Key Privacy Summary: Sage + Stone reads Apple Health data on your device, and core clinical-trial matching runs locally against the public ClinicalTrials.gov registry. Optional features you choose to turn on — AI insights and live data sync — send only the data they need (such as age, biological sex, conditions, medications, and selected health metrics) to our secure backend and our third-party AI provider (Anthropic), always with your explicit consent — see Third-Party Services. We never sell your data, share it with data brokers, or use it for advertising.

Table of Contents

  1. Scope and Overview
  2. Data We Collect
  3. Apple HealthKit Data
  4. How Trial Matching Works
  5. Third-Party Services
  6. How We Use Your Data
  7. Data Sharing and Disclosure
  8. Data Retention
  9. Security
  10. Your Rights and Choices
  11. Children's Privacy
  12. HIPAA Notice
  13. California Privacy Rights (CCPA)
  14. Changes to This Policy
  15. Contact Us

1. Scope and Overview

This Privacy Policy describes how Sage + Stone ("we," "us," or "our") collects, uses, and protects information when you use the Sage + Stone iOS application (Bundle ID: com.openagent.vitaldao). By using Sage + Stone, you agree to the practices described in this policy.

Sage + Stone is developed and operated as an independent iOS application. Our core function is to help users discover paid clinical trials listed on ClinicalTrials.gov that may match their health profile. We do not provide medical advice, and we are not a healthcare provider or covered entity under HIPAA.

2. Data We Collect

2.1 Data You Provide Directly

2.2 Automatically Collected Data

2.3 Data We Do NOT Collect

3. Apple HealthKit Data

Critical Privacy Commitment: Sage + Stone requests read-only access to Apple HealthKit. Core trial matching is processed on your device. Some optional features transmit specific health data only with your explicit consent: AI insights send a limited set of health context (such as age, biological sex, conditions, medications, and selected health metrics) to our third-party AI provider (Anthropic), and live data sync / streaming sends biometric data to our secure backend. We never send HealthKit data to advertising networks or analytics-profiling services, and we never sell it. This is described in Third-Party Services.

3.1 What HealthKit Data We Access

With your explicit permission, Sage + Stone may read the following HealthKit categories to perform trial eligibility matching:

3.2 How HealthKit Data Is Used

HealthKit data is used to compute clinical-trial eligibility and to power the optional features you enable. Specifically:

Optional AI features: Separately from the local matching described above, Sage + Stone offers optional AI-powered features (such as AI insights and trial-readiness summaries). If you choose to use them, a limited set of health context you have entered or that Sage + Stone has read from HealthKit (for example age, biological sex, conditions, medications, and selected metrics) is transmitted to our third-party AI provider (Anthropic) to generate your results. See Third-Party Services for details.

3.3 HealthKit Restrictions

In compliance with Apple's HealthKit guidelines, Sage + Stone:

4. How Trial Matching Works

Sage + Stone uses the public ClinicalTrials.gov API (operated by the U.S. National Library of Medicine, NIH) to retrieve clinical trial listings. This is a public API — no personal data is sent to ClinicalTrials.gov or the NIH when we fetch trial data.

The matching process:

  1. Trial eligibility criteria (age range, sex, conditions, biomarkers) are downloaded from the public ClinicalTrials.gov API to your device.
  2. Your local health profile (derived from HealthKit + your optional inputs) is compared against each trial's criteria on-device.
  3. A match score is calculated locally. Only the match score and trial ID are surfaced in the UI.
  4. When you choose to view a trial or apply, you are directed to the trial's official contact information on ClinicalTrials.gov. Sage + Stone does not facilitate or intermediate any application process.

5. Third-Party Services

5.1 ClinicalTrials.gov API (NIH / U.S. National Library of Medicine)

We fetch trial data from the public ClinicalTrials.gov REST API. This service is operated by the U.S. federal government. Requests to this API do not include your personal health information. The NIH's privacy policy governs their data practices: https://www.nih.gov/web-policies-notices.

5.2 Apple StoreKit (In-App Purchases)

Subscription and one-time purchase transactions are handled entirely by Apple's App Store infrastructure. Sage + Stone receives only anonymized transaction receipts for entitlement verification. Apple's privacy policy governs payment processing: https://www.apple.com/privacy/.

5.3 Anthropic (AI insights — optional)

If you enable AI insights, a limited set of health context you have provided or that Sage + Stone has read from HealthKit — which may include your age, biological sex, health conditions, medications, smoking status, and selected health metrics — is transmitted to our third-party AI provider, Anthropic, PBC, over an encrypted connection solely to generate your AI results. This happens only after you accept an in-app consent disclosure; it is not sent for ordinary local trial matching. Anthropic processes this data as our service provider to return results to you and does not use it to train models on your behalf. Anthropic's privacy practices are described at https://www.anthropic.com/legal/privacy. If you prefer not to share this information, do not use the AI features.

5.4 Sage + Stone Servers (account, sync, streaming)

Our backend — reached over our secure REST API and, for live streaming, a realtime websocket connection — stores your account email and the data required for optional features you enable — live data sync, multi-device aggregation, and rewards. These optional features are only available when our sync backend is enabled in the app. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We never sell it or share it with advertisers or data brokers.

