Privacy Policy

Version 0.2

Working draft.

1. Our approach to privacy

Users may share highly personal information about thoughts, emotions, and wellbeing. This information deserves particularly careful treatment. This policy explains what Sage collects, why it is collected, how it is used, where it may be processed, who it may be shared with, retention, and access, correction, and deletion rights.

2. Information we may collect

Depending on use, Sage may collect:

Sage should not store full payment-card details. Purchases are handled by Apple or Google. Sage receives subscription status, not your full card number.

Written Check-In responses are optional. If you write during Check-In, that text is stored as Check-In notes.

3. Sensitive and health-related information

Voluntarily entered emotional, psychological, physical, stress, and wellbeing information may be health information or sensitive personal information. Short written Check-In responses may contain that kind of information.

Sage should collect only what is reasonably necessary and seek consent where legally required. Sage should collect only the Check-In information reasonably necessary to provide the requested reflection and reset recommendation.

4. Why we use information

Information may be used to:

Deeply personal Check-In writing or emotional content should not be used for unrelated advertising.

5. AI processing

When a user chooses an AI feature, relevant information may be sent to an AI service provider to generate the requested response. Only reasonably necessary information should be transmitted. Sage does not send your full history for every request.

For Check-In reflections, that may include selected emotion, intensity, short written Check-In responses, and recent relevant Check-In history where applicable. Optional profile details are included only if you turn that setting on in Settings.

Where commercially and technically available, providers should be configured so user content is not used to train general-purpose models without appropriate authorisation. Users should be informed when external AI providers process their data. Sage currently uses OpenAI, called from Sage’s servers, for these features.

6. Data minimisation

Sage should collect only information necessary for a defined purpose, regularly review whether storage remains necessary, and never collect sensitive information merely because it may be useful someday.

7. Service providers

Sage may disclose information to trusted providers necessary to operate the app. Providers currently used are:

Sage does not currently use a separate analytics or crash-reporting provider.

8. Overseas processing

Some providers may process or store information outside Australia. Before public launch, the countries involved, provider safeguards, and any required overseas-disclosure notice should be confirmed and added here.

9. Analytics and product improvement

Sage does not currently use a separate product-analytics provider. If analytics are added later, they should be proportionate, privacy-conscious, and configured to avoid unnecessary collection of Check-In writing, emotional content, or AI conversations. Sensitive content should not be placed in event names, URLs, logs, or analytics properties.

10. Data security

Sage should use reasonable technical and organisational safeguards, including access controls, encryption in transit, secure authentication, least-privilege permissions, protected secrets, logging appropriate to risk, dependency maintenance, backups, and incident-response procedures. User content is stored in Supabase, with access scoped to the signed-in user. No system is completely secure.

11. Retention and deletion

Sage should define retention periods by data category and keep personal information only as long as needed for the purpose, legal obligations, security, or dispute resolution. Specific retention periods have not yet been published.

Account deletion should trigger deletion or de-identification across primary systems and documented downstream processes, subject to lawful exceptions and limited backup cycles.

12. Access and correction

Users may request access to or correction of personal information held about them. Sage should verify identity, respond within a reasonable period, and explain any lawful refusal and available complaint route. Recent Check-Ins and reflections can also be viewed in the app.

13. Account deletion

Users may permanently delete their Sage account through Settings. When deletion is confirmed, Sage deletes the personal information associated with the account from its active systems, subject to the limited retention circumstances and backup lifecycle described above.

Deleting a Sage account does not necessarily cancel a subscription managed through the Apple App Store or Google Play Store. Users may also need to cancel that subscription through the applicable platform. Deleting the app from a device does not, by itself, delete the Sage account.

14. Anonymity and pseudonymity

Where practical and lawful, Sage should allow interaction without identifying information, or explain why identification is required for a particular feature. An email address is required to create an account, sign in, and keep Check-Ins with that account.

15. Direct marketing

Sage should not use sensitive wellbeing content for targeted advertising. Sage does not currently send promotional marketing emails. Authentication emails are limited to sign-in codes and similar account messages. If marketing communications are sent later, they should be sent only where lawful, identify Sage, and provide a functional unsubscribe mechanism.

16. Data breaches

Sage should maintain a data-breach response plan, investigate suspected incidents promptly, contain and remediate them, preserve appropriate records, and assess notification obligations under Australia’s Notifiable Data Breaches scheme.

17. Complaints

Privacy questions or complaints may be sent to support@trysage.com.au. Sage should acknowledge and investigate complaints and explain escalation options, including the Office of the Australian Information Commissioner where applicable.

18. Changes to this policy

Sage may update this policy as the product, providers, or law changes. Material changes should be communicated appropriately, and the effective date and version should be maintained. Sage does not currently require existing users to re-accept this policy after each update.

19. Privacy contact

Brenton Darvill

Email: support@trysage.com.au

A postal service address has not yet been published. Please use the email above.