Skip to content
Sage Brief
Creative TeamsFreelancersIntegrationsPricingBlogSupport
Sign inCreate your workspace
Creative TeamsFreelancersIntegrationsPricingBlogSupport
Sign inCreate your workspace
Legal

Privacy Policy

Effective August 30, 2026

On this pageOverviewInformation we collectHow we use itWebsite measurementPayments and StripeAI processingGoogle user dataConnected servicesHow we share informationLegal basesRetention and securityYour choices and rightsChildrenInternational processingChangesContact

Overview

Sage Brief helps people collect creative requests and organize them into structured briefs. This policy explains how Sage Brief collects, uses, stores, and shares information when you visit sagebriefapp.com, use sagebrief.app, create or join a workspace, connect a third-party service, buy a subscription, or submit a request.

Sage Brief is provided by Sage Brief LLC, a California limited liability company. In this policy, “Sage Brief,” “we,” “us,” and “our” refer to Sage Brief LLC and the services it provides.

A workspace controls the requests and briefs created for that workspace. If you submit a request through an intake link, the workspace owner and authorized members can access your submission. Contact the workspace owner first with questions about how it uses that information.

For account, billing, website, security, and service-operations information, Sage Brief determines why and how the information is processed. For content a customer places in its workspace, Sage Brief generally processes the content on that customer’s instructions. A customer may have its own privacy notice and legal obligations for that content.

Information we collect

Account and workspace information

We may collect your name, email address, profile photo, pronouns, workspace name, workspace role, membership, invitations, settings, and sign-in records. Authentication providers handle passwords and sign-in credentials.

Requests, briefs, and workspace content

We collect the information you add to Sage Brief, including request text, intake answers, voice transcripts, source files, attachments, deliverables, dates, priorities, specifications, comments, edits, activity, generated brief content, missing-detail suggestions, request questions, and Smart Specs.

On a public intake page, selecting Review brief transmits the draft request details to Sage Brief before the requester selectsSend request. Sage Brief uses automated processing to review the draft for missing information. The workspace receives the request only after it is sent, but Sage Brief may process draft content earlier for review, security, and abuse prevention.

Voice and files

When you use Voice, the recording is sent to a transcription provider so it can be turned into text. Sage Brief stores the resulting transcript as request content. Sage Brief does not intentionally retain the original audio after the transcription request completes. If live speech preview is available, your browser or operating-system speech service may also process audio under the provider’s own terms.

When you add a PDF or PowerPoint source file, Sage Brief stores and processes the file to extract text and other information for the request. Extracted content may be sent to the AI providers listed on the Subprocessors page. The original is not shown to other workspace members unless you choose to share it, but Sage Brief and its providers still process it to provide the feature.

Payment and billing information

Stripe collects payment method and billing details directly during checkout. Sage Brief does not receive or store your full payment card number. We receive billing records needed to manage your account, such as your Stripe customer and subscription identifiers, selected plan, billing interval, trial or promotion status, renewal date, cancellation status, payment status, billing email, and transaction history.

Technical and usage information

We may collect IP address, browser and device information, approximate location derived from IP, dates and times of activity, features used, error reports, security events, and cookie or local-storage information needed for sign-in, drafts, onboarding, security, and preferences.

We also collect source-processing usage records, including credits used, the workspace allowance, credits remaining, reset time, and related operational counts. Workspace members with access to the usage panel may see the workspace’s aggregate meter. Authorized Sage Brief personnel may access aggregate usage and history to operate plan limits, provide support, troubleshoot, secure the service, and investigate abuse. The meter itself does not display source text, filenames, or excerpts.

We may also record privacy-limited service telemetry about usage, performance, reliability, and resource or cost information. We use these records to operate, secure, troubleshoot, and improve the service and manage service-provider usage. These telemetry records are designed not to include request or source content, prompts, generated responses, filenames, or field values.

On the public website, first-party browser storage may also remember a pseudonymous attribution identifier, first-touch and last non-direct campaign information, UTM parameters, the landing path and time, the referring hostname without its full URL, supported advertising click references, and your privacy-choice state. Campaign fields are length-limited and must not contain names, email addresses, brief content, or other personal details.

