Saga Privacy Policy
Effective date: August 16, 2026. Owner: Saga is a product owned and operated by Circe Social Co.
1. Who we are and what this covers
Saga is a family-video product owned and operated by Circe Social Co. ("Saga," "we," "us"). You use Saga to upload personal photos and videos, have them edited into films by automated systems, and share those films. This policy explains what information we collect, how automated systems and our service providers process it, how we share and retain it, what we can and cannot delete, and the choices you have.
This policy covers the Saga mobile app and the Saga websites at saga.you, including public film pages that anyone can watch through a share link without an account.
• Legal contact / address: Circe Social Co., 1955 Courtland Ave, Oakland,
CA 94601.
• Jurisdictions offered: United States only.
• Privacy contact: privacy@saga.you.
• Support contact: support@saga.you.
• Changes: When we make a material change we will update the effective date
and, where required, notify you in the app or by email.
2. Information you provide
• Account and identity. Your email address and password, handled through AWS
Cognito; your profile display name, avatar, and bio.
• Collaboration. Project titles, descriptions, story/mood/tone/location
choices, edit prompts and steering text, comments, timestamp tags, and the email addresses you enter to invite collaborators.
• Media you upload. Original photos and videos — including their bytes,
filename, type, dimensions, duration, and any metadata embedded in the file (see Section 5 on embedded location) — plus uploaded music and voice audio, and voice reactions. We derive thumbnails, proxies, transcripts, and rendered films from this content.
• Guest contributions. If someone watches a shared film without an account
and leaves a named reaction, we collect that name and reaction as pseudonymous guest content visible to the project owner.
• Support, feedback, and reports. Feedback text, an optional screenshot, the
route/app-version/platform/viewport context attached to it, and abuse reports (target, category, and optional free-text detail).
• Payments. If you buy a subscription or film, checkout happens on
Stripe-hosted pages. Payment-card details are entered at Stripe and are not stored in Saga's systems; we receive a Stripe customer reference, subscription or entitlement status, and billing events.
3. Information collected automatically
• Identifiers. Internal account, project, asset, and job IDs; your Cognito
subject; a stable browser/device key; platform and model hints; and, after you grant permission, an Expo/APNs push token.
• Share-view network data. When someone opens a public film link, we record
the viewer's IP address, user agent, first-view time, and a persistent pseudonymous viewer identifier stored on the viewing device, which can span multiple share links, used for view counts and product analytics.
• Usage and telemetry. Upload, editing, approval/rejection, voting, comment,
and usage events; per-second watch telemetry (play, progress, skip, rewatch, drop-off, completion, playhead position, watched milliseconds, app version). When you delete your account, the link between this telemetry and your account is severed; the resulting de-identified playback facts are retained indefinitely for product analytics.
• Operational logs. Standard server, security, and error logs from our AWS
infrastructure, and app context (version, platform, route, locale) attached to feedback.
4. How we use information
We use information to authenticate you and run your account; to upload, process, edit, transcribe, and render your media; to power collaboration and sharing; to deliver notifications; to bill for paid features; to provide support; to secure the service and prevent abuse; to moderate content and comply with law; and to maintain, debug, and improve Saga.
Section 5 describes what is sent to each provider. As a general rule we do not make claims about whether providers retain or train on your content until our provider agreements are verified. One verified protection we do state: AWS does not use your content to improve or train its AI services (an organization-wide opt-out has been verified and is enforced for our AWS organization). We do not extend that claim to ElevenLabs or to Saga itself, and we do not make a blanket "we don't train on your content" claim while our diagnostic logs can still contain model responses. The three scoped exceptions to our general silence are this AWS no-train statement, the abuse/CSAM detection disclosure in Section 5, and the verified-processor statements in Section 7; otherwise we describe only protections we have verified.
5. AI and automated processing
Saga's core function is automated. Your media and instructions are processed by automated systems and foundation models to analyze clips, transcribe speech, generate edit structure, and render films.
