data from commercial barcode databases (e.g., Go-UPC) for UPC-to-product mapping. These integrations are governed by their respective terms of service.
No proprietary patient data, clinical trial data, or non-public pharmaceutical data is used in the Service.
4. How We Use Your Information
We use account and usage information to:
- Authenticate your API requests
- Enforce rate limits per your subscription tier
- Calculate billing for paid plans
- Monitor service health, detect errors, and investigate incidents
- Communicate important service updates (maintenance, policy changes, security notices)
- Improve the Service based on aggregate usage patterns
We do not sell your personal information. We do not use your information for advertising. We do not share your information with third parties except as described in Section 5.
5. When We Share Information
We share information only in these circumstances:
Service providers. We use Supabase (database hosting), Vercel (application hosting), and a third-party payment processor (payment processing). These providers access data only to perform their services and are bound by their own privacy commitments.
Legal requirements. We may disclose information if required by law, subpoena, court order, or government request, or if we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our users.
Business transfers. If Salvio is acquired, merged, or substantially all of its assets are transferred, your account information would be among the assets transferred. We would notify you before this occurs.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
6. Data Retention
Account information is retained while your account is active and for 12 months after account deletion, to support billing reconciliation and potential disputes.
API usage logs are retained for 90 days for operational purposes, then aggregated into anonymized monthly summaries. Aggregated summaries (total call counts, error rates) are retained indefinitely for trend analysis.
API keys are stored as SHA-256 hashes. The plaintext key is shown once at creation and is not stored by Salvio.
7. Data Security
We implement industry-standard security measures including:
- All API communication is encrypted via TLS 1.2+
- API keys are stored as irreversible cryptographic hashes (SHA-256)
- Database access is restricted via Row Level Security policies
- Infrastructure is hosted on SOC 2 certified providers (Supabase, Vercel)
- Administrative access requires multi-factor authentication
- We conduct regular security reviews of our codebase and dependencies
No system is perfectly secure. If we discover a security breach that affects your information, we will notify you via the email address on your account as promptly as practicable.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated data
- Export your usage data in a machine-readable format
- Object to certain processing activities
To exercise any of these rights, contact us at privacy@salvio.health. We will respond within 30 days.
California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To make a CCPA request, email privacy@salvio.health.
European Residents (GDPR)
If you are located in the European Economic Area, our legal basis for processing your information is: (a) performance of our contract with you (account management, billing); (b) legitimate interests (service improvement, security); and (c) compliance with legal obligations. You may contact us to exercise your rights under GDPR, including the right to lodge a complaint with your local data protection authority.
9. Cookies
The Salvio API does not use cookies. Our website and documentation may use essential cookies for session management (login state). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
10. Children
The Service is not directed at individuals under the age of 16. We do not knowingly collect information from children. If you believe we have inadvertently collected information from a child, please contact us and we will delete it promptly.
11. International Data Transfers
Salvio is based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States. We rely on standard contractual clauses and data processing agreements with our service providers to ensure appropriate safeguards for international transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The "Last Updated" date at the top of this policy indicates the most recent revision.
13. Contact
For questions about this Privacy Policy or to exercise your data rights:
Email: privacy@salvio.health
Contact: Salvio Health — privacy@salvio.health (postal address available on request)
For data protection inquiries from the EU, you may also contact our data protection contact at dpo@salvio.health.