Trust

Privacy Policy

Last updated: August 28, 2026

Sage only works if you trust it with your world, so privacy isn't a footnote here — it's the product. This page explains, in plain language, exactly what Sage stores, who we send it to, what we never do with it, and how you can export or erase it at any time. No dark patterns, no buried clauses.

The short version

  • Sage is provided by Perpetual Core LLC, which is responsible for the data described on this page.
  • Your account is just an email and authentication, handled by Supabase Auth. We never see your password.
  • Sage stores your conversations, the memory it forms about you, and your settings — isolated to your account.
  • We do not sell your data, and we do not use it to train our own or anyone else's AI models.
  • You can export your memory and delete your private Sage data whenever you want. Contact support to request account closure.
  • We share data with a small set of named service providers only to make Sage work — and nothing more.

Your account

To use Sage you create an account with an email address. Authentication is handled by Supabase Auth, either through Google sign-in (OAuth) or an email-and-password login. If you use a password, Supabase hashes it — it is never stored in a form we (or anyone) can read, and we never see your raw password. If you sign in with Google, we receive your basic profile (name and email) to create and identify your Sage account. Google sign-in alone does not give Sage access to Gmail, Calendar, Contacts, or Drive. Those services are available only through the optional Google connector described below.

Connecting Google Workspace

You can optionally connect one or more Google accounts and choose the capabilities each account provides. Sage keeps each connection separately scoped to you. It does not silently use one account in place of another: the applicable connected account is shown for account-specific work, and you choose separate defaults where Sage supports them.

  • Gmail read-only lets Sage surface a small, recent needs-reply list and read a thread only when needed to prepare a grounded reply.
  • Gmail compose lets Sage create a draft after you approve the draft action. It does not send that draft.
  • Gmail send is used only after a human explicitly chooses Send for the named connected account. Sage agents and background jobs cannot autonomously send email.
  • Calendar read-only lets Sage read events for agendas and meeting preparation. It does not let Sage create, edit, or delete events.
  • Contacts read-only lets you request a bounded preview of contacts from a named account and choose which contacts to stage. Each selection first becomes a private import candidate, visible to you and, for workspace governance, the workspace's owners and admins. It becomes a confirmed Company People record shared with the workspace only after an owner or admin explicitly approves creating or linking that record. There is no automatic contacts sync or automatic promotion.
  • Drive selected-file access lets you choose individual files with Google Picker and import those files into your private Sage Library. Sage does not browse or copy your whole Drive. Library records keep the source Google account and file provenance.

Gmail, Calendar, and selected Drive imports remain private to the member who connected the account unless that member takes a separate, explicit sharing action inside Sage. Contacts remain private import candidates while awaiting review; workspace owners and admins can see that bounded review queue and can explicitly promote a candidate into a confirmed Company People record shared with the workspace. Disconnecting a Google account deletes the stored credential for this member in this workspace, so this connection cannot fetch new data. Other workspaces remain connected. Private candidates and files already imported into Sage remain under the applicable Sage review and delete controls until they are rejected, promoted, or deleted.

Google API data and Limited Use

Sage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide and improve the user-facing connector features you request, such as inbox triage, grounded drafts, human-approved sending, meeting preparation, selected contact import, and selected-file Library import.

  • We do not use Google user data for advertising or personalized advertising.
  • We do not sell Google user data.
  • We do not use Google user data to train generalized AI or machine-learning models, and we do not transfer it to others for that purpose.
  • Humans do not read Google user data unless you give affirmative consent for a specific support purpose, access is necessary for security or abuse investigation, we must comply with applicable law, or the data has been aggregated and anonymized for internal operations.
  • We transfer Google user data only to service providers needed to provide or secure the feature, under confidentiality and data-protection obligations, or when required by law.

What Sage stores about you

Sage is a chief of staff that remembers you, so by design it keeps a record of what you tell it. Specifically:

  • Your conversations — what you say to Sage across the web app, voice, and any channel you connect.
  • The memory Sage forms about you — the facts, people, projects, and context it derives from those conversations so it can recall them later.
  • Your settings and preferences — how you've configured Sage, your subscription tier, and similar account details.

