Privacy Policy

Effective 15 July 2026 · Sage (SEOMatic) · Contact: sageatseomatic@gmail.com

Sage is an SEO automation service for Shopify brands, operated as a small productized service. This policy describes exactly what data Sage accesses, what it does with it, where it is stored, and who it is shared with. It is written to match what the software actually does, not what a template says.

1. Who we are

Sage is operated by Khushi Dassani ("we", "the operator"). The service runs on a single application server hosted on Fly.io and serves this website and a client approval portal. Questions and requests about your data go to sageatseomatic@gmail.com.

2. Google user data

Sage connects to three Google services. Each connection is separate, uses the minimum scope needed, and is described here individually.

2a. Gmail (drafting outreach emails)

Sage requests the gmail.compose and gmail.modify scopes on the Gmail account of the person who authorizes it — today that is the operator's own Sage account; in future, a client may authorize their own Gmail account so that backlink outreach for their brand is drafted from their own address. With that access, Sage:

Limited Use disclosure. Sage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: Google user data is used only to provide the drafting and reply-tracking features described above. It is not used for advertising, not sold, not used to train AI or machine-learning models, and not read by humans except the account's own owner and, where needed to operate or debug the service, the operator.

2b. Google Search Console (read-only)

To measure a client's search performance, the client adds Sage's Google service account as a restricted/viewer user on their own Search Console property. Sage uses the read-only scope (webmasters.readonly) to read query, page, impression, click, and position data. Sage never authenticates as the client and cannot modify anything in Search Console.

2c. Google Analytics 4 (read-only)

Similarly, a client may grant the same service account Viewer access on their GA4 property. Sage uses the read-only scope (analytics.readonly) to read aggregate traffic metrics (sessions, users, conversions by channel and landing page). Sage reads aggregate reporting data only; it does not access individual visitor identities, and it cannot change anything in the client's Analytics account.

3. Shopify store data

Clients provide a Shopify Admin API access token for their own store. Sage uses it to read products, collections, pages, and blog posts, and to write only changes the client has approved in the portal: SEO titles, meta descriptions, on-page copy edits, redirects, and blog posts (drafts by default). Sage does not access customer records, orders, or payment data.

4. What we store, and where

5. Sharing and subprocessors

We do not sell or rent any data. Data is shared only with the infrastructure needed to run the service:

6. Security

All traffic to this site and the portal is forced over HTTPS. The portal is authentication-protected. Credentials live outside source control on a private server volume, and the operator is the only person with server access. No system is perfectly secure, but the attack surface here is deliberately small: one server, no database of end-user accounts, no stored passwords.

7. Retention and deletion

Credentials and client working data are kept while the engagement is active. When a client leaves — or on request at any time — we delete their tokens and workspace from the server. You can also cut off Sage's access yourself, instantly and unilaterally:

To request deletion of stored data, email sageatseomatic@gmail.com; we will confirm within 7 days.

8. Changes to this policy

If how Sage handles data changes, this page changes with it, and the effective date above is updated. Material changes affecting an active client are communicated directly.

9. Contact

For anything about this policy or your data: sageatseomatic@gmail.com.