Privacy Policy
Effective 1 October 2026
This policy explains how SABA Care Analytics LLC ("SABA Care Analytics", "we", "us") collects, uses, stores and shares information through sabacareflow.com (the "Website") and through CareFlow Publisher, an internal application we use to publish and manage our own videos on YouTube.
This policy does not govern the CareFlow clinical software product. That product is governed by the applicable customer agreement with SABA Care Analytics, including a Business Associate Agreement where applicable.
1. The Website
- The Website has no user accounts, forms, cookies, analytics, advertising or third-party tracking scripts.
- The infrastructure that delivers the Website (Amazon Web Services) receives standard technical request information, such as IP address, browser type, the page requested and the time of the request, in order to deliver and protect the Website. We use it only to operate, secure and troubleshoot the Website. We do not use it to identify visitors, sell it, or use it for advertising.
- If you email us, we receive what you choose to send and use it to respond.
2. CareFlow Publisher and YouTube API Services
CareFlow Publisher uses YouTube API Services. It is an internal application, used only by authorised SABA Care Analytics personnel to upload and manage SABA Care Analytics videos on YouTube. It is not offered to the public. Personnel connect it to our YouTube channels through Google OAuth authorisation.
What it accesses
The YouTube channel chosen at authorisation, only to carry out publishing actions the operator requests:
- uploading videos and setting their title, description, tags, category, language and visibility;
- uploading thumbnails and captions;
- adding videos to playlists, and creating playlists on our private test channel;
- reading back the details of videos it uploaded, to confirm them and keep its records current.
It does not access Gmail, Google Contacts or other Google account data, and it does not access YouTube viewer information, watch history or analytics. Visibility (private, unlisted or public) is always chosen by the operator for each upload. CareFlow Publisher never changes a video's visibility afterwards.
What it stores, and where
Everything CareFlow Publisher stores is kept only on the authorised operator's computer, in files readable only by that user. Nothing is stored in our source code repository, in cloud services or on any server.
- Authorisation credentials: the OAuth access token and refresh token.
- Channel identity: the authorised channel's ID and name, used to confirm that uploads go to the intended channel.
- Upload records, one for each video it uploaded: the YouTube video ID, caption track ID, playlist entry ID and channel ID; the video's title and visibility; and the upload and scheduled publication times.
Channel identity and upload records are refreshed from YouTube API Services at least every 7 days when the application runs. Anything not refreshed within 30 days is deleted. Records of videos that no longer exist on YouTube are deleted at the next refresh.
How we use it
Only to perform the publishing actions authorised personnel request, and to avoid uploading the same video twice. We do not use YouTube API data for advertising, profiling or any other purpose.
Sharing
We do not sell, rent or disclose information obtained through YouTube API Services to any third party. Information is sent to Google and YouTube only as needed to perform the publishing actions requested.
3. Revoking access
You can revoke CareFlow Publisher's access at any time:
- In CareFlow Publisher: its revoke function revokes the authorisation with Google and deletes all of the data listed above for that authorisation at once. This is always completed within 7 days.
- In Google's security settings: https://security.google.com/settings/security/permissions. CareFlow Publisher can then no longer access YouTube, and the stored data is deleted when the application next detects the revocation, and in any case within 30 days.
4. Requesting deletion
To ask us to delete data CareFlow Publisher stores about your authorisation, email info@sabacareanalytics.com. We will delete it as soon as possible and within 7 days of your request.
Deleting data stored by CareFlow Publisher does not delete videos, channel information or other data held by YouTube. Content on YouTube must be deleted through YouTube.
5. YouTube and Google policies
By using CareFlow Publisher, authorised users agree to be bound by the YouTube Terms of Service. Google's and YouTube's handling of information is governed by their own policies, including the Google Privacy Policy.
6. Security
Stored credentials and records are kept in files readable only by the operator's account. All communication with Google and YouTube uses encrypted (HTTPS) connections.
7. Children
The Website and CareFlow Publisher are not directed to children, and we do not knowingly collect information from children.
8. Changes
If this policy changes, we will update this page and its effective date.
9. Contact
Questions, complaints or requests about this policy or data handled by CareFlow Publisher: SABA Care Analytics LLC, info@sabacareanalytics.com.