Privacy Policy
Effective 15 July 2026 · Sage (SEOMatic) · Contact: sageatseomatic@gmail.com
Sage is an SEO automation service for Shopify brands, operated as a small productized service. This policy describes exactly what data Sage accesses, what it does with it, where it is stored, and who it is shared with. It is written to match what the software actually does, not what a template says.
1. Who we are
Sage is operated by Khushi Dassani ("we", "the operator"). The service runs on a single application server hosted on Fly.io and serves this website and a client approval portal. Questions and requests about your data go to sageatseomatic@gmail.com.
2. Google user data
Sage connects to three Google services. Each connection is separate, uses the minimum scope needed, and is described here individually.
2a. Gmail (drafting outreach emails)
Sage requests the gmail.compose and gmail.modify scopes on the Gmail account of the person who authorizes it — today that is the operator's own Sage account; in future, a client may authorize their own Gmail account so that backlink outreach for their brand is drafted from their own address. With that access, Sage:
- Creates drafts. Sage writes outreach emails (backlink pitches to journalists and bloggers, and sales outreach to prospective clients) and saves them as drafts in the authorized account, filed under a "SEOMatic Outreach" label it creates.
- Never sends email automatically. There is no code path in Sage that sends a message. Every draft is reviewed and sent (or deleted) manually by the human who owns the account. Client backlink drafts are additionally gated behind the client's approval in the portal before the draft is even created.
- Creates and applies labels to organize its own drafts, and reads the authorized account's own email address (the Gmail profile) to tell the account owner's messages apart from replies.
- Reads only its own conversations, never the inbox at large. To detect whether a prospect replied, Sage fetches only the specific threads it started, by their stored thread IDs, in metadata format (sender headers, not message bodies). For a small number of older records without a stored thread ID, it runs a search restricted to messages from that one specific contact address it previously wrote to. Sage never lists, scans, reads, or analyzes the rest of the mailbox, and it never reads the body content of received emails.
Limited Use disclosure. Sage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: Google user data is used only to provide the drafting and reply-tracking features described above. It is not used for advertising, not sold, not used to train AI or machine-learning models, and not read by humans except the account's own owner and, where needed to operate or debug the service, the operator.
2b. Google Search Console (read-only)
To measure a client's search performance, the client adds Sage's Google service account as a restricted/viewer user on their own Search Console property. Sage uses the read-only scope (webmasters.readonly) to read query, page, impression, click, and position data. Sage never authenticates as the client and cannot modify anything in Search Console.
2c. Google Analytics 4 (read-only)
Similarly, a client may grant the same service account Viewer access on their GA4 property. Sage uses the read-only scope (analytics.readonly) to read aggregate traffic metrics (sessions, users, conversions by channel and landing page). Sage reads aggregate reporting data only; it does not access individual visitor identities, and it cannot change anything in the client's Analytics account.
3. Shopify store data
Clients provide a Shopify Admin API access token for their own store. Sage uses it to read products, collections, pages, and blog posts, and to write only changes the client has approved in the portal: SEO titles, meta descriptions, on-page copy edits, redirects, and blog posts (drafts by default). Sage does not access customer records, orders, or payment data.
4. What we store, and where
- OAuth tokens and API credentials (Gmail OAuth token, Google service-account key, Shopify token) are stored as files on the application server's private volume on Fly.io. They are excluded from source control, are not shared with anyone, and are used only to make the API calls described above.
- Working data per client — search-performance snapshots, drafted content, outreach logs (contact name, publicly listed email address, site, draft status, and whether a reply arrived) — is stored as files on the same server, and is visible to the client in their password-protected portal.
- What we do not store: Gmail message bodies from anyone else's emails, Gmail contacts, inbox contents, Shopify customer or order data, or any Google account password (Sage never sees passwords — access is via OAuth and revocable tokens only).
5. Sharing and subprocessors
We do not sell or rent any data. Data is shared only with the infrastructure needed to run the service:
- Fly.io — hosts the application and its storage.
- Anthropic (Claude API) — generates draft text (blog posts, page rewrites, outreach emails). The material sent to it is the client's own brand/site content and Sage's own previously drafted emails. Received Gmail messages are not sent to any AI model — reply detection reads sender headers only.
- Google and Shopify APIs — as described above, at the direction of the account owner who granted access.
6. Security
All traffic to this site and the portal is forced over HTTPS. The portal is authentication-protected. Credentials live outside source control on a private server volume, and the operator is the only person with server access. No system is perfectly secure, but the attack surface here is deliberately small: one server, no database of end-user accounts, no stored passwords.
7. Retention and deletion
Credentials and client working data are kept while the engagement is active. When a client leaves — or on request at any time — we delete their tokens and workspace from the server. You can also cut off Sage's access yourself, instantly and unilaterally:
- Google: revoke access at myaccount.google.com/permissions, or remove the service account from your Search Console / GA4 property.
- Shopify: uninstall the private app / revoke the token in your Shopify admin.
To request deletion of stored data, email sageatseomatic@gmail.com; we will confirm within 7 days.
8. Changes to this policy
If how Sage handles data changes, this page changes with it, and the effective date above is updated. Material changes affecting an active client are communicated directly.
9. Contact
For anything about this policy or your data: sageatseomatic@gmail.com.