Privacy policy
This Notice describes what Saga Studio AI stores, why, who processes it, and your choices. Saga does not sell personal data or use third-party behavioural advertising analytics. Optional Google Ads measurement is limited to page measurement and configured waitlist or early-access conversion events after a visitor allows it. Free account registration is open for validation-beta testing; prize challenges remain paused.
1. What we collect
- Account: email, salted password hash, account status, and, if chosen, the email and identity result verified by Google. Saga never sees your Google password.
- Your work: prompts, reference media, generated images, audio and video, model/settings, job status, quality feedback, private model-shootout ratings, delivery checks and optional Creative Judge results, library metadata, private Board layout, connection, trim, sequence and exported-edit records, and shared-project canvas positions and notes.
- Project collaboration: the account owner’s editor-link label, expiry, revocation state and non-secret token prefix; collaborators’ chosen display names beside canvas changes; and 30-day operation metadata recording the project, operation type and time. Live-presence name and client state is held only in server memory for approximately 45 seconds after the last heartbeat.
- Platform automation: scoped-connection metadata; webhook destination URLs, subscribed events, encrypted signing secrets and delivery status/error metadata; and 24-hour owner-scoped API retry records containing the idempotency key, request hash, route and first JSON response. Raw platform keys and decrypted webhook secrets are not included in account views or exports.
- Billing and contracts: balance, ledger, payment/order references, refunds, and versioned evidence that current account, checkout, and one-time content-submission terms were accepted. Payment providers, not Saga, collect payment credentials.
- Traffic and security: request path, time, response status, coarse device type, referrer origin, coarse campaign source/campaign/content labels, and one-way visitor, source and signed-in account keys. The first-party traffic database does not retain a signed-in email, source IP, full referrer path, referrer query, or advertising click ID. If optional Google Ads measurement is allowed, Google may process its own campaign identifier, page visit, consent state, and a configured waitlist or early-access conversion event. Saga does not send the signup email, prompts, reference media, or generated content to Google Ads.
- Support: email, subject, message, page, user agent, delivery status, and a one-way source key used for abuse prevention.
- Waitlists and early access: email, requested model or access type, signup time, source page, consent version, user agent, and a one-way source key used for abuse prevention.
2. Purposes and legal bases
- Contract: create and authenticate an account, perform requested generations and evaluations, provide the library, administer balance/refunds, and answer service requests.
- Legal obligation: preserve accounting and transaction records, respond to lawful requests, and meet consumer and privacy duties.
- Legitimate interests: secure the service, prevent abuse and fraud, diagnose failures from status and error metadata, measure first-party traffic, improve reliability, and establish or defend legal claims. Private content is not opened for routine diagnostics or product learning.
- Consent: only for optional uses that are presented separately, such as Google Ads conversion measurement, a one-time model or account-availability notice, future marketing email, or additional publicity. Advertising measurement is off until allowed and is not required to join a waitlist or receive the core service. A waitlist or early-access consent covers only its requested availability notice, not general marketing. Consent may be withdrawn.
3. Service providers and AI processing
- Hosting: DigitalOcean hosts the service and stored content.
- AI: Anthropic supports story/prompt functions; OpenRouter and the selected downstream model provider process routed generation; OpenAI processes direct Sora requests; MiniMax processes configured reference-image analysis and, only after a separate per-run confirmation, downscaled images or three sampled video stills for the optional Creative Judge.
- Identity: Google verifies optional Google sign-in. Saga's site fonts are served directly by Saga Studio AI.
- Advertising measurement: Google Ads receives page measurement and a configured waitlist or early-access conversion event only after the visitor allows advertising measurement. Advertising personalization and Saga's use of Google Analytics remain disabled in this implementation.
- Email: Resend delivers password resets and support notifications.
- Payments: Stripe, PayPal, or CoinGate processes the method selected after paid sales open.
Saga does not train a model, tune Saga Enhance, score product quality, or build marketing material from customer prompts or media. This prohibition covers Saga's own product learning and reuse; it does not prevent an account owner from explicitly requesting a private Creative Judge evaluation for their own shootout. Creative Judge results remain in that account and are not fed into Saga's learning loop. The private learning loop is restricted to a separately configured operator-owned account. Other users and routine administrator tools cannot open another account's prompts, references, generated files, or library. Aggregate status, cost, and reliability statistics may be used without exposing the work itself.
When an account owner configures a webhook, Saga sends the selected destination compact job or agent-run metadata after completion or failure. Webhook payloads do not contain prompts or generated files; private results still require a scoped Saga connection. The destination selected by the account owner receives and processes that event under its own terms.
