This Privacy Policy describes how Sage + Stone ("we," "us," or "our") collects, uses, and protects information when you use the Sage + Stone iOS application (Bundle ID: com.openagent.vitaldao). By using Sage + Stone, you agree to the practices described in this policy.
Sage + Stone is developed and operated as an independent iOS application. Our core function is to help users discover paid clinical trials listed on ClinicalTrials.gov that may match their health profile. We do not provide medical advice, and we are not a healthcare provider or covered entity under HIPAA.
With your explicit permission, Sage + Stone may read the following HealthKit categories to perform trial eligibility matching:
HealthKit data is used to compute clinical-trial eligibility and to power the optional features you enable. Specifically:
Optional AI features: Separately from the local matching described above, Sage + Stone offers optional AI-powered features (such as AI insights and trial-readiness summaries). If you choose to use them, a limited set of health context you have entered or that Sage + Stone has read from HealthKit (for example age, biological sex, conditions, medications, and selected metrics) is transmitted to our third-party AI provider (Anthropic) to generate your results. See Third-Party Services for details.
In compliance with Apple's HealthKit guidelines, Sage + Stone:
Sage + Stone uses the public ClinicalTrials.gov API (operated by the U.S. National Library of Medicine, NIH) to retrieve clinical trial listings. This is a public API — no personal data is sent to ClinicalTrials.gov or the NIH when we fetch trial data.
The matching process:
We fetch trial data from the public ClinicalTrials.gov REST API. This service is operated by the U.S. federal government. Requests to this API do not include your personal health information. The NIH's privacy policy governs their data practices: https://www.nih.gov/web-policies-notices.
Subscription and one-time purchase transactions are handled entirely by Apple's App Store infrastructure. Sage + Stone receives only anonymized transaction receipts for entitlement verification. Apple's privacy policy governs payment processing: https://www.apple.com/privacy/.
If you enable AI insights, a limited set of health context you have provided or that Sage + Stone has read from HealthKit — which may include your age, biological sex, health conditions, medications, smoking status, and selected health metrics — is transmitted to our third-party AI provider, Anthropic, PBC, over an encrypted connection solely to generate your AI results. This happens only after you accept an in-app consent disclosure; it is not sent for ordinary local trial matching. Anthropic processes this data as our service provider to return results to you and does not use it to train models on your behalf. Anthropic's privacy practices are described at https://www.anthropic.com/legal/privacy. If you prefer not to share this information, do not use the AI features.
Our backend — reached over our secure REST API and, for live streaming, a realtime websocket connection — stores your account email and the data required for optional features you enable — live data sync, multi-device aggregation, and rewards. These optional features are only available when our sync backend is enabled in the app. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We never sell it or share it with advertisers or data brokers.
If you enable notifications, trial match alerts and app notifications are delivered through the Apple Push Notification service (APNs). Your device push token and notification content pass through Apple's infrastructure. Apple's privacy policy applies: https://www.apple.com/privacy/. You can disable notifications at any time in iPhone Settings → Notifications → Sage + Stone.
Sage + Stone does not integrate any third-party advertising SDKs, tracking pixels, or behavioral analytics platforms that share data with advertisers.
Sage + Stone includes an optional "data proof" feature that lets you create a cryptographic, on-chain record (a compressed NFT on the Solana blockchain) attesting that a health-data snapshot existed at a point in time. This feature is used only when you actively choose to mint or verify a proof; nothing is sent to these providers during ordinary use of the app.
What is sent: When you mint a proof, Sage + Stone computes a one-way SHA-256 hash of the selected health-data snapshot on your device and transmits that hash — together with limited metadata (a record-type label such as the category of data, the device source, a timestamp, and your app-generated Solana wallet address) — to Crossmint (Paella Inc.), which mints the proof on your behalf. To later display or verify your proofs, Sage + Stone queries Helius (Helius Technologies, Inc.), a Solana RPC provider, using your wallet address and proof identifiers. We do not send your raw HealthKit data, biomarker values, name, email, or other directly identifying information to either provider.
Important — on-chain data is public and permanent: Data written to a public blockchain (the data hash, record-type label, device source, timestamp, and wallet address) is, by the nature of the technology, publicly visible and effectively permanent; it generally cannot be edited or deleted, including by Sage + Stone. The hash is one-way and is not intended to reveal the underlying health values, but you should treat any on-chain proof and its metadata as public information. Because this is optional, if you prefer not to publish anything on-chain, simply do not use the data-proof feature. Crossmint's privacy policy is available at https://www.crossmint.com/legal/privacy-policy and Helius's at https://www.helius.dev/privacy-policy.
We use collected data only for the following purposes:
We do not use your data for targeted advertising, data brokerage, or any purpose unrelated to the Sage + Stone app's stated function.
We do not sell, rent, or trade your personal information. We may share information only in these limited circumstances:
This pledge matches the commitment published on our homepage and is binding on us. Notwithstanding the "Legal Compliance" circumstance above, we do not voluntarily disclose menstrual, cycle, reproductive-health, or lab data to law enforcement or any government authority, and we will challenge any legal demand for such data to the fullest extent permitted by law and notify you unless legally barred from doing so. Because core matching runs on your device and HealthKit data is never persisted on our servers, in most cases we hold no such data to produce.
Account and health profile data is retained as long as your account is active. You may delete your account and associated data at any time via Settings → Account → Delete Account within the app, or by emailing privacy@sageplusstone.com.
Anonymized analytics data may be retained for up to 24 months to improve app quality. HealthKit data is never persisted — it is read at the time of matching and discarded immediately after the on-device computation completes.
We implement industry-standard security practices including:
No system is 100% secure. If you believe your account has been compromised, contact privacy@sageplusstone.com immediately.
You can grant or revoke HealthKit access at any time in iPhone Settings → Privacy & Security → Health → Sage + Stone. Revoking access does not delete your Sage + Stone account or subscription.
You can manage push notification preferences in iPhone Settings → Notifications → Sage + Stone.
You can delete your Sage + Stone account and all associated data from within the app (Settings → Account → Delete Account) or by emailing privacy@sageplusstone.com. Deletion is processed within 30 days.
You may request a copy of personal data we hold about you by emailing privacy@sageplusstone.com. We will respond within 30 days.
Sage + Stone is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that a user under 18 has provided personal information, we will delete it promptly. If you believe a minor has used Sage + Stone, please contact privacy@sageplusstone.com.
The data you provide to Sage + Stone is for the purpose of research trial matching and the optional features described in this policy. Because Sage + Stone is not a covered entity or business associate, the health information you provide is not "Protected Health Information" as that term is defined by HIPAA, and HIPAA does not apply to it. This does not mean your information is unprotected: any health data you share with Sage + Stone is provided voluntarily and is governed by this Privacy Policy, including the disclosures above about on-device processing and our third-party AI provider.
For health information held by your healthcare providers, Apple Health, or other covered entities, the privacy protections of HIPAA and the relevant entity's Notice of Privacy Practices apply separately.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise any of these rights, contact us at privacy@sageplusstone.com with "CCPA Request" in the subject line. We will respond within 45 days.
Categories of personal information collected (last 12 months):
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notice and update the "Effective Date" at the top of this policy. Your continued use of Sage + Stone after changes take effect constitutes acceptance of the revised policy.
For privacy questions, data requests, or concerns about this policy:
We are committed to responding to all privacy inquiries within 30 days.