Sage Privacy Policy
Last updated: September 1, 2026
Sage is operated by SageOE LLC, an Illinois limited liability company ("SageOE", "we", "us"). Sage is an Organization Engine — a personal dashboard that draws on the context of your life to bring your to‑dos, calendar, email, news, weather, and a built‑in assistant (Ivy) into one place. This policy explains what we collect and how we use it.
Information we collect
- Account information — your username and email address. If you ask for a password reset, we also hold a single-use link token until you use it or it expires. Signing in creates a signed-in session for each device you sign in from, so that device does not have to ask for your password again until the session expires.
- Content you add — to‑dos, including the ones you set to repeat, the lists and labels you file them under, checklists, goals, daily habits, weight entries, milestones, notes, and the day plans Ivy keeps for you. We also keep the record of what changed on an item — which field, what it was, and what it became — so its own history is there when you look.
- What you tell Ivy about your life — your conversations with the assistant, the prompts you save and the answers she produced for them, any rating or note you leave on one of her answers, and the context you give her so she can be useful: people who matter to you and dates you care about (a partner's birthday, for instance), your interests, your working hours, and, if you choose to track it, a sobriety start date. You decide what to share; you can review and remove any of it in Sage.
- Profile details you choose to add — your name, city and state, and a birthdate if you enter one.
- Connected services (only if you connect them) — calendar events and email you choose to sync from Microsoft Outlook or Google, either via sign‑in or a Power Automate flow you set up yourself. We store this so Sage can display it and give Ivy context, along with the access tokens that let Sage read it and a note of whether that connection is currently working, so Sage can tell you when it needs reconnecting. If you connect Google, see "Google user data" below for exactly what is requested, stored, and never done with it.
- Your daily briefing — if you have the briefing turned on, Sage composes one for you each morning and keeps a copy of it on your account. That copy is the whole briefing as it was rendered: the titles, times and locations of that day's calendar events, the senders and subject lines of your unread mail, your to‑dos, goals, weight entries and milestones, whatever weather, news and scores you asked it to include, and the address it was emailed to. It is the most personal single object Sage produces, and it is kept for a reason — a mail gateway can quarantine an email without telling anybody, and the copy in Sage is how you still get to read it. Sage deletes it automatically fourteen days later.
- Companions — who you are connected to as a Companion, and the to‑dos you send them or they send you, including whatever you chose to put in one.
- Notifications — the alerts in your Sage inbox, which quote whatever they are about: a to‑do's title, an event, a briefing that is ready.
- Your settings and preferences — how you have arranged your dashboard and your briefing, the teams and topics you follow, your timezone and working hours, and which alerts and messages you have dismissed or muted.
- What you send us — if you send feedback from inside Sage, or email us, we keep your message and the address it came from, so we can answer it and fix what it describes.
- Mail we could not deliver — if a message Sage sends you bounces or is refused, we record the address, the reason given, and when it happened, so Sage can warn you that its mail is not arriving instead of failing quietly. Separately, if somebody tries to create an account with an address that already has one, Sage emails that address once to say so and records that it did — so the same address cannot be mailed on a loop by anyone repeating the attempt.
- Records of your use of Ivy — for each request you make to the assistant: which part of Sage it came from, which model answered, how much text went in and out, and what it cost us. This is a meter, not a transcript — none of what you said to her is in it. It is what enforces the daily ceiling on AI spending, and what tells us what Sage costs to run.
- Addresses you enter — a ZIP code for local weather, and, if you use the commute and travel‑time features, a home and work address. Those addresses are sent to Google Maps Platform to calculate a route or travel time, and to look up a place you are typing. We store them on your account so you do not have to type them again. On the web you can change or clear them at any time — the home address under Settings → General → Home Address, the work address under Settings → Work → Work Details. The iOS app asks for them during setup and has no screen for editing them yet.
- Device tokens — if you turn on notifications, an identifier from Apple that lets us send a notification to that device, and nothing else.
How we use your information
We use your information only to provide and improve the features of Sage that you see and use. We do not use it for advertising, we do not sell it, we do not build advertising or marketing profiles from it, and we do not use it to train AI models.