Public pages currently request font or icon files from Google Fonts, jsDelivr, Simple Icons, and Iconify. Like other ordinary web asset requests, those services may receive an IP address, device and browser information, and request metadata needed to deliver the requested file. These requests are not advertising or analytics tags.

Browsers may send “Do Not Track” signals. Because there is no uniform industry standard for those signals, Sage Brief does not respond to Do Not Track itself. We do honor Global Privacy Control as described below. Providers that deliver public web assets may receive request information across websites under their own practices; Sage Brief does not use those asset requests to build a cross-site profile.

How we use information

We use information to:

  • create and secure accounts and workspaces;
  • save requests, intake links, briefs, comments, and Smart Specs;
  • transcribe voice input and read files you choose to add;
  • organize requests, create brief summaries, apply saved specs, and identify missing details;
  • suggest repeated specifications for you to approve or dismiss;
  • process checkout, subscriptions, renewals, promotions, and cancellations;
  • measure allowances, show workspace usage, and enforce plan limits;
  • provide exports or connections you explicitly request;
  • provide support and communicate about the service;
  • understand which campaigns lead to account creation, trials, and subscriptions while applying your privacy choices;
  • monitor reliability, security, fraud, abuse, and product performance;
  • keep accounting and transaction records; and
  • comply with law and enforce our terms.

Website measurement and advertising choices

Sage Brief uses a first-party, pseudonymous attribution record to distinguish a visitor’s first campaign touch from the most recent non-direct campaign touch. When you follow a link from sagebriefapp.com to sagebrief.app, the detailed campaign record is sent directly between the two services in a signed, short-lived exchange. The link itself receives only an opaque identifier; it does not receive UTM values, advertising click references, your email address, or a full referring URL.

After Sage Brief first captures supported campaign and advertising-click parameters, it removes those captured values from the visible page URL before an optional external browser tag can load. The page path, hash, and unrelated query parameters remain. Advertising click references stay in the scoped first-party attribution and server conversion path rather than general browser analytics. If Sage Brief cannot confirm that the visible URL was cleaned, no optional external browser analytics or advertising script loads during that page visit.

Optional analytics and advertising destinations are controlled through Your Privacy Choices. Advertising is off by default. A vendor tag is not loaded unless Sage Brief has separately configured the destination and the relevant choice is allowed. The preference layer and dormant integration points do not, by themselves, activate a third-party analytics or advertising provider.

If advertising measurement is later enabled and allowed, Sage Brief may send a configured provider a conversion event, advertising click reference, event time, and relevant plan, value, and currency fields. Sage Brief will not include your name, email address, user IP address, or brief content in that conversion-event payload. Pseudonymous identifiers and click references may still be personal information under applicable law.

We honor an active Global Privacy Control signal by keeping advertising, sale/share, and targeted-ad uses off. You can reopen Your Privacy Choices from any public website page to change your settings. Choices are synchronized across open public-site tabs. A later opt-out is retried until Sage Brief confirms it and supersedes an earlier permission for future processing.

Advertising measurement and the sale/share and targeted-ad opt-outs are separate choices. Enabling advertising measurement does not clear an opt-out. Before campaign attribution is linked to an account or workspace, you may request an opt-back by turning off each opt-out, saving that revision, and then separately enabling advertising measurement. Once attribution is linked, public-site choices can make the account-linked state more restrictive but cannot restore advertising, sale/share, or targeted-ad use in this release. Sage Brief’s confirmed product state controls. Global Privacy Control disables opt-back while active. Sage Brief keeps a private, revisioned consent history without your name or email so an older permission cannot overwrite a later restriction.

If the product reports that a previously deleted attribution identifier is retired, the public site discards that entire local attribution record and its pending snapshot. It creates a new identifier with the current direct landing and preserves your privacy choices, but does not copy the retired campaign, referrer, or advertising-click information into the replacement.

When attribution first becomes linked, the current restrictions—including the privacy-protective defaults when no optional permission was given—apply across the attribution groups connected to that user or workspace. Later restrictions also apply across those connected records. The credited campaign touch is then frozen; later public-site handoffs cannot add advertising click references, change the credited campaign, or change workspace attribution.

