Privacy Policy
Effective September 17, 2026 · Last updated September 17, 2026
1. Introduction
Otto Research Labs LLC, doing business as Sage ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Sage mobile application and website (collectively, the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
We collect information you provide directly to us, information created when you use the Service, and limited information from the services that help us operate it:
Account and authentication information — your email address and password when you create an account, or the account and identifier supplied by Google or Apple if you choose social sign-in. Supabase Auth manages authentication credentials and session tokens; Sage does not receive or store your password in its application database.
Profile and relationship information — your name, relationship type and stage, anniversary or other relationship dates, partner name, love-language preferences, attachment style, apology-language preference, selected goal areas, and other onboarding answers.
Partner connection and referral data — pairing codes, invite links, referral codes, who invited or joined with whom, pairing status, and attribution information connected with an invite.
Well-being and relationship activity — emotional check-ins, emotion intensity, reflections, notes to your partner, attachment needs, stress ratings, cycle-map responses, goals, challenges, milestones, bids, gratitudes, repair attempts, date ideas and schedules, quiz results, relationship insights, and similar activity you choose to record.
Journal and conversation content — journal entries, titles, sharing choices, Sage conversation history, discussion topics, and messages you send to Sage or your partner.
Branches community data — posts, comments, replies, generated pseudonym, positive reactions, follows, blocks, reports, moderation outcomes, and the preferences and acceptance record associated with using Branches. Branches is pseudonymous to other members, but it is not anonymous to Sage or its moderators.
Subscription data — purchase and entitlement status supplied by Apple or Google through RevenueCat. RevenueCat receives the app user identifier we use to associate entitlements with your Sage account, along with subscription, purchase, and entitlement metadata. We do not receive or store your full payment card details.
Photos and local media references — when you choose a profile or Memory Book photo, the app can use your camera or photo library. The current app stores the selected media reference with your app activity; it does not operate a separate server-side photo library. Photos may remain in your device's photo library and are subject to the permissions and settings of your device.
Voice recordings — when you choose to attach a voice note to a gratitude or save a voice journal entry, the recording is uploaded to private Supabase Storage so you (and, when you tap "share with partner," your paired partner) can play it back. Gratitude recordings are visible to your paired partner; journal voice notes are private to you by default and only become accessible to your partner when you explicitly mark that entry as shared. Recordings are short (capped at one minute), encrypted in transit and at rest, and only accessible via short-lived signed URLs that the server issues after checking who owns the entry and whether it is shared. Microphone access is requested only when you tap the record button — we never record passively. Voice notes and their stored files are included in content and account deletion requests.
Voice dictation for Sage — if you tap the microphone in the Sage chat to dictate a message, your phone's built-in speech recognition converts your voice into text on-device. The audio itself is processed by your phone's operating system and is not uploaded, stored, or sent to us; only the resulting text is sent to Sage when you tap send.
Sage voice replies — if you turn on Sage's voice replies (the speaker toggle in the Sage chat), the text of Sage's reply is sent to OpenAI through Replit's AI Integrations proxy to synthesize a short audio clip that streams back to your phone for playback. The synthesized audio is played once and stored only in temporary device cache so you can replay it; we do not retain the audio on our servers, and the audio is not used to train any model. You can turn voice replies off at any time from the Sage screen.
Device and notification information — your device type, operating system, app/device identifiers, platform, and Expo push token when you enable notifications. Notification settings and reminder times may be stored on your device; notification registration and partner-activity preferences are stored with your account. Expo's push service receives the token and the notification payload needed to deliver a notification.
Attribution data — when attribution is enabled in a production build, AppsFlyer processes a device identifier, our user identifier after sign-in, and install, campaign, referral, and deep-link information so we can measure which invitation or referral led to an install. Sage does not request Apple's App Tracking Transparency permission and does not use this information for targeted advertising.
Optional profile details — gender identity (Woman, Man, Nonbinary, or Prefer not to say) and an approximate, city-level location (e.g. "Austin, Texas, United States"). Both are entirely optional and you can skip or remove them at any time. We use them only to personalize Sage's coaching: gender lets Sage use the right pronouns when you've shared them, and your city helps Sage suggest date ideas that fit where you live. We do not retain precise coordinates.
