Sage trust center

Privacy Policy

Effective August 27, 2026

This policy explains how Sage handles personal information, including the Google account, Gmail, and Google Calendar data a user chooses to connect.

1. Who we are and when this policy applies

Sage is an AI chief-of-staff and managed AI-workforce service for business operations. It helps authorized users triage inboxes, prepare and send approved replies, coordinate calendars, schedule work, use company knowledge, and automate routine workflows. This policy applies to the Sage public website, Sage application, and connected services.

2. Information Sage receives

We receive account and business information that users or their organizations provide, product usage and security logs, communications sent to us, and data from services a user deliberately connects. We request only permissions needed for the features the user enables.

Google account information

When a user authorizes a Google connection, Sage may receive the Google account email address, authorization tokens, and the data covered by the permissions shown on Google's consent screen.

Gmail

For enabled Gmail features, Sage may access message and thread identifiers, senders and recipients, timestamps, subjects, labels, message bodies, attachments when needed for the requested workflow, and mailbox profile information. Sage uses this data to ingest and organize business messages, detect work that may need attention, create summaries, prepare draft replies, send a reply only when the enabled workflow and required human approval permit it, and maintain the state needed to avoid duplicate processing. If write access is separately authorized, Sage may send messages and update mailbox state for those visible features.

Google Calendar

For enabled Calendar features, Sage may access calendars, events, attendees, times, locations, descriptions, availability, and related identifiers. Sage uses this information to show upcoming work and availability, coordinate scheduling, and—when an authorized user requests or approves the action—create, update, or delete calendar events.

3. How Sage uses information

Sage uses information to provide and secure the features a user or organization requests; authenticate users; operate integrations; generate user-facing summaries, suggestions, drafts, and workflow actions; troubleshoot failures; prevent abuse; keep required audit records; provide support; and meet legal obligations. Google user data is not used for advertising, retargeting, credit decisions, or sale to data brokers.

Sage may process the minimum Google user data needed through configured AI service providers to produce a user-facing Sage feature, such as classifying an inbox item or preparing a proposed reply. Sage does not use, or allow service providers to use, Google user data to train or improve generalized artificial intelligence or machine-learning models.

4. Storage and protection

Google OAuth refresh tokens are stored server-side in an encrypted form. Short-lived access tokens are protected from the browser and refreshed only as needed. Sage does not ask users for their Google password. Connected data and derived operational records are kept in access-controlled systems associated with the user's organization. Sage uses transport encryption, access controls, tenant and role boundaries, audit logging, credential separation, and operational monitoring designed to protect data from unauthorized access, alteration, disclosure, or destruction.

5. Sharing and human access

Sage does not sell Google user data or share it for advertising. We disclose information only:

Human access to Google user data is restricted to situations where a user gives specific consent for support, access is necessary for security or legal compliance, or the data has been aggregated and anonymized for permitted internal operations.

6. Retention, disconnecting, revocation, and deletion

Sage retains Google authorization tokens only while needed to operate an active connection. Other Google-derived content and operational records are retained only for as long as needed to provide the enabled features, preserve user-visible work and required security or audit history, comply with law, and resolve disputes. Retention needs can vary by the customer's configuration and legal obligations; Sage does not keep Google user data longer than necessary for those purposes.

A user can disconnect Gmail or Google Calendar from Sage's Integrations settings. Disconnecting stops future access, removes Sage's locally stored authorization token, and initiates revocation with Google where supported. Users can also revoke Sage directly from their Google Account permissions. Previously imported business records are not automatically erased merely by disconnecting because an organization may rely on them as part of its business and audit history.

A user or authorized organization administrator may request deletion of Google-derived content, connection records, or the Sage account by contacting leonardo@dwnow.tech. We verify authority, delete or de-identify covered information within a reasonable period, and explain any information we must retain for legal, security, fraud-prevention, contractual, or backup-integrity reasons. Residual copies are isolated from ordinary use and expire through the normal backup lifecycle.

7. Google API Services User Data Policy

Sage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is limited to providing or improving prominent, user-facing Sage features. Sage does not transfer, sell, or use that data for advertising; does not use it to determine creditworthiness; and does not use it to train generalized AI models.

8. User choices and rights

Depending on applicable law, users may request access, correction, export, restriction, objection, or deletion of personal information. Organization-managed information may require us to coordinate with the organization that controls the Sage deployment. Users may decline Google permissions or disconnect a service, but the related Sage feature will no longer work.

9. Changes and contact

We may update this policy as Sage, applicable law, or connected-service requirements change. Material changes will be communicated through the service or other appropriate means before we use Google user data for a materially different purpose.

Questions, privacy requests, or complaints can be sent to leonardo@dwnow.tech.