Sagabox Privacy Policy
Effective date: October 1, 2026
1. Who we are
Sagabox ("we", "us", "our") is a short-drama video and comics service operated by Sagabox ("Sagabox"). We provide Sagabox through our website (sagaboxtv.com) and our mobile applications, including the Android app with package name tv.sagabox.app (together, the "Service"). This policy explains what personal data we collect, why, and the choices you have.
Contact: support@sagaboxtv.com
2. Data we collect
We group the data we process into the categories below.
A. Account information. When you create or use an account we store your email address, a password (only if you set one), a display name, an avatar (profile photo), your interface language, and flags such as whether your email is verified and whether you have a password. If you sign in with Google on our website, we receive the account details returned by Google Sign-In (Google Sign-In is not available in the Android app at launch). (Source: auth.api.ts toMeUser; sign-in endpoints /api/auth/login, /api/auth/register, /api/auth/google; profile update /api/me/profile.)
B. User content. We store the content you create:
- Comments: the title you commented on and the text of your comment. Comments are public — anyone, including people who are not signed in, can read them, and other users can like them.
- Profile content: your display name and uploaded avatar image.
(Source: /api/comments GET is public and POST stores your comment; /api/me/avatar-url and /api/me/profile.)
C. Activity. We store how you use the Service so it works and syncs across devices:
- your library (saved titles), liked titles, and watch/read progress for each title/episode;
- watch and playback events (title, event type, and episode number) and, for video, quality-of-experience metrics such as time-to-first-frame, rebuffering ratio, exit-before-start, and preload waste;
- how long the app session was in the foreground;
- your coin balance, coin transactions, episode/chapter unlocks, VIP status, and rewards/task state.
(Source: /api/me/library, /api/me/saved, /api/me/liked, /api/me/progress; /api/count and /api/session; /api/coin/*, /api/rewards/*, /api/tasks/*.)
D. Device & diagnostics.
- Analytics visitor ID: a random 32-character hexadecimal identifier generated on your device and stored in local storage (MMKV). It is designed only to *distinguish devices* for counting and session measurement — it is not a secret and is not used for authentication. It is sent with analytics events (/api/count, /api/session).
- Analytics events: for each event we send the title identifier, the event type (view, play, episode start, episode done, unlock, share), the episode number where relevant, the visitor ID, and (for sessions) the measured number of seconds.
- Crash and performance reports (Sentry): error/crash events and performance traces. Sentry is configured with your internal user ID only— no email, name, or other profile data is attached. Sentry's standard event context may also include technical device/app information such as device model, operating system version, and app version.
(Source: analytics.visitor-id.ts, analytics.payload.ts, analytics.api.ts, count.mutations.ts, session.mutations.ts, monitoring.ts.)
E. Purchase history. If you buy coins or a VIP subscription, we keep records of those purchases and your entitlement (what you bought, when, and the status of the transaction). Purchases are completed on our website through a third-party checkout; the Android app itself does not sell anything at launch.
(Source: /api/checkout/create, /api/vip/plans, /api/vip/portal; purchase.api.ts.)
F. Push notification token and timezone. At launch, the Android app does not collect a push notification token and does notsend your device timezone. The endpoints /api/me/push-token and /api/me/timezone exist in our API surface but have no active call path in the app. See "Unconfirmed" in the accompanying evidence notes.
3. Why we use each category
| Category | Purpose |
|---|---|
| Account info | Create and secure your account; sign you in; sync your account across web and app; show your profile; send verification and password-reset messages. |
| User content | Display your comments and profile to you and, for comments, to the public; enable likes and moderation. |
| Activity | Operate the player/reader; remember and sync your library, likes, saves, and progress; maintain coin balance, unlocks, and VIP entitlement; compute popularity rankings and product performance metrics. |
| Device & diagnostics | Keep the Service stable and fast; diagnose crashes and performance problems; measure usage in aggregate. |
| Purchase history | Provide and support your purchases; maintain entitlement; meet accounting and tax obligations. |
4. Third parties
We share data with the following categories of service providers, only as needed to run the Service:
- Sentry — crash and performance monitoring. Receives diagnostic events and your internal user ID.
- Google — Google Sign-In on our website, if you choose it, and Google Play for app distribution.
- Payment provider — processes coin and VIP payments made on our website.
- Cloud hosting providers — host our servers and databases (Google Cloud).
We do not use advertising SDKs in the Android app, and we do not sell your personal data.
5. Retention
We keep personal data for as long as your account is active and as long as needed for the purposes above. When you delete your account (see the Account Deletion page), we delete or anonymize your data. Some records are retained after deletion for legal, accounting, and abuse-prevention reasons: purchase/payment records and comment records are kept but no longer linked to you (the link to your account is removed). The exact retention period is set by applicable law.
6. Your rights
Depending on where you live, you may have the right to access, correct, or delete your personal data, and to object to or restrict certain processing. In practice:
- Access and correction: most account and profile data (email, display name, avatar, language, password) can be viewed and edited in the app.
- Deletion: you can delete your account and its data from inside the app, or by email request — see the Account Deletion page for the exact steps.
To exercise any right, contact support@sagaboxtv.com. We may need to verify that you control the account.
7. Children
The Service is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, contact support@sagaboxtv.com and we will delete it.
8. Security
We protect data in transit using encrypted connections and store credentials and session tokens using platform-secure storage on the device (for example, the device keychain). No method of transmission or storage is perfectly secure, but we take reasonable technical and organizational measures to protect your data.
9. Changes
We may update this policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you in the Service. Continued use after an update means you accept the revised policy.
10. Contact
Questions about this policy or your data: support@sagaboxtv.com
