Privacy Policy
Version 0.2
Working draft.
1. Our approach to privacy
Users may share highly personal information about thoughts, emotions, and wellbeing. This information deserves particularly careful treatment. This policy explains what Sage collects, why it is collected, how it is used, where it may be processed, who it may be shared with, retention, and access, correction, and deletion rights.
2. Information we may collect
Depending on use, Sage may collect:
- account information, including your email address and optional profile details
- Check-In information, which may include selected emotions, intensity, and short written descriptions or contextual notes you choose to provide about how you are feeling
- activity and completion history
- AI inputs and outputs, including reflections and suggestions
- device, app, and operating-system information needed to run Sage, keep you signed in, and schedule local reminders
- subscription status, transaction identifiers, or entitlements
Sage should not store full payment-card details. Purchases are handled by Apple or Google. Sage receives subscription status, not your full card number.
Written Check-In responses are optional. If you write during Check-In, that text is stored as Check-In notes.
3. Sensitive and health-related information
Voluntarily entered emotional, psychological, physical, stress, and wellbeing information may be health information or sensitive personal information. Short written Check-In responses may contain that kind of information.
Sage should collect only what is reasonably necessary and seek consent where legally required. Sage should collect only the Check-In information reasonably necessary to provide the requested reflection and reset recommendation.
4. Why we use information
Information may be used to:
- create and maintain accounts
- provide and personalise Sage
- generate AI reflections and recommend activities
- maintain progress and session history
- deliver subscriptions
- improve reliability and security
- prevent abuse
- provide support
- comply with law
- record the Terms of Use version, Privacy Policy version, and time when you continue past the signup or trial acknowledgement
Deeply personal Check-In writing or emotional content should not be used for unrelated advertising.
5. AI processing
When a user chooses an AI feature, relevant information may be sent to an AI service provider to generate the requested response. Only reasonably necessary information should be transmitted. Sage does not send your full history for every request.
For Check-In reflections, that may include selected emotion, intensity, short written Check-In responses, and recent relevant Check-In history where applicable. Optional profile details are included only if you turn that setting on in Settings.
Where commercially and technically available, providers should be configured so user content is not used to train general-purpose models without appropriate authorisation. Users should be informed when external AI providers process their data. Sage currently uses OpenAI, called from Sage’s servers, for these features.
6. Data minimisation
Sage should collect only information necessary for a defined purpose, regularly review whether storage remains necessary, and never collect sensitive information merely because it may be useful someday.
7. Service providers
Sage may disclose information to trusted providers necessary to operate the app. Providers currently used are:
- Supabase: accounts, database, authentication email, and server functions
- OpenAI: generation of reflections, recommendations, and summaries
- RevenueCat: subscription status and paywall
- Apple: App Store billing and related iOS services
- Google: Google Play billing and related store services if you use Android
- Expo: app runtime and local notifications on your device
Sage does not currently use a separate analytics or crash-reporting provider.
8. Overseas processing
Some providers may process or store information outside Australia. Before public launch, the countries involved, provider safeguards, and any required overseas-disclosure notice should be confirmed and added here.
9. Analytics and product improvement
Sage does not currently use a separate product-analytics provider. If analytics are added later, they should be proportionate, privacy-conscious, and configured to avoid unnecessary collection of Check-In writing, emotional content, or AI conversations. Sensitive content should not be placed in event names, URLs, logs, or analytics properties.
10. Data security
Sage should use reasonable technical and organisational safeguards, including access controls, encryption in transit, secure authentication, least-privilege permissions, protected secrets, logging appropriate to risk, dependency maintenance, backups, and incident-response procedures. User content is stored in Supabase, with access scoped to the signed-in user. No system is completely secure.
11. Retention and deletion
Sage should define retention periods by data category and keep personal information only as long as needed for the purpose, legal obligations, security, or dispute resolution. Specific retention periods have not yet been published.
Account deletion should trigger deletion or de-identification across primary systems and documented downstream processes, subject to lawful exceptions and limited backup cycles.
12. Access and correction
Users may request access to or correction of personal information held about them. Sage should verify identity, respond within a reasonable period, and explain any lawful refusal and available complaint route. Recent Check-Ins and reflections can also be viewed in the app.
13. Account deletion
Users may permanently delete their Sage account through Settings. When deletion is confirmed, Sage deletes the personal information associated with the account from its active systems, subject to the limited retention circumstances and backup lifecycle described above.
Deleting a Sage account does not necessarily cancel a subscription managed through the Apple App Store or Google Play Store. Users may also need to cancel that subscription through the applicable platform. Deleting the app from a device does not, by itself, delete the Sage account.
14. Anonymity and pseudonymity
Where practical and lawful, Sage should allow interaction without identifying information, or explain why identification is required for a particular feature. An email address is required to create an account, sign in, and keep Check-Ins with that account.
15. Direct marketing
Sage should not use sensitive wellbeing content for targeted advertising. Sage does not currently send promotional marketing emails. Authentication emails are limited to sign-in codes and similar account messages. If marketing communications are sent later, they should be sent only where lawful, identify Sage, and provide a functional unsubscribe mechanism.
16. Data breaches
Sage should maintain a data-breach response plan, investigate suspected incidents promptly, contain and remediate them, preserve appropriate records, and assess notification obligations under Australia’s Notifiable Data Breaches scheme.
17. Complaints
Privacy questions or complaints may be sent to support@trysage.com.au. Sage should acknowledge and investigate complaints and explain escalation options, including the Office of the Australian Information Commissioner where applicable.
18. Changes to this policy
Sage may update this policy as the product, providers, or law changes. Material changes should be communicated appropriately, and the effective date and version should be maintained. Sage does not currently require existing users to re-accept this policy after each update.
19. Privacy contact
Brenton Darvill
Email: support@trysage.com.au
A postal service address has not yet been published. Please use the email above.