We do not collect your precise location, financial information, or contacts. Camera, photo library, microphone, speech recognition, calendar, notification, and biometric permissions are optional and requested only when you use the related feature. App Lock uses the device's local biometric/passcode capability; Sage does not receive your biometric data or store it on our servers.
3. How We Use Your Information
We use the information we collect to:
– Provide, personalize, and improve the Service, including generating AI coaching responses, relationship insights, summaries, titles, and personalized challenges tailored to your relationship profile and the context you choose to share.
– Sync your data across devices and with your partner's account (with your explicit consent to pair).
– Send you notifications about check-in reminders, partner activity, and app updates (which you can disable in settings).
– Send transactional account, pairing, subscription, and service emails through our email provider, and maintain suppression and delivery records.
– Attribute installs and referrals when AppsFlyer is enabled, prevent abuse, moderate Branches, and protect the security of the Service.
– Comply with legal obligations and enforce our Terms of Service.
Sage AI requests may include the conversation and relevant profile, check-in, goal, journal, cycle-pattern, assessment, or relationship context needed for the feature you use. We do not send every category of your data with every request. We do not use your personal data to train external AI models, and your relationship data is never sold to third parties.
4. Artificial Intelligence and Automated Processing
Sage uses AI features to provide coaching conversations, conversation titles and summaries, recurring-theme insights, relationship-profile insights, personalized daily or couples challenges, psychology bites, and optional voice replies. AI-generated content is produced from the information needed for the specific feature and may be inaccurate, incomplete, or unsuitable for your situation.
For these features, Sage sends the relevant prompt and selected context to OpenAI through Replit's AI Integrations proxy. Depending on the feature, that context can include messages you send to Sage, recent conversation history or summaries, your name or partner name, relationship type, selected goals, assessment results, check-ins and emotions, cycle-pattern information, and optional profile details such as pronouns or city-level location. The OpenAI text model currently used for these features is gpt-5-mini, but models and providers may change as the Service changes.
If you enable Sage voice replies, the text of Sage's reply is sent through the same OpenAI service to the gpt-4o-mini-tts speech model. The resulting audio is streamed to your device and is not retained on Sage's servers. Voice replies are optional; you can turn them off in the Sage screen.
Sage also has a separate AI-assisted moderation path for Branches. It is disabled by default at launch and is only used when the disclosed Branches setting is enabled. When enabled, the text of a Branches post or comment is redacted for common direct identifiers before a redacted copy is sent to OpenAI through Replit's proxy to flag harmful content or crisis signals. We do not send the post author's pseudonym, account ID, partner name, or pairing identifiers to that model, and we retain moderation results rather than the raw moderation prompt.
Using an AI feature requires this processing. You can avoid sending content to an AI provider by not using the relevant AI feature; the non-AI parts of the Service remain subject to the other processing described in this policy. Do not submit information to Sage that you do not want processed by an AI provider or that you do not have permission to share.
5. How We Share Your Information
We share your information only in these limited circumstances:
With your partner — when you choose to pair accounts, the app shares the relationship data and content the feature is designed to share, such as your name, selected profile information, check-in status, cycle-map information you mark as shared, gratitudes, shared journals, partner-directed notes, milestones, and relationship activity. Your private Sage conversations and unshared journal entries are not shared with your partner.
With service providers — we name the principal providers currently used by the Service below. They receive only the data needed for the listed purpose, subject to their own privacy policies and retention practices. We will update this policy when a material provider or processing purpose changes:
• Supabase — authentication, account identity, application database, Realtime partner-sync events, and private storage for voice recordings. Supabase can receive account identifiers, authentication metadata, relationship and app content, pairing data, and voice recordings you choose to upload.
• OpenAI, accessed through Replit's AI Integrations proxy — Sage coaching, AI-generated titles and summaries, relationship insights, personalized challenges, psychology bites, optional voice-reply synthesis, and optional Branches moderation. The AI data categories and redaction rules are described in the Artificial Intelligence section above.
