Acceptable Use Policy

Sage hands you an agent that can write files and run commands on real machines. This page draws the line between building things and doing damage.

Why this policy exists

Sage is an agentic coding tool. It can read and write files, run shell commands you approve, and drive tasks on registered machines from a text message. That is a lot of leverage, and leverage cuts both ways. This policy sets the line between building things and doing damage. It applies to the sage-ai-cli tool, the web app, the mobile apps, and the SMS bridge — whether you are running a local model on your own hardware or routing a request through Sage's cloud.

Do not use Sage to break the law

No activity that is illegal where you are, where your machines are, or where the people affected are.
No infringing on someone else's copyright, trademark, patent, or trade secrets — including laundering licensed source code through a model to obscure its origin.
No violating the license of a model you download or run. Open weights are not the same thing as unrestricted weights.
No evading sanctions, export controls, or other trade restrictions.

Do not use Sage to attack systems

Security work is legitimate; unauthorized intrusion is not. The distinguishing factor is permission. Do not use Sage to:
Write, assemble, or refine malware, ransomware, worms, keyloggers, credential stealers, or botnet tooling.
Scan, probe, exploit, or gain access to networks, accounts, or devices you do not own and are not authorized in writing to test.
Build phishing pages, spoofed login flows, or social-engineering scripts aimed at deceiving people out of credentials, funds, or personal data.
Develop tools whose purpose is mass surveillance, stalking, or de-anonymizing individuals against their will.
Circumvent DRM, licensing checks, or authentication controls on software you do not own.
Authorized penetration testing, capture-the-flag exercises, vulnerability research on your own systems, and defensive security work are all permitted and welcome.

Do not use Sage to harm people

No content that sexually exploits or endangers children. This is an immediate, permanent ban with no appeal.
No harassment, targeted abuse, threats, doxxing, or incitement to violence.
No generating sexual content involving real people without consent, including synthetic imagery of identifiable individuals.
No instructions for building weapons, explosives, or chemical, biological, radiological, or nuclear devices.
No coordinated disinformation, impersonation of real people or organizations, or fabricated news presented as fact.
No automated fraud, spam campaigns, fake reviews, or bulk unsolicited messaging.

Do not abuse the infrastructure

Do not share, resell, or sublicense your account or API access. One account is for one person.
Do not use scripts or automation to evade plan limits, rotate through free accounts, or otherwise avoid paying for output tokens you consume.
Do not attempt to extract model weights, reverse-engineer Sage's cloud routing, or bypass the anonymization layer.
Do not deliberately overwhelm the service, disrupt other users, or probe Sage's own systems for vulnerabilities without contacting us first.

The SMS bridge carries extra responsibility

The SMS bridge lets you fire tasks at your registered computers from iMessage, Google Messages, or email. Anything that arrives from an allowlisted sender can act on that machine. Keep the allowlist tight, remove numbers you no longer control, and treat a lost phone as a compromised credential — revoke it from the Devices page immediately. You are responsible for every task executed on a machine you registered.

You own what you run

Because Sage is local-first, most prompts never reach us and we cannot see them. That is a privacy guarantee, not a loophole. This policy applies with equal force to work done entirely on your own hardware — we simply cannot be the ones to catch it. The responsibility sits with you.

Enforcement

When we become aware of a violation — through a report, a billing anomaly, or a legal request — we respond in proportion to what happened. That can mean a warning, a rate limit, suspension of cloud model access, or permanent termination of the account. Violations involving child sexual abuse material, credible threats of violence, or active attacks on third parties are terminated immediately and may be referred to law enforcement. Where an account is terminated for a violation, no refund is issued.

Reporting abuse

If you believe someone is using Sage in a way this policy forbids, email support@sageworksai.com with as much detail as you can share. If you have found a security vulnerability in Sage itself, send it to the same address rather than disclosing it publicly, and give us a reasonable window to fix it.
Last updated: July 24, 2026