Scope
This Privacy Policy applies to Saberra.com, the Organizational Memory Audit, the manual Memory OS request form, demo and referral forms, early adopter access forms, and related communications with Saberra. It also explains how Saberra approaches information processed during a done-for-you deployment.
This policy does not replace a signed services agreement, data processing addendum, statement of work, or security addendum. If a signed agreement says something different, the signed agreement controls for that customer relationship.
Information we collect
We collect information in a few practical ways.
Information you submit
This includes name, work email, organization, organization type, team size, current tools, Memory Admin candidate, demo context, audit responses, and anything else you choose to send through a form or email.
Website and device information
Hosting, security, and form tools may process basic technical information such as IP address, browser type, device information, pages requested, referral URL, timestamps, and spam-prevention signals.
Communications
If you email us, book a call, request a resource, or respond to an outreach message, we may keep the contents of that communication and related contact details.
Deployment information
During a Saberra deployment, we may process meeting outputs, emailed transcripts, source emails, decisions, tasks, risks, roles, policies, review records, and source links as needed to configure and operate the memory workflow.
How we use information
We use information to provide, improve, secure, and communicate about Saberra. For example, we may use it to:
- Send the requested Memory OS resource or respond to a demo, referral, or early adopter access request.
- Score or display Organizational Memory Audit results.
- Evaluate whether Saberra is a fit for your tools, team size, and memory review capacity.
- Configure capture inboxes, review queues, Notion records, source links, and Sera answer workflows.
- Provide onboarding, support, maintenance, troubleshooting, and security monitoring.
- Send operational updates, follow-up emails, and relevant resources.
- Comply with legal obligations and protect Saberra, clients, users, and the public.
We do not sell personal information. We do not use client organizational memory to train a general public AI model.
How deployment data is handled
Saberra is designed around client-controlled tools. The standard deployment uses Google Workspace, native Google Meet capture, a dedicated inbox, Notion, an AI provider account, Railway, and human review. Meeting transcripts or summaries from other meeting platforms may be processed when they are emailed into the dedicated capture inbox.
Client memory records live in the client's Notion workspace by default. Custom deployments may use Postgres or other systems of record when scoped in writing. Saberra may need access to configure, maintain, troubleshoot, or support the workflow, but the goal is that the organizational record remains inspectable by the client.
AI extraction creates candidate records. Human review happens before those records become trusted memory. Sera answers from reviewed organizational records with source context.
Google user data
Saberra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Saberra connects to individual users' Google accounts via OAuth and, separately, to a client organization's meeting documents via an administrator-level grant. All connections are optional and revocable at any time.
What we access, why, and what we store
- Gmail — send only: When a user asks Sera to compose and send an email, Sera drafts the message and presents it to the user for review. The email is sent from the user's own Gmail address only after the user explicitly approves it. Saberra never reads, scans, or indexes the user's inbox. Email content is transmitted to Google at send time and is not retained by Saberra after sending.
- Google Calendar — event creation and reading: Saberra creates calendar events — including Google Meet links — that the user explicitly requests and approves. Saberra reads upcoming calendar events to build meeting-prep briefs. Attendees are never automatically emailed. Calendar data is read on demand and is not retained by Saberra.
- Google Drive — files Saberra creates only: When a user asks Saberra to save a document, it is saved as a Google Doc inside a “Saberra Documents” folder the app creates in the user's Drive. Saberra can only access files it created. It cannot read, search, or access any other content in the user's Drive.
- Google Docs — meeting transcripts (org-level admin grant): Separately from individual user OAuth, a client's administrator may authorize Saberra to read the Google Docs that Google Meet automatically produces (meeting transcripts and notes). This grant is the organization's responsibility and is revocable by the administrator. Meeting-transcript text is processed into structured records — decisions, tasks, risks, roles — that live in the client's own workspace (for example, their Notion), not on Saberra infrastructure. A human reviewer must approve every record before it becomes part of the organizational memory.
- Google account identity: Saberra reads the connected account's email address to identify which Google account is linked and display it in the product (“Connected as …” in Settings). Nothing else is read from the profile.
Saberra stores the OAuth access token, the connected email address, and the list of granted scopes in the client's database. Email content is not retained after sending. Calendar data is not retained after being read on demand. Meeting-transcript text is processed into records in the client's own workspace, not on Saberra infrastructure. OAuth callbacks pass through our relay at auth.saberra.com, which never receives or stores tokens.
How Google user data is not used
- Google user data is not used for advertising of any kind.
- Google user data is never sold or transferred to data brokers or any third party for their own purposes (beyond sub-processors acting on Saberra's instructions, as listed in the DPA).
- Google user data is not used to train machine-learning or AI models — neither general-purpose models nor Saberra's own.
- Human access to Google user data occurs only with the user's explicit consent, for security purposes, to comply with applicable law, or as part of aggregated and anonymized internal operations — consistent with the Limited Use exceptions.
Revoking Google access
- In Saberra: Settings → Google Integration → Disconnect. This immediately invalidates Saberra's tokens and deletes the stored token and connected email address from the database.
- At Google: myaccount.google.com/permissions — remove “Saberra.” This works even if you no longer have product access.
After revocation, Saberra cannot take further actions on connected accounts. Stored connection data (token and connected email) is deleted on disconnection or on request via privacy@saberra.com.
Retention
We keep information for as long as reasonably needed for the purposes described in this policy, including providing services, responding to requests, maintaining business records, resolving disputes, improving security, and complying with legal obligations.
Client deployment data retention may depend on the client's own Notion workspace, Google Workspace, Railway project, AI provider account, and any signed agreement or deletion request.
Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information. You may also have the right to opt out of certain sharing or marketing communications.
To make a request, contact privacy@saberra.com. We may need to verify your identity and your authority to act on behalf of an organization before responding. If your information is controlled by a Saberra client, we may direct the request to that client.
We do not knowingly sell or share personal information as those terms are commonly used in U.S. consumer privacy laws. If that changes, we will update this policy and provide any required choices.
Children
Saberra is designed for business and organizational use. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
International visitors
Saberra is operated from the United States. If you access the site or services from outside the United States, your information may be processed in the United States or other countries where our service providers operate.
Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information we process. No system can be guaranteed perfectly secure. Clients are responsible for securing their own Google Workspace, Notion, Railway, AI provider, email, and related accounts.
Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new effective date. If changes are material, we may provide additional notice where appropriate.
Contact
Questions or privacy requests can be sent to privacy@saberra.com.