This lives in two places: a Supabase (Postgres) database, where every row is isolated to your account by row-level security so one account can never read another's data; and Mnemosyne, an external memory service operated for Sage that stores and retrieves your memory so Sage can recall the right thing at the right moment.

Who we share your data with (subprocessors)

To provide Sage, we send some of your data to a small set of third-party providers — only to deliver the service, never to advertise to you or build a profile elsewhere. Each one receives only what it needs:

  • Anthropic (Claude) — to generate Sage's responses.
  • Voyage AI — to create embeddings (the numeric representations that power memory and search).
  • ElevenLabs — for voice synthesis. When Sage speaks, the text of the reply is sent to produce audio; it is not retained by us beyond fulfilling that request.
  • Supabase — our database, authentication, and file storage.
  • Stripe — to process payments. Stripe handles your card details directly; we never store your card number.
  • Vercel — hosting and delivery of the application.
  • Resend — to deliver account, trial, workspace invitation, and service notification emails.
  • Google — when you connect an optional Google Workspace capability, Sage receives only the Google data covered by the permissions you select and the actions you request.

What we never do

  • We do not sell your data. Ever.
  • We do not use your conversations or memory to train our own AI models, and we do not let our providers use your data to train theirs.
  • We do not run third-party advertising or ad-tracking on you.

Sharing with your workspace

Your memories are private by default. Nothing is shared unless you share it. Ever. If you're on a team plan, you can choose to share individual memories — or everything from a conversation — with your workspace. Sharing is always an explicit act by you; Sage never shares anything on its own and never suggests that you should.

When you share a memory, your teammates in that workspace can see:

  • the content of the memory you shared;
  • your name, as the person who shared it;
  • the date you shared it.

Sage uses shared memories to answer your teammates' questions from that pooled knowledge, attributing the answer to you the way a colleague would (“per your note from the pricing discussion”). Teammates only ever see what you've chosen to share — never your private memories.

You can make anything private again at any time, from the memory browser or from the conversation. The moment you do, it drops out of your workspace and Sage stops using it for anyone else — immediately. If you leave a workspace, the memories you shared stay with the team as shared knowledge and remain attributed to you; your private memories leave with your account.

Your control over your data

Because the memory is the whole point of Sage, you get full control over it:

  • Export — you can export your memory from inside the app at any time.
  • Delete selectively — you can delete individual memories whenever you want.
  • Delete your private Sage data — you can remove your private memories and files from inside Sage. On a single-member workspace, Sage also sends a deletion request to the external memory service (Mnemosyne). On a shared workspace, that external purge is held for support review so one person cannot erase the team's memory.

Contact support@perpetualcore.com to request closure of your login account. Memories or files you explicitly shared with a workspace may remain with that workspace after your private data is removed.

You can disconnect an individual Google account at any time in Sage under Settings → Connections. Sage deletes that workspace connection's stored credential. Other workspaces remain connected. To stop access across all workspaces, revoke Sage from your Google Account's third-party access settings. Revocation stops future Google access; it does not silently delete contacts or files you previously chose to import into Sage.

To be honest about the limits: deletion is immediate in our live systems, but encrypted backups and operational logs may still contain some data for a short period before they age out and are overwritten. We don't restore deleted data from backups except to recover from a system failure.

Cookies

We use essential cookies only — the session cookies that keep you signed in. We do not use third-party advertising or cross-site tracking cookies. Because these cookies are required for the app to function, there is no advertising profile to opt out of.

Data security

Your data is encrypted in transit and isolated by workspace and member through row-level security. Private data is limited to its authenticated member; data you explicitly share can be accessed by authorized members of that workspace and the named providers above as needed to operate Sage. No system is perfectly secure, but we limit who and what can touch your data to the minimum needed to run Sage.

Changes to this policy

If we change how we handle your data, we'll update this page and revise the “Last updated” date above. For material changes, we'll make a reasonable effort to notify you in the app or by email before they take effect.

Contact

Questions, requests, or concerns about your privacy? Email us at support@perpetualcore.com.