• Replit — application hosting and the proxy that routes Sage's OpenAI requests. Replit may process information as infrastructure and service provider while operating the Service.
• RevenueCat — subscription and entitlement management. RevenueCat receives the Sage app user identifier and purchase, subscription, and entitlement metadata, but not your relationship conversations or journal content.
• Apple App Store and Google Play — account, purchase, and subscription services when you buy Sage+. These stores control billing records and payment-card processing; Sage does not receive your full card number.
• Expo's push notification service — delivery of notifications using your push token, device/platform information, and the notification payload needed for delivery.
• SendGrid — transactional, account, pairing, subscription, and service email. SendGrid may receive your email address, the content and metadata of messages sent through it, and delivery or suppression records.
• AppsFlyer — install, deep-link, referral, campaign attribution, and limited product-event measurement when attribution is enabled in a production build. Sage does not request Apple's App Tracking Transparency permission and does not use AppsFlyer data for targeted advertising.
• FirstPromoter — optional website referral attribution. If you allow optional cookies, FirstPromoter may receive referral, campaign, and browser-cookie information to record a referral click or sign-up. Its script is not loaded before you make an optional-cookie choice.
We may also send information to Apple, Google, or another identity provider when you choose a corresponding sign-in method. We do not sell your personal information or allow service providers to use your relationship content to train external AI models.
For legal reasons — we may disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Sage, our users, or the public.
Business transfers — in the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your personal information is transferred.
We never sell your personal information.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. You can delete your account at any time from Profile → Edit Profile in the app, or use our web data-management page at https://meetsage.io/manage-my-data#delete. Account deletion removes the account, application data, pairing data, authored content, private audio files, notification registrations, and the account's active subscription association from our systems; store billing records remain with Apple or Google as required by those services. A content-only wipe removes authored app content while keeping the account and data needed for pairing, billing, referrals, notifications, and security. We will remove remaining personal data from active systems within 30 days, except where retention is required for legal compliance, fraud prevention, abuse prevention, or security records. Backups and provider-side retention may take longer to age out under those providers' retention policies.
7. Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS) and at rest, row-level security policies on our database, and secure token-based authentication. However, no method of internet transmission or electronic storage is 100% secure, and we cannot guarantee absolute security.
8. Branches — Community Posts & AI-Assisted Moderation
Branches is Sage's opt-in, pseudonymous community space. Posts and comments you publish there are visible to other Branches members under a generated pseudonym — never your real name or email. Sage and authorized moderators can associate Branches activity with your account when needed for safety, abuse prevention, support, or legal compliance.
To keep Branches safe and supportive, every post and comment is checked by a word-list and a tone filter that run entirely on our own servers.
When AI-assisted moderation is enabled (this is OFF by default at launch and shown in the Code of Warmth screen before you post), the text of your post or comment is also sent to an external AI model (currently OpenAI's gpt-5-mini, accessed through Replit's AI Integrations proxy) so it can flag harmful content or crisis signals for a human reviewer. Before any text leaves our servers we automatically strip identifying details — email addresses, phone numbers, links, street addresses, long number sequences (e.g. card or account numbers), and @-handles. We never send your pseudonym, your account ID, your partner's name, or any data tying the text back to you.
We do not use your Branches posts or comments to train external AI models. We log only the model's verdict, scores, latency, and the count of identifying details that were redacted — never the raw text you sent.
You can see whether AI-assisted moderation is currently on, and what the disclosure says, at any time from the Code of Warmth banner in the Branches tab.
9. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, please contact us immediately at support@ottoresearch.io and we will delete it promptly.
10. Your Rights
Depending on your location, you may have the right to:
– Access the personal information we hold about you.
– Request correction of inaccurate information.
– Request deletion of your personal information.
– Object to or restrict our processing of your data.
– Data portability — receive your data in a structured, machine-readable format.
To exercise any of these rights, please contact Otto Research Labs LLC at support@ottoresearch.io.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice in the app or sending an email to your registered address. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact:
Otto Research Labs LLC
support@ottoresearch.io
Salt Lake City, Utah, United States