1. What Sage Is
Sage is an invite-only personal AI assistant operated by Omer Ekin ("we," "us," or "our"). Sage currently works through WhatsApp messages and helps the invited user think through goals, decisions, reflections, and follow-ups over time.
2. Information We Collect
We collect information needed to operate Sage for invited users:
- Messages you send to Sage and Sage's replies.
- WhatsApp channel identifiers, such as the WhatsApp phone-number ID, your WhatsApp handle or phone number, and message IDs needed for delivery, deduplication, and abuse prevention.
- Memories and profile-like notes Sage derives from your messages, such as preferences, values, commitments, and recurring context.
- Control commands you send, such as pause, resume, memory summary, and archive-memory requests.
- Operational metadata, such as timestamps, delivery status, model provider, model name, token counts, latency, error codes, and internal user IDs.
Sage currently does not operate a public self-serve signup flow, advertising tracker, or analytics product.
3. How We Use Information
We use information only to provide and operate Sage, including to:
- Receive and send WhatsApp messages.
- Generate AI-assisted replies.
- Remember relevant context so Sage can be useful across days and weeks.
- Honor pause, resume, archive-memory, and deletion requests.
- Monitor reliability, security, and abuse-prevention signals.
We do not sell personal information, use it for advertising, or share it with data brokers.
4. AI and Infrastructure Providers
Sage uses service providers only as needed to operate the product:
- Meta / WhatsApp: WhatsApp messages and delivery metadata are processed by Meta under WhatsApp's applicable terms and policies.
- Google Cloud: Sage runs on Google Cloud services, including Cloud Run, Cloud SQL for PostgreSQL, Cloud KMS, and Secret Manager.
- AI model providers: Sage can route model tasks to OpenAI and Anthropic. Message content and relevant context may be sent to the configured provider to generate replies or memory operations. Provider security and abuse-monitoring retention may apply according to the provider account settings and terms.
5. Storage and Security
Sage stores production data in PostgreSQL on Google Cloud. Sensitive application records, including message content, memories, delivery payloads, and channel handles, are encrypted at the application layer with per-user data encryption keys wrapped by Google Cloud KMS. Runtime secrets are stored in Google Secret Manager. Logs are designed to contain operational IDs, states, timing, and error codes rather than message plaintext.
No system can guarantee absolute security, but we restrict access, use HTTPS for external services, and keep administrative access limited to operating Sage.
6. Retention
Sage keeps account data, message history, and memories while your account is active so the assistant can provide continuity. If you use the WhatsApp command ARCHIVE MEMORY and confirm with CONFIRM, active memories are archived and excluded from future replies, but they are not permanently deleted by that command.
If you request full account deletion, we delete the active production records associated with your Sage user account after verifying the request. Database backups and point-in-time recovery logs may retain deleted data until they expire, currently up to 7 days.
7. Your Choices
- Send MEMORY in WhatsApp to see a summary of active memories.
- Send ARCHIVE MEMORY and then reply CONFIRM when Sage asks you to confirm to stop Sage from using current active memories in future replies.
- Send PAUSE to pause Sage replies and RESUME to turn them back on. Commands are exact and uppercase.
- Request full account deletion by emailing omerekin4@gmail.com.
8. Data Deletion
To request full deletion of your Sage account data, email omerekin4@gmail.com with the subject line "Sage data deletion request". Include the WhatsApp phone number you used with Sage or another identifier we can use to verify your account.
After verifying the request, we delete the active production records associated with your Sage user account, including user records, linked WhatsApp channel identity, access grants, message events, memories, turn data, deliveries, follow-ups, and user encryption key material. Deleted data may remain in database backups and point-in-time recovery logs until those backups expire, currently up to 7 days.
9. Children's Privacy
Sage is not intended for anyone under 18.
10. Changes
If we make material changes to this policy, we will notify affected invited users through Sage or by email before the changes take effect when practical.
11. Contact
For privacy, access, or deletion requests, email omerekin4@gmail.com.