- To operate your Sage dashboard and show your information back to you.
- To let Ivy, the assistant, answer questions using your to‑dos, calendar, and email as context.
- To send the alerts and notifications you enable.
Google user data
If you connect a Google account, Sage requests three permissions and uses each only for the feature it names:
- See your email messages and settings (
gmail.readonly) — to show your recent mail on your dashboard and to let Ivy answer questions about it. Sage reads mail; it never sends, deletes, or modifies anything in your mailbox.
- See your calendars (
calendar.readonly) — to show your agenda and reason about your schedule. Sage never creates or changes events.
- See your primary email address (
userinfo.email) — to identify which account is connected.
What we store. To make your dashboard load quickly and to give Ivy context, Sage stores a copy of your recent messages — sender, subject, date, and the message body text (email snippets) — along with your recent and upcoming calendar events. This copy lives in Sage's own database, is tied to your account, and is never visible to another Sage user. Older mail is discarded as newer mail syncs; we keep roughly your most recent few hundred messages, not your whole mailbox. Attachments are not downloaded or stored.
What we never do. We do not sell Google user data, use it for advertising, use it to build advertising or marketing profiles, or transfer it to anyone except as needed to provide the features above. We do not use Google user data to develop, improve, or train generalized or non‑personalized AI or machine‑learning models. No human at Sage reads your mail. The only exceptions Google's policy allows, and the only ones we would use, are: with your explicit consent, for security purposes such as investigating abuse, or to comply with applicable law.
Ivy and your Google data. When you ask Ivy something, the relevant context — which may include the text of an email or a calendar entry — is sent to our AI provider (Anthropic) solely to generate that one answer for you. Anthropic acts as our service provider for that request: the content is not used to train Anthropic's models or ours, and it is not retained for any other purpose. This transfer happens only because it is what makes the assistant feature work.
The spoken briefing and your Google data. If you use the Morning Routine, Sage reads your day aloud. The lines it speaks — which can include the titles and times of your calendar events, and the subject lines and sender names of your unread mail — are sent as text to OpenAI's text‑to‑speech API, which returns the audio. OpenAI acts as our service provider for that request only. It is not used to train OpenAI's models or ours, and Sage requests no other processing. If you never use the spoken briefing, no Google data is sent to OpenAI at all.
Google user data and other people. Sage never shares your Google user data with other Sage users automatically, and never shares it with anyone for their own purposes. One deliberate exception exists and it is entirely in your hands: if you use a feature that turns something into a to‑do item — for example asking Ivy to act on an email — and you then choose to send that to‑do to a Companion, whatever you put in it goes with it, exactly as it would if you typed it yourself. Sage never does this on your behalf.
Your control. On the web you can disconnect Google at any time in Settings → Integrations, which stops all further syncing; the iOS app can connect an account but cannot yet disconnect one. From any device, you can also revoke Sage's access directly from your Google Account at myaccount.google.com/permissions, which has the same effect. Deleting your account removes the stored copy along with everything else — see Data retention & deletion below.
Sage's use and transfer of information received from Google APIs — including Google Workspace APIs — to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: raw, aggregated, anonymized and derived data received from those APIs is never used, transferred or sold to create, train or improve any foundational or generalized artificial‑intelligence or machine‑learning model, whether ours or a third party's.
AI processing
Sage uses two AI service providers, and only ever as service providers acting on a single request from you:
- Anthropic (Claude, via the paid commercial API) powers Ivy. The relevant context — a to‑do, a calendar item, or the email you're asking about — is sent so Ivy can answer. Under Anthropic's commercial terms, inputs and outputs are not used to train their models.
- OpenAI (via the paid API) provides two things: the voice that reads your Morning Routine aloud (text‑to‑speech), and transcription of audio you dictate, such as a voice capture from your watch or phone (speech‑to‑text). Under OpenAI's API terms, data sent through the API is not used to train their models by default, and Sage has not opted in to any such sharing.
