Sage
Privacy Policy
In short
- Sage is a voice coach. During a session, your voice is streamed live to Sage's server and on to the AI voice model that listens and speaks as Sage. We keep the transcript, the notes, and a private summary Sage uses to remember you. We do not keep the audio.
- You sign in with Apple. We receive a stable identifier for you and, the first time, your name and email if you choose to share them.
- No ads, no trackers, no analytics kits. We never sell your data or share it for marketing.
- Your conversations are stored privately in Sage, encrypted on our servers. We do not look at them unless you ask us to or the law requires it. AI tools you connect can retrieve context under the access you grant. You can disconnect them at any time.
- Your sessions are yours. Delete any session on your phone and, after thirty days in Recently Deleted, it leaves our servers too, or delete your account in Settings and everything goes, on your phone and on our servers.
- Sage is for adults. You confirm you are 18 or older when you set it up.
Who we are
Sage is made by Omer Ekin, an independent developer. When this policy says "we", it means him. Questions about this policy or your data go to omerekin4@gmail.com.
What Sage collects, and why
Your account
When you sign in with Apple, Apple gives us a stable identifier that stands for you in Sage. We turn it into an account id so that a second phone signed in with the same Apple Account finds the same sessions. Apple also sends your name and email the first time you sign in, unless you hide them. If you use Apple's "Hide My Email", we receive a relay address instead, and that is what we keep. We use your email only to reach you about your account.
Your profile
The name you ask Sage to call you, the core values you choose, and your phone's language and time zone. Sage uses these to address you, to speak your language, and to shape sessions around what matters to you. They are kept on our server with your account, and updated when you change them in the app, so a new phone signed in with the same Apple Account finds them.
Your sessions
A session is a live conversation. While it runs, your voice is streamed to our server and on to the voice model that listens, transcribes what you say, and speaks Sage's replies. When it ends we keep:
- the transcript, that is what you said and what Sage said;
- the notes Sage writes afterwards: a title, Insights and Shifts, and Intentions, with each intention also kept in a few words for the card at the top of your sessions;
- the edits you make to a note afterwards, so your record is the same on every phone, and, for sessions before September 28, 2026, anything you typed in the notepad the app had then;
- Sage's memory of you: after each session, a short private record of what from it matters over time, and a summary of you rebuilt from all of those records: your goals, what is still unfolding, what you have said about yourself, what gives you energy and what drains it, and how you have changed, in your own words where possible. It is how Sage knows you across all your sessions and not only the last few. Sage reads it at the start of each session. It is not shown in the app; you can ask us for a copy;
- when the session started and ended, how long it was allowed to run, and, for sessions from earlier versions of the app, whether it was one of your scheduled sessions;
- how the conversation ran, in numbers only: when each of you was speaking and for how many words, and how long Sage took to respond. We keep this so that a problem like Sage leaving you in a long silence can be found and fixed without anyone opening your session. It never includes anything that was said, and it is removed if you discard the session;
- where you were: the city, and the park, landmark or part of the city when Apple knows one, only if you allowed location access (see below).
The audio itself is not recorded and not stored, on your phone or on our servers.
Your location
Optional. If you allow it, your phone asks Apple where you are and Sage attaches two names to the session, so you can look back at where a conversation happened: the city, and, when Apple knows one, the park or landmark you are in or your neighborhood (such as "Central Park" or "Back Bay"). In New York City, where Apple names only the borough, the neighborhood comes from a list of neighborhood names kept inside the app, so nothing more leaves your phone for it. Sage never keeps a street address or the name of a business, and if you allow only an approximate location it keeps the city alone. Sage only ever sees these names, never your coordinates. You can turn this off at any time in iOS Settings.
Your phone
The first time Sage runs it creates a cryptographic key on your phone. The private half never leaves the phone's secure hardware; the public half is registered with our server and identifies this install. Every request the app makes is signed with that key and carries a timestamp and the app version; registering the install also tells us the platform. Our server keeps ordinary connection logs, including IP addresses, for a short time for security and troubleshooting.
Sage uses the microphone only during a session, and only for the conversation and its transcript.