• Processors. Editing and analysis run on AWS Bedrock (foundation
models). The foundation-model providers reached through Bedrock in the current configuration include Anthropic (Claude) for creative editing roles and, for optional/legacy roles, Moonshot. Speech transcription uses ElevenLabs Scribe as the default transcription provider: it receives the full audio recording of all footage you upload (every non-photo asset except audio you tag as music), transcribed with speaker labels (diarization). AWS Transcribe is a fallback that receives only a storage reference to the audio. When ElevenLabs is used, the audio is transmitted to ElevenLabs' own service (api.elevenlabs.io) outside AWS/Bedrock, under Saga's ElevenLabs API key. We do not state ElevenLabs' provider-side retention terms in this policy until they are verified against the deployed production configuration. The final provider list and legal roles are confirmed against production configuration before release.
• Embedded location coordinates. Saga does not read your phone's live GPS
or Core Location. However, a photo or video you select can contain location coordinates embedded in the file (photo EXIF GPS, or a video container location tag). Our media pipeline extracts those coordinates and persists them server-side in media-metadata artifacts, and your original file (which also carries them) is retained in versioned storage. From the coordinates we derive a coarse place name using an offline lookup on our own servers — we do not call any location provider. That derived place name is stored server-side and linked to your account. Only that place name, never the coordinates, is sent to our AI providers, where it informs the edit. This is not live-phone tracking, and we do not use it for advertising. Saga v1 extracts and retains these coordinates rather than stripping them; a future stripping option may be offered but is not part of v1.
• Written descriptions of people. To assemble films, the AI analysis
generates and stores short written descriptions of the people in your clips — their appearance, clothing, and expressions — on a per-clip basis. Saga does not run face recognition or any biometric identification, and stores no faceprints or biometric templates.
• Support triage. Support feedback you submit is summarized by a foundation
model before it reaches our issue tracker.
• Accuracy. Automated outputs can be wrong, incomplete, or unexpected. You
should review films before relying on or sharing them.
• Automated abuse and CSAM detection. Separately from any product-improvement
use of content, the AI providers that process your media may run automated abuse and child-sexual-abuse-material (CSAM) detection as part of their service. Where a provider's system flags content, that provider may retain and human-review the flagged input and report apparent CSAM to the authorities (including NCMEC) under the provider's terms and applicable law. This is the provider's process, not a Saga retention promise, and it is not a blanket "never retained" statement. We will state the applicable retention period once it is verified (task #341).
• Retention/region/human review. Except for the abuse-detection basis above,
we have not yet established, and so do not claim, provider-side retention terms (including transcription-provider retention), data region, or routine human review. We will state these only once the relevant provider agreements are verified against the deployed configuration.
6. Sharing and collaboration
• Collaborators. People you add to a project may see that project's media and
content according to their role.
• Share links. A film share link is a bearer capability: anyone who has a
live link can watch the film, and can forward it. Revoking a link stops new resolutions but cannot recall copies already loaded. Some links can also let a viewer join the project; this is chosen when the link is minted.
• Guest data. Guest names and reactions are visible to the project owner.
• Notifications are disclosures to delivery providers. Push and email are
not content-free. Depending on the message, Expo/Apple (APNs) and AWS SES receive titles, choice prompts, synopsis/runtime copy, identifiers, and deep links; a film-ready message may include a short-lived presigned still-image URL (configured expiry ~900 seconds). URL expiry is not message deletion: the notification or email can remain at the provider, on your device, or in a recipient's mailbox, and we cannot retract copies already delivered.
7. Service providers and disclosures
We share data with providers who process it on our behalf:
Provider — Role — Data involved
Amazon Web Services — Identity (Cognito), media storage (S3), database (RDS), processing (Lambda/ECS/SQS), delivery (CloudFront), email (SES), AI (Bedrock — creative editing and support-feedback summarization; Transcribe), logging (CloudWatch) — Nearly all account, media, content, usage, and diagnostic data, including support feedback summarized before it reaches the issue tracker
Stripe — Hosted checkout/portal, subscriptions, entitlements — Email, Saga user reference, purchase/billing status; card data at Stripe
Expo — App updates and push transport — App/device metadata, push token, notification content
Apple — Photo-library permission, APNs delivery, App Store distribution — Selected media, device token, notification content
ElevenLabs — Speech transcription — default provider; receives the full audio recording of all footage (diarized, speaker-labelled); called directly at api.elevenlabs.io (outside AWS/Bedrock, under Saga's own API key) — Full footage audio and returned transcript; provider-side retention terms not stated until verified against the deployed configuration
GitHub — Optional private feedback sink — Feedback text, context, IDs, screenshot reference
Circe Social Co. is the controller of your personal information; the providers above act as our processors/service providers. We may also disclose information for legal or safety reasons, in a corporate transaction, or to professional advisers. Our infrastructure and AI providers (AWS, ElevenLabs) are contractually prohibited from selling or sharing your personal information. We are completing a review of every provider in our data map, including our payment processor, before making a service-wide statement.