Downstream provider retention and training policies vary. OpenRouter states that its Zero Data Retention control does not apply to asynchronous video generation because temporary retention is needed to complete those jobs. Users make a one-time contractual agreement not to submit sensitive, confidential, or unauthorized content. Saga records the policy version, time, account, user agent, and a one-way source key as evidence of that agreement. Saga continues to review provider roles, retention, locations, and transfer safeguards as the available provider set changes.
4. Cookies, local storage, and advertising measurement
The session token and account email are stored in browser local storage. First-party sign-in, media-session, private-review and private-collaboration cookies may be used for navigation, restricted project access, and private media playback. First-touch campaign source may also be stored locally.
Google Ads measurement is disabled by default. Saga stores the visitor's choice locally as saga:adsMeasurementConsent. Choosing Allow loads Google tag AW-10997479255 with advertising personalization disabled and permits a conversion event when a new waitlist or early-access record is saved. Choosing No thanks leaves the Google tag unloaded. The choice can be changed below.
5. Retention and deletion
- Prompts, references, generated media, shootout ratings and evaluations, Board layouts, edit sequences, exported edits, and account records are kept while the account exists or until an earlier deletion request is completed.
- First-party traffic records are automatically deleted after 30 days.
- Webhook delivery history is automatically deleted after 30 days. Endpoint configuration remains until the account owner deletes it or closes the account.
- API idempotency records are automatically deleted after 24 hours and are deleted immediately when the account closes.
- Shared-project canvas operation metadata is automatically deleted after 30 days. Canvas layout and notes remain with the project; editor links remain until they expire, are revoked, the project is deleted, or the account closes. Live presence is transient.
- Support messages are automatically deleted after three years.
- Waitlist and early-access records are deleted after withdrawal or within 30 days after the requested availability notice is sent.
- Accounting, payment, acceptance, fraud, and legal-claim records are kept only for the applicable statutory or claims period.
- Privacy-minimized Nginx access logs omit client IP addresses, query strings, referrers, and user agents; they rotate daily and retain 14 rotations. All five operational SQLite databases are backed up every six hours and locally retained for 14 days. Access-restricted off-host copies are transferred to Mac and NAS storage on a separate four-times-daily schedule. Separate DigitalOcean platform-log retention remains subject to the provider configuration.
You can download account data or close a non-admin account from Billing. The export includes shared-project canvas content, collaborator-link metadata without token hashes, and canvas-operation metadata. Closure deletes live stories, prompts, generation records and media, Board layouts, edit sequences and exported edits, project canvases, notes, editor links and operation metadata, invalidates login, and pseudonymises records retained for accounting or legal claims. Matching support and pseudonymous signed-in traffic rows are deleted. Deletion from backups follows the 14-day backup cycle.
6. Security
Passwords are hashed with scrypt and a per-account salt. Traffic is encrypted in transit with HTTPS. Platform idempotency keys are owner- and route-scoped, and a key reused with different request content is rejected. Webhook signing secrets are encrypted at rest, each outbound payload is signed with HMAC-SHA256, and destinations are re-resolved and pinned to public network addresses for each delivery. Private collaboration capabilities are hashed at rest, exchanged once from a non-referring URL fragment into an HttpOnly, SameSite cookie, independently revocable, and limited to arranging and annotating media already in one project; they cannot generate, spend, browse the owner’s library, run agents, or change account settings. Generated files require an authenticated, owner-matching media session or a valid project-limited capability, are not served from the public static directory, and may be reused only by the requesting browser's private cache. Routine administrator views are owner-scoped; global operational reporting is aggregate-only. Acceptance, support-abuse, and traffic source/account evidence uses one-way keys rather than recoverable IP addresses or account emails in the traffic database. Access control, backups, monitoring, and incident handling reduce risk, but no online service can promise absolute security.
7. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, objection, and portability, and withdraw optional consent without affecting earlier lawful processing. A waitlist or early-access signup can be removed through the public support form. You may complain to the Norwegian Data Protection Authority, Datatilsynet. Saga may verify identity before acting and will not request more information than necessary.
8. International transfers
Some service providers may process data outside Norway or the EEA. Saga reviews provider roles, locations, data-processing agreements, and transfer mechanisms as the available provider set changes. Account holders must not submit sensitive, confidential, or unauthorized content.
9. Children
Saga accounts and challenges are for people aged 18 or older. Saga does not knowingly offer accounts to children. Report suspected under-age use through support.
10. Controller and contact
Hantho Invest AS (org. no. 930369926), Spannalia 6F, 5542 Karmsund, Norway, is the data controller for Saga Studio AI. Prize challenges remain paused.
Users can submit privacy questions, rights requests, account closure, or concerns through the public support form.
11. Changes
Material changes will be announced before they take effect. Where required, Saga will request active acceptance or consent. See also the Terms of use.
© 2026 Saga Studio AI. All rights reserved.