Skip to content

Privacy Policy

Version 3 · Effective 2026-06-25. This is the canonical published document; it mirrors what you accept when signing in.

Saga IT, LLC — OpenShare Beta Program

This Privacy Policy describes how Saga IT, LLC (“Saga IT,” “we,” “us”) collects, uses, and shares information in connection with the OpenShare beta service at openshare.health, including its web application, APIs, and the OpenShare integration-engine plugin and gateway software (the “Service”).

1. Important: No PHI or PII Should Be Submitted

Section titled “1. Important: No PHI or PII Should Be Submitted”

The beta Service is not intended to receive protected health information (PHI) or personally identifiable information (PII) beyond the account information described below. The Terms of Service prohibit connecting the Service to production systems or transmitting regulated data through it. Message payloads exchanged between your connected systems travel peer-to-peer over encrypted channels (DTLS) and are not stored by Saga IT; relay infrastructure, where used, carries only encrypted traffic it cannot read.

  • Account information: email address, display name, authentication identifiers (including your single-sign-on subject identifier if you sign in with a social provider), and multi-factor enrollment status.
  • Organization information: organization names, memberships, roles, and invitations you create or join.
  • Server and channel metadata: names, identifiers, statuses, capabilities, health and performance metrics, and alert events for the integration-engine servers and channels you register. This is operational metadata only — not message content.
  • Usage and audit records: actions taken in the Service, timestamps, IP addresses, user-agent strings, and records of your acceptance of legal documents.
  • Communications: messages you send us (for example, support or feedback emails).
  • Technical data: logs, error reports, and security telemetry generated by operating the Service.

We do not collect payment information during the free beta.

We use the information above to: operate, maintain, and secure the Service; authenticate you and enforce access controls; monitor health and performance of registered servers as the Service is designed to do; investigate abuse and security incidents; communicate with you about the Service (including beta updates, security notices, and changes to legal documents); and improve the Service. We do not use your information for third-party advertising, and we do not sell your information.

We share information only with service providers that host and support the Service, and as required by law:

  • Amazon Web Services (cloud hosting, United States — us-east-1): all Service data is stored and processed on AWS infrastructure.
  • Identity providers (if you sign in with a third-party account, e.g. Google): the provider receives the sign-in request; we receive your name, email, and account identifier from it.
  • Cloudflare (Turnstile bot protection): processes a token and connection metadata when you register or sign in.
  • Amazon SES (email delivery): processes the email address and content of messages the Service sends you.
  • Legal and safety: we may disclose information if required by law or to protect the rights, safety, or property of Saga IT, our users, or the public.
  • Business transfers: if Saga IT is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.

Visibility to other beta participants. When you sign in, your display name and your organization name are listed in the in-app contact directory, where other signed-in beta participants can see them and send you connection (“peering”) requests. During the beta this directory listing is enabled for all accounts and cannot be turned off. Other participants see only your name and organization in the directory — never your email address, servers, channels, credentials, or message data. Server and channel metadata is shared with another participant only when you establish a connection (peering agreement) with them.

The Service uses cookies necessary for authentication and session management (including sign-in cookies set by our authentication service) and browser storage (such as sessionStorage) for session hints and interface state. These are required for the Service to function; we do not use advertising or cross-site tracking cookies.

We retain account data, audit records, and acceptance records while your account is active and as needed for security, legal, and operational purposes. Records of your acceptance of these legal documents (the document version, timestamp, IP address, and the email address used) are retained after account deletion so that we can demonstrate the agreement was made. Server metadata and metrics are retained on rolling windows appropriate to monitoring. Because the Service is a beta, data may also be deleted at any time as part of beta operations — do not rely on the Service to retain anything.

To request deletion of your account and associated personal information, or a copy of the personal information we hold about you, email privacy@saga-it.com from your account email address. We will respond within a reasonable period and honor applicable legal rights.

We use TLS for data in transit, encryption at rest for stored data, role-based access controls, multi-factor authentication, and audit logging. No system is perfectly secure, and the Service is beta software; we cannot guarantee the security of information you submit.

The Service is not directed to anyone under 18, and we do not knowingly collect information from children.

We may update this Privacy Policy. When we publish a new version, you will be required to review and accept it through the Service before continuing to use it. The current version number and publication date are displayed with this document.

Privacy questions or requests: privacy@saga-it.com. Saga IT, LLC, Florida, United States.