5.5 Apple Push Notifications (APNs)

If you enable notifications, trial match alerts and app notifications are delivered through the Apple Push Notification service (APNs). Your device push token and notification content pass through Apple's infrastructure. Apple's privacy policy applies: https://www.apple.com/privacy/. You can disable notifications at any time in iPhone Settings → Notifications → Sage + Stone.

5.6 No Advertising Networks

Sage + Stone does not integrate any third-party advertising SDKs, tracking pixels, or behavioral analytics platforms that share data with advertisers.

5.7 Blockchain Data-Proof Providers (Crossmint & Helius)

Sage + Stone includes an optional "data proof" feature that lets you create a cryptographic, on-chain record (a compressed NFT on the Solana blockchain) attesting that a health-data snapshot existed at a point in time. This feature is used only when you actively choose to mint or verify a proof; nothing is sent to these providers during ordinary use of the app.

What is sent: When you mint a proof, Sage + Stone computes a one-way SHA-256 hash of the selected health-data snapshot on your device and transmits that hash — together with limited metadata (a record-type label such as the category of data, the device source, a timestamp, and your app-generated Solana wallet address) — to Crossmint (Paella Inc.), which mints the proof on your behalf. To later display or verify your proofs, Sage + Stone queries Helius (Helius Technologies, Inc.), a Solana RPC provider, using your wallet address and proof identifiers. We do not send your raw HealthKit data, biomarker values, name, email, or other directly identifying information to either provider.

Important — on-chain data is public and permanent: Data written to a public blockchain (the data hash, record-type label, device source, timestamp, and wallet address) is, by the nature of the technology, publicly visible and effectively permanent; it generally cannot be edited or deleted, including by Sage + Stone. The hash is one-way and is not intended to reveal the underlying health values, but you should treat any on-chain proof and its metadata as public information. Because this is optional, if you prefer not to publish anything on-chain, simply do not use the data-proof feature. Crossmint's privacy policy is available at https://www.crossmint.com/legal/privacy-policy and Helius's at https://www.helius.dev/privacy-policy.

6. How We Use Your Data

We use collected data only for the following purposes:

We do not use your data for targeted advertising, data brokerage, or any purpose unrelated to the Sage + Stone app's stated function.

7. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share information only in these limited circumstances:

7.1 Menstrual, Cycle and Lab Data — Our Binding Pledge

We never sell your data, and we never sell or hand over your menstrual, cycle or lab data to third parties or law enforcement.

This pledge matches the commitment published on our homepage and is binding on us. Notwithstanding the "Legal Compliance" circumstance above, we do not voluntarily disclose menstrual, cycle, reproductive-health, or lab data to law enforcement or any government authority, and we will challenge any legal demand for such data to the fullest extent permitted by law and notify you unless legally barred from doing so. Because core matching runs on your device and HealthKit data is never persisted on our servers, in most cases we hold no such data to produce.

8. Data Retention

Account and health profile data is retained as long as your account is active. You may delete your account and associated data at any time via Settings → Account → Delete Account within the app, or by emailing privacy@sageplusstone.com.

Anonymized analytics data may be retained for up to 24 months to improve app quality. HealthKit data is never persisted — it is read at the time of matching and discarded immediately after the on-device computation completes.

9. Security

We implement industry-standard security practices including:

No system is 100% secure. If you believe your account has been compromised, contact privacy@sageplusstone.com immediately.

10. Your Rights and Choices

HealthKit Access

You can grant or revoke HealthKit access at any time in iPhone Settings → Privacy & Security → Health → Sage + Stone. Revoking access does not delete your Sage + Stone account or subscription.

Notifications

You can manage push notification preferences in iPhone Settings → Notifications → Sage + Stone.

Account Deletion

You can delete your Sage + Stone account and all associated data from within the app (Settings → Account → Delete Account) or by emailing privacy@sageplusstone.com. Deletion is processed within 30 days.

Data Access and Portability

You may request a copy of personal data we hold about you by emailing privacy@sageplusstone.com. We will respond within 30 days.

11. Children's Privacy

Sage + Stone is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that a user under 18 has provided personal information, we will delete it promptly. If you believe a minor has used Sage + Stone, please contact privacy@sageplusstone.com.

12. HIPAA Notice

Important HIPAA Clarification: Sage + Stone is NOT a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). Sage + Stone is a consumer application that helps individuals discover publicly listed clinical trials. We are not a healthcare provider, health plan, or healthcare clearinghouse.

The data you provide to Sage + Stone is for the purpose of research trial matching and the optional features described in this policy. Because Sage + Stone is not a covered entity or business associate, the health information you provide is not "Protected Health Information" as that term is defined by HIPAA, and HIPAA does not apply to it. This does not mean your information is unprotected: any health data you share with Sage + Stone is provided voluntarily and is governed by this Privacy Policy, including the disclosures above about on-device processing and our third-party AI provider.

For health information held by your healthcare providers, Apple Health, or other covered entities, the privacy protections of HIPAA and the relevant entity's Notice of Privacy Practices apply separately.

13. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise any of these rights, contact us at privacy@sageplusstone.com with "CCPA Request" in the subject line. We will respond within 45 days.

Categories of personal information collected (last 12 months):

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notice and update the "Effective Date" at the top of this policy. Your continued use of Sage + Stone after changes take effect constitutes acceptance of the revised policy.

15. Contact Us

For privacy questions, data requests, or concerns about this policy:

We are committed to responding to all privacy inquiries within 30 days.