Payments and Stripe

Sage Brief uses Stripe for checkout, payment processing, subscription billing, and fraud prevention. Stripe may collect payment method, billing, transaction, device, IP address, cookie, and fraud-prevention information. Stripe handles that information under its own Privacy Policy.

We use the billing information Stripe returns to activate and manage your plan, provide billing support, prevent fraud, and meet tax, accounting, dispute, and legal obligations.

AI processing

Sage Brief sends the content needed for a selected feature to AI and transcription service providers. These providers help transcribe audio, interpret submitted text and files, support clarification, and generate or organize request outputs. Within Sage Brief, stored uploads and request content remain scoped to the relevant workspace, intake session, or request.

Sage Brief does not itself use your requests, files, briefs, Smart Specs, transcripts, or Google user data to train a generalized AI model, and we do not submit that information for that purpose. Providers process content under their applicable business or API terms and configured settings. Depending on the provider and configuration, they may retain limited content or metadata for service delivery, monitoring, security, abuse prevention, troubleshooting, billing, or legal compliance. See our Subprocessors page for the providers currently involved.

AI output may be incomplete or wrong. A person should review a brief before submitting, sharing, or relying on it.

Sage Brief does not use AI output to decide whether a person is eligible for employment, housing, credit, insurance, healthcare, education, government benefits, or another similarly significant opportunity. The service is not designed for those decisions.

Google user data

If you use Google to sign in, Google may provide Sage Brief with basic account information such as your Google account identifier, name, email address, and profile image. We use it to create, secure, and display your Sage Brief account.

If you separately choose to connect Google Drive, Sage Brief may request the drive.file and documents.readonly permissions. The current service uses the connection to create or update a Google Doc export you request. Although the Google Docs permission is broader, Sage Brief does not use it to browse or read unrelated Drive files.

We use connected Google data only to authenticate the connection, create or update an export you request, return the relevant link, and maintain or secure the connection. Google refresh tokens are encrypted at rest.

We do not sell Google user data, use it for advertising, or use or permit it to train generalized AI models. Humans do not read Google user data except when you give permission for support, when needed for security or abuse investigation, or when required by law.

Sage Brief’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google from Sage Brief settings or revoke access from your Google Account. Disconnecting removes Sage Brief’s stored connection credentials and stops future access. It does not delete documents already created in your Drive.

User-connected services

You may connect Google, Asana, ClickUp, monday.com, Trello, or Jira. Depending on the service, Sage Brief may store encrypted access or refresh tokens, account identity and email, granted scopes, workspace or project names and identifiers, destination settings, timestamps, and connection errors. At your direction, Sage Brief may send the complete consolidated brief—including its title, requester, priority, due date, deliverables, specifications, brief sections, and a Sage Brief link—to the destination you choose.

These services receive information as independent services you direct Sage Brief to use and process it under their own terms and privacy policies. You can disconnect a supported service in Sage Brief settings or revoke access with the service provider. Disconnecting stops future access and removes stored Sage Brief credentials where supported; it does not delete information already exported to that service.

How we share information

Sage Brief does not sell personal information or share it for cross-context behavioral advertising. We may share information:

  • Within a workspace. Workspace owners, administrators, and authorized members can access information based on their role.
  • With service providers. Providers support hosting, database, authentication, file storage, security, email, payment processing, transcription, AI processing, and service analytics. Our current provider list appears on the Subprocessors page.
  • With connected services. We send information to a third-party service only when you connect it or ask Sage Brief to perform an action there.
  • During a business transaction. Information may be disclosed to advisers and a potential or completed buyer, investor, financing source, or successor as part of due diligence or a corporate transaction, subject to appropriate safeguards.
  • For legal and safety reasons. We may disclose information when required by law or reasonably needed to protect rights, safety, users, or the service.
  • With your direction or consent. We share information when you ask us to.

Legal bases for processing

Where data-protection law requires a legal basis, we process information as needed to provide the service and perform our contract with you. We also process information for legitimate interests such as security, fraud prevention, support, service operation, and improvement. We rely on consent when required, including for certain connected services, and on legal obligations when we must keep records or respond to lawful requests.

Retention and security

Request, brief, intake, comment, membership, and Smart Specs data may remain until the relevant content, account, or workspace is deleted, subject to limited backup, security, and legal-retention periods.

