← Back to Salvio

Privacy Policy

Salvio Health
Effective Date: June 7, 2026
Last Updated: August 14, 2026

This Privacy Policy describes how Salvio Health ("Salvio," "we," "us") collects, uses, and protects information when you use the Salvio API, documentation, dashboards, and related services (the "Service").

1. What We Collect

Account Information

When you create a Salvio account, we collect your email address, name, and organization name.

Payment Information

We do not sell subscriptions and we do not use a payment processor, so we never collect or store billing information, card numbers, or bank details — there is nothing of that kind to collect.

Requests paid per call use the x402 protocol, which settles on a public blockchain. For each such payment we record the paying wallet address, the amount, the endpoint requested, and the resulting transaction reference. A wallet address is a pseudonymous identifier: it is not linked to a Salvio account and we do not attempt to identify the person behind it. Note that the payment itself is recorded on a public blockchain by design — that record is outside our control and cannot be deleted by us or by you.

API Usage Data

We log each API request for rate limiting, billing, debugging, and service improvement. Usage logs include: the endpoint called, HTTP method, response status code, response time, timestamp, and your API key identifier (not the full key). We do not log the content of API request parameters or response bodies.

Analytics

We use Google Analytics on our website and documentation to understand page traffic — which pages are read, which sites refer visitors, and roughly where in the world visitors are. This tells us which documentation is worth expanding. We do not use it for advertising, we do not run ad-personalisation or remarketing, and we do not sell or share the data.

Google Analytics sets cookies in your browser. In the UK, the EEA, and Switzerland it does not run at all unless you accept it — no analytics cookie is set and no data is sent to Google before you choose. Elsewhere it is on by default and you can turn it off at any time. Either way you can change your mind whenever you like using the Cookie preferences link below and in the site footer. See section 9 for the detail.

The Salvio API itself carries no analytics. Nothing described here applies to API or MCP requests.

2. What We Do NOT Collect

We do not collect, store, or process any end-user health information. Salvio is a product data API. We return information about OTC products (ingredients, labels, equivalents). We do not receive or store:

  • Patient names, health conditions, symptoms, or diagnoses
  • Prescription information or medication histories
  • Insurance or claims data
  • Any Protected Health Information (PHI) as defined by HIPAA

If you send health-related information in API request parameters (e.g., a symptom query in the ingredient analysis endpoint), that information is processed in memory to generate the response and is not stored in our logs or databases.

3. Data Sources

Salvio product data is derived from publicly available U.S. government databases:

  • OpenFDA NDC Directory — Product registry maintained by the U.S. Food and Drug Administration. Public domain.
  • OpenFDA Drug Label API — FDA drug labeling data. Public domain.
  • RxNorm — Clinical drug vocabulary maintained by the National Library of Medicine. Public domain.

We may also incorporate data from commercial barcode databases (e.g., Go-UPC) for UPC-to-product mapping. These integrations are governed by their respective terms of service.

No proprietary patient data, clinical trial data, or non-public pharmaceutical data is used in the Service.

4. How We Use Your Information

We use account and usage information to:

  • Authenticate your API requests
  • Enforce rate limits — per API key, per IP address for anonymous requests, or per wallet for requests paid per call
  • Verify and settle per-call payments, and prevent a payment being spent twice
  • Monitor service health, detect errors, and investigate incidents
  • Communicate important service updates (maintenance, policy changes, security notices)
  • Improve the Service based on aggregate usage patterns

We do not sell your personal information. We do not use your information for advertising. We do not share your information with third parties except as described in Section 5.

5. When We Share Information

We share information only in these circumstances:

Service providers. We use Supabase (database hosting), Vercel (application hosting), the Coinbase Developer Platform (settlement of per-call x402 payments — see section 1), and Google (website analytics, where you have accepted analytics cookies — see section 9). These providers access data only to perform their services and are bound by their own privacy commitments.

Legal requirements. We may disclose information if required by law, subpoena, court order, or government request, or if we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our users.

Business transfers. If Salvio is acquired, merged, or substantially all of its assets are transferred, your account information would be among the assets transferred. We would notify you before this occurs.

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

6. Data Retention

Account information is retained while your account is active and for 12 months after account deletion, to support billing reconciliation and potential disputes.

API usage logs are retained for 90 days for operational purposes, then aggregated into anonymized monthly summaries. Aggregated summaries (total call counts, error rates) are retained indefinitely for trend analysis.

API keys are stored as SHA-256 hashes. The plaintext key is shown once at creation and is not stored by Salvio.

7. Data Security

We implement industry-standard security measures including:

  • All API communication is encrypted via TLS 1.2+
  • API keys are stored as irreversible cryptographic hashes (SHA-256)
  • Database access is restricted via Row Level Security policies
  • Infrastructure is hosted on SOC 2 certified providers (Supabase, Vercel)
  • Administrative access requires multi-factor authentication
  • We conduct regular security reviews of our codebase and dependencies

No system is perfectly secure. If we discover a security breach that affects your information, we will notify you via the email address on your account as promptly as practicable.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your usage data in a machine-readable format
  • Object to certain processing activities

To exercise any of these rights, contact us at privacy@salvio.health. We will respond within 30 days.

California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To make a CCPA request, email privacy@salvio.health.

European Residents (GDPR)

If you are located in the European Economic Area, the UK, or Switzerland, our legal basis for processing your information is: (a) performance of our contract with you (account management, billing); (b) legitimate interests (service improvement, security); (c) compliance with legal obligations; and (d) your consent, which is the sole basis on which we run website analytics in these regions. You may withdraw that consent at any time using the Cookie preferences link, with no effect on anything processed before you withdrew it. You may contact us to exercise your rights under GDPR, including the right to lodge a complaint with your local data protection authority.

9. Cookies

The Salvio API does not use cookies. API and MCP requests are authenticated by key and set nothing in your browser. What follows applies only to the website and documentation.

Essential cookies keep you signed in and keep the site secure. They cannot be switched off, and we also use one short-lived cookie to remember which consent rules apply to your region.

Analytics cookies are set by Google Analytics and measure page traffic. In the UK, the EEA, and Switzerland these are set only after you accept them; until then the Google script is never loaded. Elsewhere they are on by default and you can switch them off. We use no advertising cookies and no cross-site tracking cookies at all.

To change your choice at any time, use Cookie preferences. Withdrawing consent stops any further analytics collection immediately.

10. Children

The Service is not directed at individuals under the age of 16. We do not knowingly collect information from children. If you believe we have inadvertently collected information from a child, please contact us and we will delete it promptly.

11. International Data Transfers

Salvio is based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States. We rely on standard contractual clauses and data processing agreements with our service providers to ensure appropriate safeguards for international transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The "Last Updated" date at the top of this policy indicates the most recent revision.

13. Contact

For questions about this Privacy Policy or to exercise your data rights:

Email: privacy@salvio.health
Contact: Salvio Health — privacy@salvio.health (postal address available on request)

For data protection inquiries from the EU, you may also contact our data protection contact at dpo@salvio.health.

← Back to Salvio