Notifications
Optional. The daily reminder, if you turn it on, and "your notes are ready" alerts are scheduled locally on your phone; there is no push notification server. Earlier versions of Sage could also keep your scheduled sessions in your calendar. If you allowed that, the current version removes those events the first time it runs and uses your calendar for nothing else.
Feedback
"Send Feedback" opens your mail app with a draft addressed to us. The draft ends with the app version, your iOS version, and your phone's model, so we can tell which build you are describing; you can see and delete those lines before sending. Whatever you choose to send, and the address you send it from, reaches us by email like any other message.
Connected AI tools
You can connect your own AI assistant, such as ChatGPT, Claude, or Gemini, to your Sage record, so it can draw on what you have been working through. This only ever happens when you sign in with your Apple Account on the page the tool opens, see which tool is asking, and choose what it may read: your profile and core values, your session notes, and the full transcripts. Transcripts are off unless you turn them on. A connected tool reads what you allowed and nothing more; it cannot change or delete anything. The app shows every tool you have connected and what it read, and you can narrow its access or disconnect it at any time, which cuts it off immediately. What a connected tool does with what it reads is governed by that tool's own privacy policy.
How we use it
- To hold sessions. Your live audio goes to the voice model that listens and speaks as Sage. The transcript, your profile, Sage's summary of you, and the notes from your last few sessions go to the language model that decides what Sage says, so it can respond and pick up where you left off.
- To write your notes. The transcript is summarized into the session note you see in the app, and each intention in the note, including one you have reworded, is put into a few words by the same AI provider for the card at the top of your sessions. Each session is first read once by the same AI provider to tell whether it was started by mistake; if so, no note is written unless you ask for one in the app. We can see that a session was marked that way, never what was said in it.
- To remember you over time. After each session the transcript is read once more to write Sage's private record of that session, and your summary is rebuilt from all of those records, taking your edits to a note over what Sage wrote.
- To answer the AI tools you connect. When a connected tool asks, we give it the parts of your record you allowed it, and note that it did.
- To keep Sage fair and affordable. Session length and the number of sessions per day are limited; we count minutes per account to enforce that. We also see when sessions happen, how long they run, how the timing within them went (who was speaking when, how quickly Sage responded, and which of Sage's voice setups and AI models ran the session), and which app build and connected tools each account uses. Never what was said.
- To keep Sage secure and to answer you when you write to us.
We do not use your sessions, notes, or transcripts to improve Sage or to train any model. Should that ever change, it would be a choice you make in the app, off unless you turn it on, and this policy would say so first.
We do not show ads, build marketing profiles, or sell or rent your data. There are no third-party analytics or advertising kits in the app.
Where your data lives
| Data | On your phone | On Sage's servers |
|---|---|---|
| Session notes and transcripts | Yes | Yes |
| Sage's memory of you | No | Yes |
| Audio of your sessions | Not stored | Not stored, streamed live only |
| Name, core values, language, time zone | Yes | Yes |
| Apple account id and email | Yes, Apple's identifier in the keychain | Yes |
| City and place of a session | Yes, if allowed | Yes, if allowed |
| Daily reminder | Yes, if you turn it on | No |
| Install key | Private half, in secure hardware | Public half only |
| Connected AI tools and what they read | No | Which tool, what access, when it read what |
Who else processes your data
Sage runs on a few services that act on our instructions. Each one receives only what it needs to do its job, under its own terms for developers, and none of them may use your data for their own purposes or to train their models.
| Service | What it does for Sage | What it receives |
|---|---|---|
| Apple | Sign in with Apple; turning your location into a city and place name; notifications on your phone. | Handled by iOS under Apple's own privacy policy. |
| LiveKit | Carries the live audio between your phone and Sage's server. Through LiveKit Inference it also turns what you say into text and Sage's words into Sage's voice, using speech models from xAI, with Google's as a backup. LiveKit Inference keeps none of it. | Live audio, your account id and name, the session details the app sends (city and place, language, and time zone; from earlier versions of the app, also whether it was a scheduled session), and the words Sage says. Recording is turned off. |
| OpenAI | Provides GPT-Live, a voice model Sage can use instead of the speech models above. When it does, it listens to you and speaks as Sage. | Your live audio, your first name and language, the conversation as it unfolds, and the words Sage says next. |
| Anthropic | Provides Claude, the AI model that decides what Sage says and writes your notes. | The transcript as it happens, your profile and core values, the city and time of the session, notes from your recent sessions, and Sage's summary of you. After a session, the transcript again, to write Sage's memory of it, and those memories, to rebuild the summary; and a note's intentions, to put each in a few words. |
| Fly.io | Runs Sage's server, in Virginia. | Whatever the server handles while it runs. Nothing is stored there. |
| Neon | Hosts Sage's database, in the same region. | Your account, profile, transcripts, notes, and Sage's memory of you in encrypted form, plus the ids and timestamps kept in the clear. |
These services operate in the United States and other countries. Using Sage means your data may be processed there.
