# Savva: CAIHL reassessment

September 8, 2026. Published AI-assisted draft.

Savva offers local models and separately selected cloud-provider queries, with model and context choices. Shared API keys do not make record contents anonymous. Optional cloud processing and metadata retention qualify broader local-only and anonymity claims.

## Scope and agency posture

Local record app with on-device AI and separately selected cloud-provider queries. Shared API credentials do not make record contents anonymous.

Posture: **Potentially agency-expanding**.

Axis: 78/100, retained provisionally. No numerical recalibration was performed.

## Sources and documented findings

- The current homepage offers local models and provider-specific cloud consent, model switching and context-size control. It says shared API-key traffic is anonymous and also uses broad no-cloud language despite optional cloud processing. https://www.savva.ai/

- The privacy policy documents instance/device identifiers, diagnostic and security logs, retained billing records, optional health-data transfers and support exceptions. These qualify the homepage's no-identity and no-cloud slogans. https://www.savva.ai/legal/privacy

- Terms retain a vendor-controlled content framework and refer linked health-data processing to the privacy policy. No hands-on export or output-license resolution was established. https://www.savva.ai/legal/terms

## Patient authority

Inference from the documented workflow: Choice of models, local execution and context size give users meaningful control over analysis. Switching models does not itself establish a way to correct extracted records or resolve conflicting advice.

## Critical capacity

Editorial assessment: Comparing interpretations can prompt useful questions when users can inspect original records. Agreement between models is not validation.

## Informed control

Editorial assessment: An API key identifies the application, not necessarily the patient, but health-record content may identify them. Provider choice must include that distinction and policy retention exceptions.

## Assessment and limits

Keep the potentially positive placement while correcting overly absolute anonymity and local-only claims. Current marketing is more developed than the pre-launch baseline, but actual availability was not installed or tested.

Confidence: Moderate for current documented choices, limited for runtime behavior.

Remaining uncertainty: Actual local/cloud boundaries, export, derived-data correction and provider retention remain unverified

Published documentation is evidence of stated conditions, not proof of actual implementation. Unknowns did not receive automatic negative points. Funding, sponsorship, and public code do not determine agency by themselves.

## Review provenance

- Reviewer/model: OpenAI Codex / GPT-6.
- Method: Focused public-source reassessment using CAIHL: patient authority, critical capacity, and informed control. Existing evidence plus one focused primary-source pass and at most one targeted follow-up. No live product testing. Numerical scores remain provisional editorial placements, not a new calculation.
- Human review: Hugo Campos authorized publication of these AI-assisted draft reassessments on September 8, 2026. This does not claim comprehensive human verification of every finding.
- Earlier review: 2026-06-30. [Historical assessment](https://github.com/hugooc/HugoScore/blob/7e0ba68fae543832fe5f19009448e473983f48a9/site/reports/savva-caihl-report.md). Earlier claims are not automatically reverified by this publication.
