SAINTBack home
Privacy notice · pre-launch

Close enough to help. Clear enough to trust.

This notice explains how SAINT handles personal data on this website, in the Founding Circle, in private investor access and during the private pilot.

Development-stage notice. SAINT is currently a project based in Helsinki. The final contracting entity, registered address and business ID will be published before paid access begins. For the current website, waitlist and pilot, contact privacy@sa-nt.com.
01 · SeeCapture is visible.

The device signal and explicit language tell you—and the room—when sensing is active.

02 · KnowSources stay legible.

Useful answers should show where the fact came from and what Saint inferred.

03 · DecideOutward action waits.

Drafts, purchases and commitments remain behind a clear confirmation boundary.

04 · ExitMemory can leave.

Inspect, correct, erase or ask Saint to forget. Full erasure is self-serve: text DELETE MY ACCOUNT to Saint, confirm, and the run starts immediately — no email, no waiting on us.

Who and what this covers

For the activities described here, the SAINT project acts as the controller: it decides why and how personal data is used. This notice covers sa-nt.com, Founding Circle registrations, enquiries, private investor access and invited private-pilot use.

Product sales and subscriptions receive the purchase-specific terms shown before payment. A gift buyer may also provide limited information about a recipient for fulfilment and transfer of the gift; that does not subscribe the recipient to marketing. Employers or organisations running their own pilot may also be controllers under a separate agreement.

What we may handle

Website and waitlistName, contact details, consent and source information, plus essential security logs.
Orders and giftsBuyer identity, purchased items, payment reference, delivery planning and, for a gift, the recipient name and contact, personal note, book destination and chosen delivery-alert route. SAINT never receives card details.
Investor accessName, work email, organisation, a short request note, approval and delivery state, and content-free access receipts. Investor questions and generated answers are not retained by SAINT.
Account and deviceIdentity, connected services, preferences, device identifiers, provisioning and diagnostic events.
Things you captureMessages, voice, transcripts, images, documents, meeting context and the instructions you give Saint.
Maintained contextApproved memories, contacts, commitments, lists and settings that make later answers useful.
Support and safetyEnquiries, audit events, consent records, abuse signals and incident information.

SAINT is not designed for children, medical records, emergency response or covert recording. Please do not submit special-category or highly sensitive information unless an approved pilot explicitly requires and protects it.

Why we use it

To provide the service and pilot: capture what you ask for, return useful summaries, carry out confirmed actions, operate devices and support your account. The legal basis is performance of an agreement or steps you request before one.

To administer investor access: review a requested diligence relationship, deliver a temporary invitation, secure the room and respond to access problems. The legal basis is the steps you request and our legitimate interest in running a controlled financing process.

With your consent: send Founding Circle updates, connect optional services, or run non-essential analytics. You may withdraw consent at any time.

For legitimate interests: secure the service, prevent abuse, improve reliability and understand aggregate product use, after balancing those interests against your rights.

To meet legal obligations: keep records required by law and respond to valid legal requests.

Voice, images and people nearby

The device is designed around explicit capture, a visible recording state, haptic confirmation and a hardware privacy control. Those signals do not replace permission. The person using SAINT is responsible for telling other people and obtaining any consent required by local law or workplace policy.

Automated systems may transcribe, summarise and rank information. They can be wrong. SAINT should show its reasoning or source context where practical, and consequential actions require confirmation. We do not make decisions producing legal or similarly significant effects about you solely by automation.

How long things remain

Captured itemsNormally deleted after 90 days unless you retain or convert them into maintained context.
Meeting audio7 days by default; a pilot may allow up to 30 days. A transcript or summary can remain separately.
Captured imagesNormally 1 day after processing, unless you deliberately keep the result.
Maintained contextUntil you delete it or close the account, subject to backup and legal hold periods.
Waitlist detailsUntil you unsubscribe, ask us to erase them, or the list is retired.
Gift fulfilmentThe recipient contact and book address are used only to deliver and transfer that gift. The address is removed after fulfilment when it no longer has to remain with an open delivery, return or accounting case; the content-free service right remains with the paid order until accepted, refunded or expired.
Investor access receiptsRequests, hashed grants and content-free browser access receipts are removed after 30 days or sooner on request. Invitations expire after 48 hours; sessions after 14 days or 24 hours idle.
Security and consent recordsOnly as long as reasonably needed to protect the service or demonstrate compliance.

Deletion from active systems may be followed by a limited backup-expiry period. We will publish the final backup and operational-log schedule before general availability.

Connected Google accounts

If you connect a Google account, Saint first asks only for read access to Gmail, Google Calendar and Contacts. Separately, and only when you first use a feature that needs it, Saint asks again for permission to send email as you, apply labels or create Gmail drafts, set or clear your vacation responder, accept, decline or block time in your calendar, or save a contact into your address book. Each request names the feature that needs it. You can see what is granted at any time under Google Account → Security → Third-party access, and revoke it there or from your Saint trust page.

We use this data only to produce your briefs, identify who is contacting or meeting you, and carry out actions you explicitly ask for. Mail and calendar content is processed to generate an answer and retained no longer than the periods above; it is never used for advertising, never sold, and never used to train general-purpose AI models. Human access is limited to what you consent to, security investigation, or legal compliance. Processors that handle it in transit — hosting, communications and AI inference — are bound by contract and listed in our sub-processor register.

Saint's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Processors, transfers and security

We use specialist providers for hosting, communications, speech processing, AI inference, analytics and support. They receive only the data needed for their task and must act under contract. A current subprocessor register, including locations and safeguards, will be published before commercial launch.

If data is processed outside the EEA, SAINT will use an adequacy decision or another lawful safeguard such as the European Commission’s standard contractual clauses. We do not sell personal data or use it for behavioural advertising.

Production settings and provider contracts are intended to prevent customer content being used to train general-purpose models. That control must be contractually verified before launch. Security measures include encryption in transit and at rest, scoped credentials, device identity, audit events and restricted operator access. No system is risk-free.

Your choices and rights

Depending on the circumstances, you may ask to access, correct, delete, restrict or receive your personal data, object to certain uses, and withdraw consent without affecting earlier lawful processing.

Email privacy@sa-nt.com. We may need to verify your identity before acting. You may also complain to the Office of the Data Protection Ombudsman in Finland or your local supervisory authority.

Essential cookies or local storage may be used for security and session continuity. Non-essential analytics remain off until you choose them. See or change the exact cookie choices.

Changes and contact

We will update this notice as the pilot, legal entity and supplier set mature. Material changes will be called out here and, where appropriate, sent to registered participants.

Privacy: privacy@sa-nt.com
General enquiries: hello@sa-nt.com
Helsinki, Finland

Version 1.3 · 16 August 2026