Patient-controlled health records AI
Savva
Savva is a patient-controlled, local-first health records AI app from Vircode, Inc. that aims to combine medical records, labs, medications, notes, scans, PDFs, wearables, fitness data, and multiple AI models on the user's phone. As of June 30, 2026, the homepage says Savva is launching July 7, 2026, while a company blog describes beta access for early users. The vendor privacy policy says health data stays on-device by default, with optional cloud AI inference sent only to a user-selected third-party provider. A CAIHL review should still verify app availability, source traceability, correction/export/deletion controls, AI-provider egress, connector governance, and whether the terms' broad user-content license is consistent with the privacy policy's health-data promises.
Public-source research has been drafted, often with AI assistance. No comprehensive human review is recorded unless the profile provenance says so.
Summary judgment · 78% toward patient-directed
Potentially agency-expanding
A patient-chosen longitudinal record and wearable-data copilot may support reflection, visit preparation, and self-advocacy. The local-first, no-account design is agency-positive if verified in practice, while cloud AI egress, billing logs, connector governance, correction/export/deletion controls, and clinical boundaries still need review.
Patient agency
How this tool changes agency
Timelines, source-linked summaries, lab explanations, fitness charts, and multiple AI perspectives could support visit preparation and self-advocacy. No independent outcome, accuracy, safety, or patient-burden evaluation was found.
The privacy policy says each data connection is opt-in, no account is required by default, cloud AI requires explicit provider consent, and app deletion withdraws consent. Hands-on review of onboarding, export, deletion, subscription, and model-selection UX remains necessary.
Patient-facing signals
Who does this AI serve?
Public materials position Savva as a consumer app for people to bring their own medical records, labs, notes, scans, wearables, and fitness data into one AI-powered health view. No current payer, employer, or provider deployment was found in the reviewed sources.
Can patients tell AI is involved?
AI-generated summaries, multiple model comparison, and cloud/on-device AI choices are central product claims.
Can patients meaningfully choose?
The privacy policy says each data connection is opt-in, no account is required by default, cloud AI requires explicit provider consent, and app deletion withdraws consent. Hands-on review of onboarding, export, deletion, subscription, and model-selection UX remains necessary.
Can patients correct or challenge what the AI produces?
The privacy policy includes correction rights for personal data, and the product emphasizes source visibility, but public materials do not document an AI-output challenge flow, error-reporting workflow, model-disagreement handling, or clinician annotation process.
Does it help patients understand or act?
Timelines, source-linked summaries, lab explanations, fitness charts, and multiple AI perspectives could support visit preparation and self-advocacy. No independent outcome, accuracy, safety, or patient-burden evaluation was found.
Text findings
Who is left out or burdened?
Partially documented
Public sources indicate adult use only, pre-launch/beta status, app/device dependence, and likely record connector limits. Accessibility, non-English UX, caregiver/proxy support, low-literacy support, disability access, Android/iOS parity, and cost burden need hands-on review.
What happens to patient data?
Documented by vendor policy, not independently verified
Privacy policy, last updated February 12, 2026, says connected health data remains on the device by default, no account is required, and Savva does not sell or share data. Optional cloud AI inference sends selected fitness or medical records to the user's chosen provider, including OpenAI, Google Cloud, Alibaba Cloud, Moonshot AI, Anthropic, Mistral AI, or xAI. Savva says its server facilitates transfer but does not save chat history or medical information, while usage is logged for billing. The terms' broad user-content license needs review against the privacy policy's health-data promises. Independent verification is pending.
Are the clinical boundaries clear?
Mostly documented
Public site language and terms say AI-generated wellness insights are informational only, may be wrong, and are not medical advice, diagnosis, treatment, or emergency support. In-app escalation behavior, high-risk lab findings, contradictory model outputs, and user comprehension of those boundaries remain unverified.
Who defined what good looks like?
Vendor-defined; independent evidence not found
No peer-reviewed evaluation, public safety testing, independent security audit, connector accuracy audit, source-grounding evaluation, or patient-partnered design evidence was found in the reviewed sources.
Review provenance
Criteria
Same HugoScore CAIHL-derived criteria for every tool; the public criteria are shown on How Reviews Work, displayed from site/data/criteria.json, with fuller method notes in SCORING_FRAMEWORK.md.
Reviewer
AI-assisted public-source draft; no named human reviewer is recorded in the profile data.
AI / model
Not recorded in profile data.
Human review
No comprehensive human review is recorded unless explicitly stated here.
Review date
Jun 30, 2026
Limitations
Deep public-source review of Savva's homepage, About page, Universal Records page, beta launch blog, privacy policy, and terms of use. No hands-on app walkthrough, network-traffic inspection, source-code review, vendor interview, patient interview, connector audit, security review, or independent model evaluation.
Review method
Deep public-source review of Savva's homepage, About page, Universal Records page, beta launch blog, privacy policy, and terms of use. No hands-on app walkthrough, network-traffic inspection, source-code review, vendor interview, patient interview, connector audit, security review, or independent model evaluation.
Draft profile · Medium draft, official sources only, not independently verified