Privacy Policy
Last updated: July 22 2025
Applies only to use of the Saga Star Platform within the United States.
1. Scope & Who We Are
Saga Star, Inc. ("Saga Star", "we", "our") operates the online platform sagastar.com (the "Platform"). We help professionals turn traditional resumes into living STAR stories ("sagas") and, if they choose, share those sagas with hiring companies.
2. Key Definitions (U.S. State Privacy Acts)
“Personal Information” (PI) - data that identifies, relates to, or could reasonably be linked with an individual.
“Sensitive Personal Information” (SPI) - content of resume or saga text you provide.
“Sale” / “Sharing” - disclosure of PI to a third party for monetary value or for cross-context behavioural advertising.
“Profiling” - automated processing to evaluate work performance, economic situation, interests, reliability, behaviour, location, or movements.
“De-identified Data” - information that cannot reasonably identify an individual and is protected by controls that prevent re-identification.
Categories of PI (CPRA §1798.140(v))
• Identifiers (name, email, IP address)
• Professional or employment-related information (resume, sagas)
• Internet or electronic-network activity (log data)
• Inferences drawn from the above
3. Information We Collect
3.1 Account Details
• Name, email address, password hash
• Retention: 30 days
3.2 Career Content
• Resumes you upload, sagas you write, attachments or links you add, job-seeking preferences
• Retention: until account deletion + 30 days backup grace
3.3 Platform Logs (automatic)
• IP address, device or browser type, timestamps
• Retention: 30 days
3.4 Essential Cookie
• Single authentication token to keep you signed in
We do not collect marketing or analytics cookies, biometric identifiers, or data scraped from third-party websites.
4. How We Use Information
• Provide, operate, secure, and improve the Platform
• Process resumes and sagas through an AI processor to generate insights you request (including optional AI resume tailoring)
• Offer optional job-matching and discoverability services if you opt in
• Generate de-identified, aggregated talent-market analytics for businesses
• Detect, investigate, and prevent fraud or abuse
• Conduct internal research and product development
4.1 No Automated Final Decisions
AI scores and matches are recommendations only; hiring decisions remain with people. You may opt-out of any profiling that produces legal or similarly significant effects.
5. Sharing & Disclosure
• Service Providers / Contractors - cloud hosting, database backup, email delivery, and the AI processor (all bound by contract)
• Hiring Companies - see your career content only after you explicitly opt in
• Affiliates or Successors - PI may transfer in connection with a merger, acquisition, or sale of assets
• Aggregated Insights Recipients - receive de-identified statistics; re-identification is contractually prohibited
• Legal or Safety - disclosure to comply with U.S. law or protect rights (we notify you when legally permissible)
We never sell or share PI for advertising purposes.
6. Your Privacy Rights (U.S. State Laws)
You may, subject to verification:
• Access - know the PI we hold about you
• Delete - request deletion (subject to 30-day backup grace)
• Correct - ask us to rectify inaccurate PI
• Portability - obtain a copy in portable format
• Opt-out of Sale/Sharing - discoverability is opt-in; no ads-based sharing
• Opt-out of Targeted Advertising & Profiling - we do not serve targeted ads; you may opt-out of profiling with significant effects
• Limit use of Sensitive PI - we use SPI only to provide the service; no sale or sharing
• Global Privacy Control (GPC) - a GPC signal is treated as a request to opt-out of sale/sharing
7. Exercising Rights & Appeals
• Submit a request via the in-app Privacy Center or email ·
• We will verify your identity and respond within the timeframes required by law
• If we deny your request, you may appeal via ·
• Authorized agents may act on your behalf with written permission
8. Data Retention
We retain each category of PI only for as long as necessary for:
• the purposes described in this policy
• backup integrity and fraud prevention (30 days post-deletion)
• compliance with legal obligations
Detailed retention schedule available on request at ·.
9. Security
• TLS encryption for data in transit
• AES-256 (or stronger) encryption at rest
• Role-based access, least-privilege principle
No method is 100 % secure, but we apply industry-standard safeguards.
10. Children & Minimum-Age Policy
The Platform is intended for individuals legally permitted to work in the United States - generally 16 years or older, or higher if your state requires. We do not knowingly collect PI from anyone under that age. If you believe we have, email · and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be posted at or before the point of collection, announced via an in-app banner and/or email, and take effect 30 days after posting (or sooner if required by law). Continued use after the effective date constitutes acceptance.