Privacy Policy
Last updated: July 29, 2026
Sage (“Sage”, “we”, “us”) is a personal AI assistant available at https://app.sage.fyi. This policy explains what information Sage collects, why, who else processes it, how long it is kept, and how to have it deleted. It applies to the Sage web application and to this website.
Information we collect
- Account information. The email address you sign in with, and — if you sign in with Google — the basic profile information Google returns for that sign-in (your Google account identifier, email address, and, where you provide one, a display name and avatar). You may also set a username, display name, and profile picture yourself.
- Content you give the assistant. Your messages, uploaded files, documents created in your workspace, notes the assistant records about your preferences (“memory”), scheduled instructions, and messages sent to the email address your account is assigned.
- Data from services you connect. If you connect Google, GitHub, or another third-party service, Sage accesses data in that account on your behalf, within the permissions you granted. See Google user data below.
- Credentials for connected services. OAuth access and refresh tokens, and any API keys you enter in Settings. These are stored encrypted and are never shown back to you, to the model, or to any browser after you save them.
- Operational data. Session records, request and error logs, timestamps, IP-derived request metadata produced by our hosting provider, and usage counters used to apply rate and plan limits. We do not use advertising cookies or third-party analytics or tracking pixels.
How we use information
- To run the assistant: answering you, executing the tools you ask for, and keeping your chat history, memories, and files available to you.
- To authenticate you, keep your account secure, and enforce workspace access rules.
- To operate the service: preventing abuse, applying usage limits, diagnosing failures, and keeping backups.
- To communicate with you about the service, including sign-in emails and replies the assistant sends at your request.
We do not sell your information, we do not share it with advertisers, and we do not use your content to train generalized AI or machine-learning models.
Google user data
Connecting a Google account is optional and separate from signing in. When you connect one, Sage requests these OAuth scopes:
openidandemail— to identify which Google account was connected.https://mail.google.com/— to search, read, label, send, and trash mail in that account when you ask the assistant to.https://www.googleapis.com/auth/calendar— to list, create, update, delete, and respond to events in that account’s calendars.https://www.googleapis.com/auth/drive— to search for and read files in that account’s Drive.
Data returned by these APIs is used only to carry out the request you made in your Sage conversation, and to show you the result. Message bodies, event details, and file contents are read at the time of the request; what persists is the part of the exchange that lands in your own chat history, workspace files, or memories, all of which you can delete. Google access and refresh tokens are held encrypted on our servers and are never exposed to the model, to your browser, or to code running in your workspace sandbox.
Limited Use. Sage’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is not used for advertising, is not sold, is not transferred to others except as needed to provide or improve the assistant’s features you requested, to comply with applicable law, or as part of a merger or acquisition, and is not used to develop, improve, or train generalized AI or ML models. Human access to Google user data occurs only with your explicit consent, for security purposes, to comply with applicable law, or on aggregated, anonymized data used for operational reporting.
You can disconnect a Google account at any time in Sage under Settings → Connections, which revokes the token, or from Google account permissions.
How your content reaches an AI model
Answering you requires sending the relevant part of your conversation — which may include your messages, retrieved memories, file contents, and results returned by tools such as Gmail, Calendar, Drive, or web search — to a large-language-model provider. This is routed through OpenRouter to the model provider serving the configured model. Those providers process the request to generate the response. We select providers that do not train on submitted content, but their handling is governed by their own terms.
Service providers
- Cloudflare — hosting, application runtime, per-user databases, file storage, embeddings, browser automation, email routing, and bot protection on the sign-in page. Substantially all Sage data is stored on Cloudflare infrastructure.
- OpenRouter and the model providers it routes to — generating assistant responses.
- Google — sign-in; the Gmail, Calendar, and Drive APIs for accounts you connect; and font hosting for the application (this website serves its fonts itself).
- Other services you connect yourself, such as GitHub or an MCP server. You choose these; data flows to them only through actions you authorize.
These providers process data on our behalf to deliver the service. We may also disclose information where required by law, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or transfer of the service.
Retention and deletion
Chats, memories, files, and connections are kept until you delete them or ask us to delete your account. Deleting content in the app removes it from every surface of the product, but the underlying record is retained in your account’s storage so that mistaken deletions are recoverable; it is not permanently erased at that point. Operational logs are short-lived and retained only as long as needed to run and secure the service. Disconnecting a third-party service permanently erases its stored credential secrets.
To have your information permanently erased, request deletion of your account: write to support@sage.fyi from your account email address, and we will remove your account’s data from our systems and backups without undue delay.
Security
Traffic is served over HTTPS. Each user’s data lives in a separate per-user database, and workspace files run in a per-user isolated sandbox. Third-party credentials are stored in an encrypted vault, decrypted only for the specific outbound request that needs them, and stripped from anything shown to the model or the browser. Sessions can be revoked centrally. No system is perfectly secure, but we design for these boundaries and treat a break in them as a serious incident.
Your choices and rights
You can view and delete your chats, memories, and files in the app, disconnect any connected service, and request access to, correction of, or deletion of your personal information by writing to support@sage.fyi. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to processing or to lodge a complaint with your local supervisory authority.
International transfers
Sage runs on globally distributed infrastructure, so your information may be processed in countries other than your own, including the United States.
Children
Sage is not directed to children under 13 (or the minimum age of digital consent where you live), and we do not knowingly collect their information. If you believe a child has given us information, write to us and we will delete it.
Changes to this policy
We will update this page when our practices change and revise the “last updated” date above. Material changes will also be communicated in the app or by email.
Contact
Questions about this policy or about your data: support@sage.fyi.