8. Safety, reports, and moderation
You can report content and accounts. We collect the category reported, your reporter details, and any evidence, and we preserve it as safety evidence. We investigate reports and may restrict, remove, or quarantine content or accounts, but we do not promise that every report results in removal, and we do not promise universal monitoring. Emergency and illegal-content escalation follows our internal takedown runbook. We review reports promptly. A logged-out report path is provided on every public film page before public sharing is enabled, so viewers without an account can report content.
9. Retention and deletion
We keep information for as long as needed to provide Saga and for the additional purposes described here. Deleting content is not instantaneous across every copy, and some copies persist on defined schedules:
• Active storage. Media lives in private, encrypted, versioned S3 with no
general expiration; database rows persist while your account and resources exist. Incomplete multipart uploads expire after 7 days.
• Deletion today. You can delete individual assets and projects. A
"permanent delete" request is accepted, and an in-app account deletion flow (including identity deletion and media purge) is being built to meet Apple's requirement; it is not yet fully live. When deletion runs, removal from our systems completes on our deletion schedule (see the windows below). We do not publish a fixed completion time and will not claim one we cannot prove in production.
• Secondary copies (facts from configuration, not a full schedule). Database
backups are retained ~14 days; deleting a live row does not selectively erase it from an existing backup. Processing queues and dead-letter queues retain message bodies ~14 days. Worker container logs are copied to CloudWatch and retained 30 days (an ECS log-group override); API and Lambda logs are retained 90 days; identity logs are retained 30–90 days depending on the log group. Worker logs may contain a short excerpt of the editing instructions you typed. Deleting your data does not individually purge these; they age out on schedule or require operator-level deletion.
• Legal holds and retained records. We may retain certain records (e.g. safety
evidence, billing records, or data under legal hold) after deletion where required.
• Viewer telemetry for public links. When people open your public film links,
we retain rows about those viewers — including IP address and user agent (see Section 3). Those viewers are not account holders, so these rows are not covered by account deletion and have no fixed expiry today. A retention lifecycle for these rows is a separate backend task, not yet scheduled.
• Delivered messages. We cannot recall notifications or emails already
delivered to a device or mailbox.
To request deletion or ask about the status of a request, contact support@saga.you.
10. Security
Your media is stored in private S3 buckets, encrypted in transit and at rest, served over SSL only, versioned, and blocked from public access; film stills are served through short-lived signed URLs. We use access controls and account security measures. No method of storage or transmission is perfectly secure, and we do not guarantee absolute security.
11. Your choices and rights
• Permissions. You control photo-library and notification permissions through
your device.
• Share links. You can revoke share links at any time (subject to the limits
in Section 6).
• Access, correction, deletion, and other rights. Depending on the US state
you live in, you may have rights to access, correct, delete, or obtain a copy of your personal information, to opt out of sale/sharing (we do not permit our verified providers to sell or share your personal information; see Section 7), and to appeal a decision — including the rights California residents have under the CCPA as amended. Contact privacy@saga.you to exercise them; we will not discriminate against you for doing so. Saga is offered in the United States only, so this policy does not provide EEA/UK legal bases or international-transfer terms.
12. Children and family content
Saga is a family product, and the media you upload may depict children even though accounts are held by adults. You must be 18 or older to hold a Saga account, and Saga has no child-account mode in this version. We handle requests concerning child subjects and child safety as described in Sections 8 and 11.
13. International transfers
Saga is offered in the United States only and runs on US-based AWS and provider infrastructure. We do not offer Saga outside the US at launch, so this policy does not provide an international-transfer mechanism. If that changes, we will update this section before offering Saga in other countries.
14. Contact
Privacy requests: privacy@saga.you. Support: support@saga.you. Postal/legal contact: Circe Social Co., 1955 Courtland Ave, Oakland, CA 94601.