Raw source-file originals are normally retained for a limited recovery period after successful extraction, and an unsubmitted source may become eligible for cleanup after 30 days. If you share an original with a workspace, it may remain with the request. Extracted text, mapped facts, and source evidence may remain as part of the request or its history until the related request, account, or workspace is deleted. Removing a source from the active source panel does not necessarily erase information already incorporated into a brief or audit history.

Billing and transaction records may be retained after an account closes when needed for tax, accounting, dispute, fraud-prevention, and legal obligations. Service providers may keep information under their own documented retention schedules.

Source-processing usage records may be kept as needed to operate and enforce plan allowances, troubleshoot meter questions, prevent abuse, maintain security, and resolve billing or service disputes.

Public-site acquisition context that has not been bound to an account expires, and the local marketing attribution record and any pending consent sync expire or rotate, after 180 days. When an account or workspace enters pending deletion, Sage Brief stops future local advertising-provider dispatch and physically deletes its row-level conversion records and queued provider events for that data. To prevent deleted data from being recreated by delayed retries, Sage Brief may keep two separate private, pseudonymous one-way keyed-HMAC suppression records, made with distinct secret peppers for distinct purposes. The first contains only a keyed HMAC of the former conversion event identifier and a day-coarse deletion date. It is kept only as long as necessary to stop delayed product or Stripe retries from recreating a deleted conversion; there is currently no fixed purge period for this safeguard. The second contains only a keyed HMAC of the former acquisition identifier and a day-coarse retirement date. It blocks a retired browser attribution from being inserted again and is purged after 400 days, exceeding the 180-day browser replay window. Neither record contains a foreign key, event, source, value, conversion date, or reporting link, and the two records are not used as reporting facts. They are pseudonymous suppression safeguards, not anonymous or deidentified data. The private consent history tied to that data is deleted when the account or workspace deletion completes.

Advertising events already delivered to a configured provider cannot be recalled from Sage Brief’s systems. Requests concerning information already held by an advertising processor must also follow that processor’s deletion or opt-out channels. Service providers may retain information when required by their own legal obligations.

We use safeguards designed to protect information, including access controls, encrypted connections, and encryption of stored Google refresh tokens. No online service can promise complete security. Keep your credentials private and avoid adding sensitive information that a creative request does not need.

Your choices and rights

Depending on where you live, you may be able to ask for a copy of your personal information, correct it, delete it, object to or limit certain processing, withdraw consent, receive portable information, or appeal a privacy decision.

Email support@sagebriefapp.com to make a request. We may need to verify your identity. Workspace administrators may control workspace data, so we may direct a request to the relevant workspace.

You can review or change common account and workspace information in the product. Privacy requests are handled under the law that applies to the request; describing a right here does not mean every privacy statute applies to Sage Brief or every request.

Sage Brief does not currently sell personal information or share it for cross-context behavioral advertising. Even so, Your Privacy Choices lets you record sale/share and targeted-ad opt-outs, and an active Global Privacy Control signal applies those opt-outs automatically.

Children

Sage Brief is intended only for adults age 18 or older and is not directed to children. We do not knowingly collect personal information directly from a child under 13. Customer content may contain information about other people, including minors, and the customer is responsible for having a lawful basis to submit it. If you believe a child has used Sage Brief directly, contact us so we can take appropriate action.

International processing

Sage Brief and its service providers may process information in countries other than the country where you live. Those countries may have different data protection laws. Where required, we use appropriate safeguards for international transfers.

Changes to this policy

We may update this policy as Sage Brief changes. We will post the new effective date here. Before a material change that permits a meaningfully broader use of personal information, we will provide notice by email or prominently in the service and obtain consent when required by law.

Contact

For privacy questions or requests, email support@sagebriefapp.com.

Sage Brief LLC
2108 N Street, Suite N
Sacramento, CA 95816

Sage Brief
ExploreIntegrationsPricing
SolutionsCreative TeamsFreelancers
ResourcesBlogHelp Center
Company & legalPressPrivacy PolicyYour Privacy ChoicesTerms of ServiceSubprocessors
© 2026 Sage Brief LLC
Sign insupport@sagebriefapp.compress@sagebriefapp.com