Neither provider is permitted to use your content for anything except returning that one result to Sage. We do not use your data — from Google or anywhere else — to develop, improve or train AI or machine‑learning models, and we do not transfer it to any AI provider that would.
Where your information is held, and who else it reaches
Sage does not run on its own hardware, and some of what it does cannot be done without asking somebody else a question. This is every company that holds, carries or receives any part of your information in the course of running Sage, and the only thing each one gets. Sage sends nothing about you to anyone who is not on this list.
- Railway — our hosting provider. Sage's server and the database holding everything described above run on Railway's infrastructure, so Railway holds your data on our behalf. It does not use it for anything of its own. Sage's server and its database run on Railway's machines.
- Cloudflare — sits in front of sageoe.com. Every request from your browser or your phone passes through Cloudflare before it reaches Sage, so Cloudflare sees the connection itself: your IP address, and which page or endpoint you asked for. Cloudflare also stores Sage's daily offsite backup, which is a copy of the whole database. Sage's server connects to r2.cloudflarestorage.com.
- Google — if you connect a Google account, Sage's requests for your mail and calendar go to Google's APIs. See "Google user data" above for exactly what that covers. Sage's server connects to accounts.google.com, gmail.googleapis.com, mail.google.com, oauth2.googleapis.com, www.googleapis.com.
- Microsoft — the same, if you connect Outlook or Microsoft 365: Sage signs in and reads your mail and calendar through Microsoft Graph. Sage's server connects to graph.microsoft.com, login.microsoftonline.com.
- Google Maps Platform — an address or place name, when you use commute times, travel‑time estimates, or address autocomplete. If Ivy works out when you need to leave for something, the destination for that trip is sent too. Sage's server connects to places.googleapis.com, routes.googleapis.com.
- Anthropic and OpenAI — the context for one answer from Ivy, the text of one spoken briefing, or one audio clip you dictated, as described under AI processing. Sage's server includes their own software (@anthropic-ai/sdk, openai).
- Stripe — payment processing and your email address, as described under Payments and subscriptions. Sage's server includes their own software (stripe).
- Apple — subscription verification for iOS purchases, and, if you enable notifications, the notification itself so your device can be reached. Sage's server connects to api.push.apple.com, api.sandbox.push.apple.com; Sage's server includes their own software (@apple/app-store-server-library).
- Resend — our email sender, for the mail Sage sends you: password resets, your daily briefing if you turn it on, and account notices. Sage's server connects to api.resend.com.
- Weather — the ZIP code you gave us goes to Zippopotam.us, a public postcode lookup, to be turned into coordinates. Those coordinates then go to the U.S. National Weather Service, which is where forecasts come from today, or to Open-Meteo if we switch providers. Neither request carries your name, your account, or anything about you beyond that location. Sage's server connects to api.zippopotam.us, api.weather.gov, www.weather.gov, api.open-meteo.com, customer-api.open-meteo.com, open-meteo.com.
- News and sports — headlines come from publishers' own feeds, and can be switched to a commercial news service (NewsAPI, GNews or the Guardian's) without that changing; scores come from ESPN's public endpoints. Sage's own server makes all of these requests, on a timer, and sends nothing that identifies you or says who is reading. Sage's server connects to site.api.espn.com, www.espn.com, feeds.arstechnica.com, feeds.bbci.co.uk, feeds.content.dowjones.io, feeds.npr.org, rss.politico.com, variety.com, www.aljazeera.com, www.sciencedaily.com, www.theverge.com, newsapi.org, gnews.io, bonobo.capi.gutools.co.uk, content.guardianapis.com, open-platform.theguardian.com.
- Google Fonts — Sage's web pages load two typefaces from Google's font service, so your browser tells Google its IP address when it fetches them. Nothing about your account goes with that request. Sage's server connects to fonts.googleapis.com, fonts.gstatic.com.
Payments and subscriptions
Sage has a free tier and a paid one. If you subscribe, how your payment is handled depends on where you subscribed.
