Sage Privacy Policy

Last updated: September 1, 2026

Sage is operated by SageOE LLC, an Illinois limited liability company ("SageOE", "we", "us"). Sage is an Organization Engine — a personal dashboard that draws on the context of your life to bring your to‑dos, calendar, email, news, weather, and a built‑in assistant (Ivy) into one place. This policy explains what we collect and how we use it.

Information we collect

How we use your information

We use your information only to provide and improve the features of Sage that you see and use. We do not use it for advertising, we do not sell it, we do not build advertising or marketing profiles from it, and we do not use it to train AI models.

Google user data

If you connect a Google account, Sage requests three permissions and uses each only for the feature it names:

What we store. To make your dashboard load quickly and to give Ivy context, Sage stores a copy of your recent messages — sender, subject, date, and the message body text (email snippets) — along with your recent and upcoming calendar events. This copy lives in Sage's own database, is tied to your account, and is never visible to another Sage user. Older mail is discarded as newer mail syncs; we keep roughly your most recent few hundred messages, not your whole mailbox. Attachments are not downloaded or stored.

What we never do. We do not sell Google user data, use it for advertising, use it to build advertising or marketing profiles, or transfer it to anyone except as needed to provide the features above. We do not use Google user data to develop, improve, or train generalized or non‑personalized AI or machine‑learning models. No human at Sage reads your mail. The only exceptions Google's policy allows, and the only ones we would use, are: with your explicit consent, for security purposes such as investigating abuse, or to comply with applicable law.

Ivy and your Google data. When you ask Ivy something, the relevant context — which may include the text of an email or a calendar entry — is sent to our AI provider (Anthropic) solely to generate that one answer for you. Anthropic acts as our service provider for that request: the content is not used to train Anthropic's models or ours, and it is not retained for any other purpose. This transfer happens only because it is what makes the assistant feature work.

The spoken briefing and your Google data. If you use the Morning Routine, Sage reads your day aloud. The lines it speaks — which can include the titles and times of your calendar events, and the subject lines and sender names of your unread mail — are sent as text to OpenAI's text‑to‑speech API, which returns the audio. OpenAI acts as our service provider for that request only. It is not used to train OpenAI's models or ours, and Sage requests no other processing. If you never use the spoken briefing, no Google data is sent to OpenAI at all.

Google user data and other people. Sage never shares your Google user data with other Sage users automatically, and never shares it with anyone for their own purposes. One deliberate exception exists and it is entirely in your hands: if you use a feature that turns something into a to‑do item — for example asking Ivy to act on an email — and you then choose to send that to‑do to a Companion, whatever you put in it goes with it, exactly as it would if you typed it yourself. Sage never does this on your behalf.

Your control. On the web you can disconnect Google at any time in Settings → Integrations, which stops all further syncing; the iOS app can connect an account but cannot yet disconnect one. From any device, you can also revoke Sage's access directly from your Google Account at myaccount.google.com/permissions, which has the same effect. Deleting your account removes the stored copy along with everything else — see Data retention & deletion below.

Sage's use and transfer of information received from Google APIs — including Google Workspace APIs — to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: raw, aggregated, anonymized and derived data received from those APIs is never used, transferred or sold to create, train or improve any foundational or generalized artificial‑intelligence or machine‑learning model, whether ours or a third party's.

AI processing

Sage uses two AI service providers, and only ever as service providers acting on a single request from you:

Neither provider is permitted to use your content for anything except returning that one result to Sage. We do not use your data — from Google or anywhere else — to develop, improve or train AI or machine‑learning models, and we do not transfer it to any AI provider that would.

Where your information is held, and who else it reaches

Sage does not run on its own hardware, and some of what it does cannot be done without asking somebody else a question. This is every company that holds, carries or receives any part of your information in the course of running Sage, and the only thing each one gets. Sage sends nothing about you to anyone who is not on this list.

Payments and subscriptions

Sage has a free tier and a paid one. If you subscribe, how your payment is handled depends on where you subscribed.

If you redeem a promotional code, we record that you used it — which is what stops the same code being used twice. If we grant you a paid plan directly, for instance a comped or a staff account, we keep a record of who granted it and why. When a subscription starts we email you once to say so, and record that we sent it, so a repeated notice from Stripe or Apple cannot make the same email arrive again. And if you administer Sage and you create a promotional code, we store the code and its limits along with a record that you created it.

We do not use anything about your payments for advertising or profiling, and we do not sell it.

Sharing

We do not sell your personal information, and we do not share it with anyone for their own purposes. We share it only in these ways:

Data retention & deletion

On the web you can disconnect a connected account at any time in Settings → Integrations, which stops further syncing and removes the tokens for it. The iOS app cannot do that yet; revoking Sage's access from Google or Microsoft achieves the same thing from any device.

You can delete your account yourself, from inside Sage — on the web at Settings → General → Account, and on iOS at Settings → Account → Delete account. It asks for your password, then removes your account and the data attached to it in one pass: your to‑dos and lists, checklists, goals, habits, weight entries, people and dates, interests, Ivy conversations and day plans, your stored briefings, your notifications, the synced copy of your mail and calendar, connected‑account tokens, notification devices, and your settings. If you pay through the web, Sage cancels that subscription first and refuses to delete anything if the cancellation fails — so an account can never be deleted while a card keeps being charged. If you subscribed in the iOS app, only Apple can cancel it: Sage will decline the deletion and ask you to cancel with Apple first (Settings → your name → Subscriptions), then come back.

Deletion is immediate and cannot be undone. Backups are kept for operational recovery and roll off on their own schedule; we do not restore deleted accounts from them. If you would rather we did it for you, email [email protected].

Some things expire on their own, without you doing anything: a stored briefing after 14 days, a ride‑along day plan after 60, a notification you have read after 90 days and one you have not after 365, a password‑reset token after 7 days, the sign‑in for a device you have not used in 180 days, the marker that remembers you dismissed an email after 365, and the marker that remembers Sage already warned an address after 24 hours. The meter of your Ivy usage is kept for 400 days, because it is what answers a question about a bill. Everything else is yours until you delete it, or delete your account.

Security

Data is transmitted over encrypted connections and stored on access‑controlled servers. Connected‑account tokens and per‑user sync keys are stored per account and are not shared across users.

What is encrypted inside the database, and what is not. Three things carry their own encryption within Sage's database, so that a stolen copy of the file does not disclose them: the tokens for a connected account; the copy of your mail and calendar that Sage syncs — senders, subjects, message text, event titles and locations; and, if two‑factor sign‑in is set up on your account, the secret behind two‑factor sign‑in. The rest of what you keep in Sage — your to‑dos, your conversations with Ivy, your day plans and your stored briefings — is held as ordinary text in that database, protected by the access controls and encrypted connections around it rather than by encryption of its own. The same facts appear in several of those places, so encrypting one of them and not the others would change how this paragraph reads without changing what a stolen backup would show. We would rather say that plainly than imply more than is true.

Contact

Questions about this policy? Email [email protected].


We will update this policy as Sage changes. If a change materially affects how we handle your information, we will say so here and change the date above.