Privacy Policy — Last updated July 2026
Sage (“we”, “us”, or “our”) is a nutrition-tracking mobile application. This policy explains, in plain language, exactly what leaves your phone, where it goes, how long we keep it, and how to get rid of it.
Sage is a small operation, not a large company. We do not sell your data, we do not run advertising, and we do not share your data with data brokers. We do, however, send some of your data to our own server and to Google’s AI service so the app’s features can work — sections 3 and 4 set out precisely what.
Unless you turn on Cloud backup (section 3.6), the following is kept in the app’s private storage on your phone and is not uploaded:
This on-device data is stored as ordinary application data inside the app’s private sandbox. It is not additionally encrypted by us, so treat your device passcode as what protects it. Uninstalling the app, or Settings → Reset app, removes it.
Sage talks to our own API server (hosted on Render, with a managed PostgreSQL database) over HTTPS. Here is every request the app makes and what travels with it.
On first launch the app asks our server for a random device token that authenticates later requests. We store that token together with the IP address the request came from and an expiry date. The IP address is used for abuse and cost control (capping how many tokens can be minted from one network) and is also written into a per-day request counter. The device token is not linked to your name or email unless you sign in with Google.
When you scan a meal, the photo (or the text description you typed) is sent to our server and forwarded to Google Gemini for analysis. We do not store the photo or the description.
If you ask Sage to review a progress photo, the photo is sent to our server and forwarded to Google Gemini, along with your first name, goal, current weight, target weight and recent weight trend so the advice is relevant. We do not store the photo or that context.
Every message you send Sage is transmitted. Each request contains the content of up to your last 12 chat messages plus a snapshot of your day: name, goal, dietary preferences, country, calorie goal, calories eaten today, protein remaining, glasses of water, current streak, average fullness rating, liquid calories and drinks logged today, and your device’s local hour. This is sent to our server and forwarded to Google Gemini. We do not store the messages or the context on our server.
Recipe generation and suggestions send the dish name, description, your country, dietary preferences and your calorie/macro targets to our server and on to Google Gemini. The generated recipe is cached in our database so the same dish does not cost another AI call; that cache is keyed on the dish, country and diet only — it contains no identifier for you and no personal data.
If you choose “Continue with Google”, cloud backup is switched on automatically. From then on, your profile, complete meal log and complete weight history are uploaded to our server (shortly after each change) and stored in our database so you can restore them on a new device. Progress photos and chat history are not included. You can turn this off at any time in Settings → Cloud backup, and delete what has already been uploaded via Settings → Delete cloud data & account.
If you sign in with Google, we receive and store your Google account identifier, email address and name, plus whether you opted in to occasional nutrition emails. Signing in is optional — every feature of Sage works without it.
When you subscribe, the Google Play purchase token is sent to our server, which passes it to Google Play to confirm the subscription is genuine and active. We keep only a one-way hash of that token (so one purchase cannot be reused on many devices), together with your device token, the product id and the subscription expiry date. We never see or receive your card details — payment is handled entirely by Google Play.
To enforce the free-trial and fair-use limits (monthly scans, daily chat messages, daily photo reviews, monthly recipes) we keep simple counters in our database keyed to your device token, and a per-day registration counter keyed to your IP address.
Sage’s AI features are powered by Google Gemini. Everything described in sections 3.2 to 3.5 — your food photos, your progress check-in photos, the text of your chat messages, and the profile/nutrition context listed above — is transmitted to Google’s Gemini API for processing. This is not optional for those features; if you would rather nothing were sent, use manual food entry and do not use the Sage chat, photo check-in or recipe features.
Once Google has returned a result we discard the input on our side. What Google does with data it receives is governed by Google’s own Privacy Policy and its API terms; we cannot make promises on Google’s behalf.
| Data | Stored on our server? | How long |
|---|---|---|
| Food photos & descriptions | No — processed and discarded | Not retained |
| Progress check-in photos | No — processed and discarded | Not retained |
| Sage chat messages | No — processed and discarded | Not retained |
| Recipe request details | No — only the generated recipe is cached, with no link to you | Cache is indefinite |
| Device token + IP address | Yes | Up to 1 year, then deleted automatically |
| Usage counters (per device / per IP per day) | Yes | Retained as historical counters |
| Google account id, email, name | Yes | Until you delete your account |
| Cloud backup (profile, meals, weight) | Yes, if backup is on | Until overwritten or you delete your account |
| Hashed purchase token, product id, expiry | Yes | Kept for subscription integrity |
| Crash reports | Held by Sentry, not by us | Per Sentry’s retention |
Our server’s request logs record the method, path and status code of each request. They do not include request bodies, so your photos, chat messages, meals and weight never appear in them. A handful of events additionally log one non-identifying detail — the product id of a verified purchase, the domain part of a sign-in email address, or the name of a dish served from the recipe cache.
We do not sell your data, and we do not share it with any third party for advertising or profiling.
Sage handles health-adjacent information: body metrics, dietary preferences and allergies, weight history, meal logs and body photos. We use it only to calculate your targets, generate your analysis and advice, and — where you have enabled it — to back it up so you can restore it.
Please be aware that this information is transmitted as described in section 3 and processed by Google Gemini as described in section 4. If that is not acceptable to you, do not use the AI features. Sage is a general wellness app and is not a medical device or a healthcare service.
Sage requests access to your camera and photo library only for the AI food scanner, the progress-photo check-in, and your profile picture. Images you supply for analysis are sent to our server and on to Google Gemini for that analysis (see section 4); we do not retain them, and we do not use them for anything else. You can deny or revoke these permissions at any time in your device settings — the app still works with manual food entry.
If you are in the EU/UK you also have rights of access, correction, erasure, restriction, objection and portability. Email us and we will action them.
Retention periods are listed in section 5. Device tokens (and the IP address stored with them) expire and are deleted automatically within one year. Account records and cloud backups are kept until you delete them — from within the app via Settings → Delete cloud data & account, or by emailing us at musharraf@impactofy.org. We will action emailed deletion requests promptly.
Your subscription is held by Google Play, not by us. Deleting your data in Sage — whether by Reset app, by Delete cloud data & account, or by uninstalling — does not cancel it. Cancel in the Play Store → Menu → Subscriptions.
Sage is not directed at children under the age of 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with data, contact us and we will delete it.
We may update this policy. The “last updated” date at the top of this page changes when we do. Continued use of the app after an update constitutes acceptance of the revised policy.
Questions about this policy, or to request access to or deletion of your data? Email musharraf@impactofy.org.
Sage © 2026 — All rights reserved