- On the web, payments are processed by Stripe. You enter your card details on Stripe's own checkout page — Sage never sees or stores your card number. We store what we need to know that your subscription exists and is current: a Stripe customer and subscription reference, which plan you are on, its status, and when the current period ends. Stripe also receives your email address so it can send you receipts and, if a payment fails, tell you. Stripe processes this as its own controller under Stripe's privacy policy.
- In the iOS app, purchases go through Apple, and Apple handles the payment entirely. Sage receives only a confirmation from Apple that a subscription is valid, which we verify with Apple directly. We never see your payment details, and we cannot cancel or refund an Apple subscription ourselves — Apple owns that.
If you redeem a promotional code, we record that you used it — which is what stops the same code being used twice. If we grant you a paid plan directly, for instance a comped or a staff account, we keep a record of who granted it and why. When a subscription starts we email you once to say so, and record that we sent it, so a repeated notice from Stripe or Apple cannot make the same email arrive again. And if you administer Sage and you create a promotional code, we store the code and its limits along with a record that you created it.
We do not use anything about your payments for advertising or profiling, and we do not sell it.
Sharing
We do not sell your personal information, and we do not share it with anyone for their own purposes. We share it only in these ways:
- Service providers who make a feature work — for example the AI processing described above. They may use it only to perform that service for us.
- People you deliberately send something to — if you send a to‑do item to a Companion, that item goes to them, including whatever you chose to put in it. This only ever happens because you asked for it; Sage never shares your content with another person on its own.
- When the law requires it, or to investigate abuse and keep the service secure.
Data retention & deletion
On the web you can disconnect a connected account at any time in Settings → Integrations, which stops further syncing and removes the tokens for it. The iOS app cannot do that yet; revoking Sage's access from Google or Microsoft achieves the same thing from any device.
You can delete your account yourself, from inside Sage — on the web at Settings → General → Account, and on iOS at Settings → Account → Delete account. It asks for your password, then removes your account and the data attached to it in one pass: your to‑dos and lists, checklists, goals, habits, weight entries, people and dates, interests, Ivy conversations and day plans, your stored briefings, your notifications, the synced copy of your mail and calendar, connected‑account tokens, notification devices, and your settings. If you pay through the web, Sage cancels that subscription first and refuses to delete anything if the cancellation fails — so an account can never be deleted while a card keeps being charged. If you subscribed in the iOS app, only Apple can cancel it: Sage will decline the deletion and ask you to cancel with Apple first (Settings → your name → Subscriptions), then come back.
Deletion is immediate and cannot be undone. Backups are kept for operational recovery and roll off on their own schedule; we do not restore deleted accounts from them. If you would rather we did it for you, email [email protected].
Some things expire on their own, without you doing anything: a stored briefing after 14 days, a ride‑along day plan after 60, a notification you have read after 90 days and one you have not after 365, a password‑reset token after 7 days, the sign‑in for a device you have not used in 180 days, the marker that remembers you dismissed an email after 365, and the marker that remembers Sage already warned an address after 24 hours. The meter of your Ivy usage is kept for 400 days, because it is what answers a question about a bill. Everything else is yours until you delete it, or delete your account.
Security
Data is transmitted over encrypted connections and stored on access‑controlled servers. Connected‑account tokens and per‑user sync keys are stored per account and are not shared across users.
What is encrypted inside the database, and what is not. Three things carry their own encryption within Sage's database, so that a stolen copy of the file does not disclose them: the tokens for a connected account; the copy of your mail and calendar that Sage syncs — senders, subjects, message text, event titles and locations; and, if two‑factor sign‑in is set up on your account, the secret behind two‑factor sign‑in. The rest of what you keep in Sage — your to‑dos, your conversations with Ivy, your day plans and your stored briefings — is held as ordinary text in that database, protected by the access controls and encrypted connections around it rather than by encryption of its own. The same facts appear in several of those places, so encrypting one of them and not the others would change how this paragraph reads without changing what a stolen backup would show. We would rather say that plainly than imply more than is true.
Contact
Questions about this policy? Email [email protected].
We will update this policy as Sage changes. If a change materially affects how we handle your information, we will say so here and change the date above.
Home · About Sage · Terms · Support
© 2026 SageOE LLC