Sage

Privacy Policy — Last updated July 2026

1. Who We Are & What This Covers

Sage (“we”, “us”, or “our”) is a nutrition-tracking mobile application. This policy explains, in plain language, exactly what leaves your phone, where it goes, how long we keep it, and how to get rid of it.

Sage is a small operation, not a large company. We do not sell your data, we do not run advertising, and we do not share your data with data brokers. We do, however, send some of your data to our own server and to Google’s AI service so the app’s features can work — sections 3 and 4 set out precisely what.

2. Data Held on Your Device

Unless you turn on Cloud backup (section 3.6), the following is kept in the app’s private storage on your phone and is not uploaded:

This on-device data is stored as ordinary application data inside the app’s private sandbox. It is not additionally encrypted by us, so treat your device passcode as what protects it. Uninstalling the app, or Settings → Reset app, removes it.

3. Data We Send to Our Server

Sage talks to our own API server (hosted on Render, with a managed PostgreSQL database) over HTTPS. Here is every request the app makes and what travels with it.

3.1 Device registration

On first launch the app asks our server for a random device token that authenticates later requests. We store that token together with the IP address the request came from and an expiry date. The IP address is used for abuse and cost control (capping how many tokens can be minted from one network) and is also written into a per-day request counter. The device token is not linked to your name or email unless you sign in with Google.

3.2 AI food scanner

When you scan a meal, the photo (or the text description you typed) is sent to our server and forwarded to Google Gemini for analysis. We do not store the photo or the description.

3.3 Progress-photo check-in

If you ask Sage to review a progress photo, the photo is sent to our server and forwarded to Google Gemini, along with your first name, goal, current weight, target weight and recent weight trend so the advice is relevant. We do not store the photo or that context.

3.4 Chatting with Sage

Every message you send Sage is transmitted. Each request contains the content of up to your last 12 chat messages plus a snapshot of your day: name, goal, dietary preferences, country, calorie goal, calories eaten today, protein remaining, glasses of water, current streak, average fullness rating, liquid calories and drinks logged today, and your device’s local hour. This is sent to our server and forwarded to Google Gemini. We do not store the messages or the context on our server.

3.5 Recipes

Recipe generation and suggestions send the dish name, description, your country, dietary preferences and your calorie/macro targets to our server and on to Google Gemini. The generated recipe is cached in our database so the same dish does not cost another AI call; that cache is keyed on the dish, country and diet only — it contains no identifier for you and no personal data.

3.6 Cloud backup (optional, but ON by default once you sign in)

If you choose “Continue with Google”, cloud backup is switched on automatically. From then on, your profile, complete meal log and complete weight history are uploaded to our server (shortly after each change) and stored in our database so you can restore them on a new device. Progress photos and chat history are not included. You can turn this off at any time in Settings → Cloud backup, and delete what has already been uploaded via Settings → Delete cloud data & account.

3.7 Google sign-in

If you sign in with Google, we receive and store your Google account identifier, email address and name, plus whether you opted in to occasional nutrition emails. Signing in is optional — every feature of Sage works without it.

3.8 Purchases

When you subscribe, the Google Play purchase token is sent to our server, which passes it to Google Play to confirm the subscription is genuine and active. We keep only a one-way hash of that token (so one purchase cannot be reused on many devices), together with your device token, the product id and the subscription expiry date. We never see or receive your card details — payment is handled entirely by Google Play.

3.9 Usage counters

To enforce the free-trial and fair-use limits (monthly scans, daily chat messages, daily photo reviews, monthly recipes) we keep simple counters in our database keyed to your device token, and a per-day registration counter keyed to your IP address.

4. AI Processing by Google Gemini

Sage’s AI features are powered by Google Gemini. Everything described in sections 3.2 to 3.5 — your food photos, your progress check-in photos, the text of your chat messages, and the profile/nutrition context listed above — is transmitted to Google’s Gemini API for processing. This is not optional for those features; if you would rather nothing were sent, use manual food entry and do not use the Sage chat, photo check-in or recipe features.

Once Google has returned a result we discard the input on our side. What Google does with data it receives is governed by Google’s own Privacy Policy and its API terms; we cannot make promises on Google’s behalf.

5. What We Keep and What We Discard

DataStored on our server?How long
Food photos & descriptionsNo — processed and discardedNot retained
Progress check-in photosNo — processed and discardedNot retained
Sage chat messagesNo — processed and discardedNot retained
Recipe request detailsNo — only the generated recipe is cached, with no link to youCache is indefinite
Device token + IP addressYesUp to 1 year, then deleted automatically
Usage counters (per device / per IP per day)YesRetained as historical counters
Google account id, email, nameYesUntil you delete your account
Cloud backup (profile, meals, weight)Yes, if backup is onUntil overwritten or you delete your account
Hashed purchase token, product id, expiryYesKept for subscription integrity
Crash reportsHeld by Sentry, not by usPer Sentry’s retention

Our server’s request logs record the method, path and status code of each request. They do not include request bodies, so your photos, chat messages, meals and weight never appear in them. A handful of events additionally log one non-identifying detail — the product id of a verified purchase, the domain part of a sign-in email address, or the name of a dish served from the recipe cache.

6. Third-Party Services

We do not sell your data, and we do not share it with any third party for advertising or profiling.

7. Health-Related Data

Sage handles health-adjacent information: body metrics, dietary preferences and allergies, weight history, meal logs and body photos. We use it only to calculate your targets, generate your analysis and advice, and — where you have enabled it — to back it up so you can restore it.

Please be aware that this information is transmitted as described in section 3 and processed by Google Gemini as described in section 4. If that is not acceptable to you, do not use the AI features. Sage is a general wellness app and is not a medical device or a healthcare service.

8. Camera & Photo Library

Sage requests access to your camera and photo library only for the AI food scanner, the progress-photo check-in, and your profile picture. Images you supply for analysis are sent to our server and on to Google Gemini for that analysis (see section 4); we do not retain them, and we do not use them for anything else. You can deny or revoke these permissions at any time in your device settings — the app still works with manual food entry.

9. Your Choices & Controls

If you are in the EU/UK you also have rights of access, correction, erasure, restriction, objection and portability. Email us and we will action them.

10. Data Retention & Deletion

Retention periods are listed in section 5. Device tokens (and the IP address stored with them) expire and are deleted automatically within one year. Account records and cloud backups are kept until you delete them — from within the app via Settings → Delete cloud data & account, or by emailing us at musharraf@impactofy.org. We will action emailed deletion requests promptly.

11. Subscriptions

Your subscription is held by Google Play, not by us. Deleting your data in Sage — whether by Reset app, by Delete cloud data & account, or by uninstalling — does not cancel it. Cancel in the Play Store → Menu → Subscriptions.

12. Children

Sage is not directed at children under the age of 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with data, contact us and we will delete it.

13. Changes to This Policy

We may update this policy. The “last updated” date at the top of this page changes when we do. Continued use of the app after an update constitutes acceptance of the revised policy.

14. Contact

Questions about this policy, or to request access to or deletion of your data? Email musharraf@impactofy.org.

Sage © 2026 — All rights reserved