Sage Privacy Policy
Sage

Privacy Policy

In short

Who we are

Sage is made by Omer Ekin, an independent developer. When this policy says "we", it means him. Questions about this policy or your data go to omerekin4@gmail.com.

What Sage collects, and why

Your account

When you sign in with Apple, Apple gives us a stable identifier that stands for you in Sage. We turn it into an account id so that a second phone signed in with the same Apple Account finds the same sessions. Apple also sends your name and email the first time you sign in, unless you hide them. If you use Apple's "Hide My Email", we receive a relay address instead, and that is what we keep. We use your email only to reach you about your account.

Your profile

The name you ask Sage to call you, the core values you choose, and your phone's language and time zone. Sage uses these to address you, to speak your language, and to shape sessions around what matters to you. They are kept on our server with your account, and updated when you change them in the app, so a new phone signed in with the same Apple Account finds them.

Your sessions

A session is a live conversation. While it runs, your voice is streamed to our server and on to the voice model that listens, transcribes what you say, and speaks Sage's replies. When it ends we keep:

The audio itself is not recorded and not stored, on your phone or on our servers.

Your location

Optional. If you allow it, your phone asks Apple where you are and Sage attaches two names to the session, so you can look back at where a conversation happened: the city, and, when Apple knows one, the park or landmark you are in or your neighborhood (such as "Central Park" or "Back Bay"). In New York City, where Apple names only the borough, the neighborhood comes from a list of neighborhood names kept inside the app, so nothing more leaves your phone for it. Sage never keeps a street address or the name of a business, and if you allow only an approximate location it keeps the city alone. Sage only ever sees these names, never your coordinates. You can turn this off at any time in iOS Settings.

Your phone

The first time Sage runs it creates a cryptographic key on your phone. The private half never leaves the phone's secure hardware; the public half is registered with our server and identifies this install. Every request the app makes is signed with that key and carries a timestamp and the app version; registering the install also tells us the platform. Our server keeps ordinary connection logs, including IP addresses, for a short time for security and troubleshooting.

Sage uses the microphone only during a session, and only for the conversation and its transcript.

Notifications

Optional. The daily reminder, if you turn it on, and "your notes are ready" alerts are scheduled locally on your phone; there is no push notification server. Earlier versions of Sage could also keep your scheduled sessions in your calendar. If you allowed that, the current version removes those events the first time it runs and uses your calendar for nothing else.

Feedback

"Send Feedback" opens your mail app with a draft addressed to us. The draft ends with the app version, your iOS version, and your phone's model, so we can tell which build you are describing; you can see and delete those lines before sending. Whatever you choose to send, and the address you send it from, reaches us by email like any other message.

Connected AI tools

You can connect your own AI assistant, such as ChatGPT, Claude, or Gemini, to your Sage record, so it can draw on what you have been working through. This only ever happens when you sign in with your Apple Account on the page the tool opens, see which tool is asking, and choose what it may read: your profile and core values, your session notes, and the full transcripts. Transcripts are off unless you turn them on. A connected tool reads what you allowed and nothing more; it cannot change or delete anything. The app shows every tool you have connected and what it read, and you can narrow its access or disconnect it at any time, which cuts it off immediately. What a connected tool does with what it reads is governed by that tool's own privacy policy.

How we use it

We do not use your sessions, notes, or transcripts to improve Sage or to train any model. Should that ever change, it would be a choice you make in the app, off unless you turn it on, and this policy would say so first.

We do not show ads, build marketing profiles, or sell or rent your data. There are no third-party analytics or advertising kits in the app.

Where your data lives

DataOn your phoneOn Sage's servers
Session notes and transcriptsYesYes
Sage's memory of youNoYes
Audio of your sessionsNot storedNot stored, streamed live only
Name, core values, language, time zoneYesYes
Apple account id and emailYes, Apple's identifier in the keychainYes
City and place of a sessionYes, if allowedYes, if allowed
Daily reminderYes, if you turn it onNo
Install keyPrivate half, in secure hardwarePublic half only
Connected AI tools and what they readNoWhich tool, what access, when it read what

Who else processes your data

Sage runs on a few services that act on our instructions. Each one receives only what it needs to do its job, under its own terms for developers, and none of them may use your data for their own purposes or to train their models.

ServiceWhat it does for SageWhat it receives
AppleSign in with Apple; turning your location into a city and place name; notifications on your phone.Handled by iOS under Apple's own privacy policy.
LiveKitCarries the live audio between your phone and Sage's server. Through LiveKit Inference it also turns what you say into text and Sage's words into Sage's voice, using speech models from xAI, with Google's as a backup. LiveKit Inference keeps none of it.Live audio, your account id and name, the session details the app sends (city and place, language, and time zone; from earlier versions of the app, also whether it was a scheduled session), and the words Sage says. Recording is turned off.
OpenAIProvides GPT-Live, a voice model Sage can use instead of the speech models above. When it does, it listens to you and speaks as Sage.Your live audio, your first name and language, the conversation as it unfolds, and the words Sage says next.
AnthropicProvides Claude, the AI model that decides what Sage says and writes your notes.The transcript as it happens, your profile and core values, the city and time of the session, notes from your recent sessions, and Sage's summary of you. After a session, the transcript again, to write Sage's memory of it, and those memories, to rebuild the summary; and a note's intentions, to put each in a few words.
Fly.ioRuns Sage's server, in Virginia.Whatever the server handles while it runs. Nothing is stored there.
NeonHosts Sage's database, in the same region.Your account, profile, transcripts, notes, and Sage's memory of you in encrypted form, plus the ids and timestamps kept in the clear.

These services operate in the United States and other countries. Using Sage means your data may be processed there.

Beyond these services, we share personal data only if the law requires it, or to protect the rights and safety of you, us, or others.

How long we keep it

When you delete your account, everything under it is removed from our servers right away, and the key that could read it is destroyed. The database keeps a short recovery history, currently less than a day, and any copy of your records in it is unreadable without that key.

Your choices

Security

Requests between the app and our server are signed by the key on your phone and travel over encrypted connections, as does the live audio. On our servers, everything personal, your transcripts, notes, name, values, and email, is encrypted before it is stored, with a key that exists only for you and is itself locked by a master key. Sage's backend uses the master key to read your record when its work needs it: to remember past sessions, to write your notes, and to answer the AI tools you connect. The database and its backups contain only the encrypted form. A recovery copy of the master key is kept separately, so the service can be restored if its server is lost. Because the backend can read your record, the person who runs Sage technically could too. We do not look at your conversations unless you ask us to, for example to investigate a problem you report, or the law requires it. When you delete your account, your key is destroyed, which makes any remaining copy unreadable. Connected AI tools authenticate with short-lived tokens that you can revoke at any time. No system is perfectly secure; if you believe something is wrong, please tell us at the address below.

Children

Sage is for people 18 and older. We do not knowingly collect data from anyone younger. If you believe a minor has used Sage, write to us and we will delete their data.

Changes to this policy

When this policy changes, we post the new version here with a new effective date. If a change matters to how your data is used, we will also say so in the app before it takes effect.

Contact

Omer Ekin, developer of Sage

omerekin4@gmail.com