Privacy Policy

Sage is local-first by design. This policy explains exactly what we collect, what we never collect, and how you can delete any of it at any time.

1. Our local-first principle

Sage runs on your machine by default. When you use a local model, your prompts, your source code, and your files are processed entirely on your own hardware and are never transmitted to us or to any third party. There is no background telemetry of your prompt contents.

2. What we collect

We collect only what is required to operate your account and bill you accurately:
Account identity — your email address and the provider you signed in with (Google or Apple), plus a Sage user ID.
Subscription and billing state — your plan tier, renewal date, and payment status. Card numbers are never stored on Sage servers; they are handled by our payment processor.
Usage metering — the number of output tokens you consume, so we can enforce plan limits and bill overages. We record counts, not content.
Device registry — a name and identifier for each computer you pair with the SMS bridge, so tasks can be routed to the right machine.
Operational logs — timestamps, error codes, and request IDs used to keep the service running and to debug failures.
Conversation history for cloud models — when you choose a cloud-hosted model, the messages in that conversation are stored on Sage servers so your history is there when you come back. Conversations with local models are not.
Files you attach — a file you attach to a message is uploaded to Sage servers, stored, and its text is included in the request sent to the model you chose.
Crash and diagnostic reports — the mobile apps include Firebase Crashlytics. When the app crashes it sends Google a stack trace, your device model, OS version, and a Crashlytics installation identifier. It does not send your conversations.

3. What we do not collect

We do not store the contents of prompts or responses generated by local models.
We do not sell, rent, or trade your personal information to anyone, for any purpose.
We do not use your code or conversations to train models.
We do not run third-party advertising or behavioural tracking pixels.

4. Cloud models and anonymization

If you explicitly choose a cloud-hosted model, that request must leave your machine to be answered. Before it does, Sage strips identifying fields — user ID, email, and session identifiers — and scrubs email addresses and phone numbers from the prompt body. The upstream provider receives an anonymized request that is not linked to your identity.

5. Voice input

When you use the Talk screen, your speech is turned into text by your device's own speech recognition, not by Sage. Sage asks for on-device recognition every time and only accepts the alternative when your device cannot do it — on Android that means the offline language pack for your chosen dialect must be installed. If it is not, your device sends the audio to its system speech provider (Google or Apple) to transcribe, and the app tells you so on screen while it is happening. Either way, Sage's own servers never receive the audio; they receive only the resulting text, which is then treated like any other message.

6. Your data rights

You can exercise all of the following yourself from the Account page, without contacting support:
Export — download a JSON archive of every record Sage holds about your account.
Delete conversations — permanently remove your chat history while keeping your account.
Delete SMS bridge data — wipe paired devices and the contact allowlist only.
Delete account — permanently erase your account and all associated data. This is immediate and cannot be reversed.
Deletion is real deletion. We do not retain shadow copies, and we do not apply a 30-day grace period during which your data still exists on our systems.

7. Data isolation between users

Every record in Sage — conversations, usage, billing, devices, organizations, and connected accounts — is scoped to the authenticated user who owns it. Requests are authorized against your user ID on the server; one account cannot read or modify another account's data.

8. Children

Sage is a developer tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.

9. Changes to this policy

If we make a material change to how we handle your data, we will update this page and note the revision date below. Continued use after a change constitutes acceptance.

10. Contact

Questions about privacy or a data request: support@sageworksai.com
Last updated: July 27, 2026