Beyond these services, we share personal data only if the law requires it, or to protect the rights and safety of you, us, or others.
How long we keep it
- Sessions, transcripts, and notes stay until you delete them or your account. A deleted session stays in Recently Deleted for thirty days and is then deleted for good, or sooner if you delete it from there.
- Sage's memory of you keeps what a session added for as long as the session exists, including while it is in Recently Deleted. When a session is deleted for good, Sage stops using the summary until it has been rebuilt without that session, which happens within minutes.
- Connected AI tools stay connected until you disconnect them. The record of what a tool read is kept for ninety days.
- Your account and profile stay as long as your account exists.
- Session credentials are valid for minutes and their records are cleared within two days.
- Connection logs are kept for a short period for security and troubleshooting.
When you delete your account, everything under it is removed from our servers right away, and the key that could read it is destroyed. The database keeps a short recovery history, currently less than a day, and any copy of your records in it is unreadable without that key.
Your choices
- Delete your account. Settings, then Delete account. This removes your account, every session, note, and transcript, on this phone and on our servers, and tells Apple to disconnect the sign-in. It cannot be undone.
- Sign out. Settings, then Sign out. Your sessions stay on the phone and under your account; sign in again to continue.
- Delete a session. Swipe it and tap Delete, and it moves to Recently Deleted. It disappears from your sessions, from the notes Sage reads at the start of a session, and from connected tools right away. What it added to Sage's summary of you stays until the session leaves Recently Deleted, when it is deleted from our servers and the summary is rebuilt without it. Restore it within thirty days if you change your mind, or delete it from Recently Deleted to remove it now.
- Discard a session. On the session screen, Discard session ends the conversation and throws it away: the transcript is not kept and no note is written.
- Disconnect an AI tool. Settings, then Connected AI tools. Disconnecting takes effect immediately; you can also change what a tool may read there.
- Change permissions. Microphone, location, and notifications can each be turned off in iOS Settings under Sage. Without the microphone, sessions cannot start.
- Disconnect Sign in with Apple from your Apple Account settings at any time. Sage will sign you out the next time it opens.
- Ask us. Wherever you live, you can ask us to send you a copy of your data, correct it, or delete it. Email us and we will answer within 30 days.
Security
Requests between the app and our server are signed by the key on your phone and travel over encrypted connections, as does the live audio. On our servers, everything personal, your transcripts, notes, name, values, and email, is encrypted before it is stored, with a key that exists only for you and is itself locked by a master key. Sage's backend uses the master key to read your record when its work needs it: to remember past sessions, to write your notes, and to answer the AI tools you connect. The database and its backups contain only the encrypted form. A recovery copy of the master key is kept separately, so the service can be restored if its server is lost. Because the backend can read your record, the person who runs Sage technically could too. We do not look at your conversations unless you ask us to, for example to investigate a problem you report, or the law requires it. When you delete your account, your key is destroyed, which makes any remaining copy unreadable. Connected AI tools authenticate with short-lived tokens that you can revoke at any time. No system is perfectly secure; if you believe something is wrong, please tell us at the address below.
Children
Sage is for people 18 and older. We do not knowingly collect data from anyone younger. If you believe a minor has used Sage, write to us and we will delete their data.
Changes to this policy
When this policy changes, we post the new version here with a new effective date. If a change matters to how your data is used, we will also say so in the app before it takes effect.
Contact
Omer Ekin, developer of Sage