Legal

Privacy Policy

Effective 28 July 2026

This policy covers Sally Skills, the API gateway at sally.a1c.io, and the Sally A1C GPT that calls it. It does not cover the A1C Insights iOS app, which handles personal health data under its own policy.

The short version

The Sally A1C GPT reads three shared reference data sets. It has no access to your glucose, labs, sleep, or wearables, and it does not ask for them. The only content that reaches our servers is the text you type into a question, and we do not use it to build a profile of you.

What we receive

Three skills are reachable from the GPT. Each sends only the field listed below:

SkillWhat it sendsWhy
search_health_knowledgeThe health question, as textRetrieve matching passages from our research library
lookup_supplement_gradeA brand and product name, as textLook up a stored quality grade for that product
lookup_foodA food name and an optional portion in gramsReturn nutrition figures and a classification

None of these accept a name, an account identifier, a lab value, a medication, a symptom, or a location. The GPT is instructed to strip identifying detail before it calls a skill, and the request schemas reject any field not listed above.

If you type personal health information into a question anyway, it reaches our servers inside that text. We do not store the text of your questions. Please do not send us your medical details through this route.

What we log

Every API call writes one operational record so we can bill, rate limit, and debug. That record holds the API key identifier, the skill name and version, a timestamp, the response time, the cost, and whether the call succeeded. It does not hold your question, the response, or anything identifying you.

When the GPT is published publicly it authenticates with a single service key belonging to A1C, so these records cannot be traced back to an individual user of the GPT.

What we do not do

  • We do not sell or rent your data.
  • We do not serve advertising, and we do not share data with ad networks.
  • We do not build behavioural profiles, and we do not track you across other sites or apps.
  • We do not read your ChatGPT conversation. Our servers see only the single field each skill is given.
  • We do not accept protected health information, payment card data, government identifiers, or credentials through these skills.

Who processes data on our behalf

ProcessorRoleWhat it receives
OpenRouterText embedding for semantic searchThe query text, to convert into a vector
Google Cloud PlatformHosting, database, vector searchRequests in transit, plus the operational records above
StripePayments, for API customers onlyBilling details you give Stripe directly. We never see your card number

OpenAI operates ChatGPT and the GPT Store, and its own privacy policy governs your conversation with the GPT before any call reaches us.

How long we keep it

Question text is not written to disk. Search results are cached for one hour, keyed by a hash of the query, then discarded. Operational records are kept for 24 months for billing and abuse investigation, and then deleted.

Where data is processed

Production runs in Google Cloud in Singapore, with staging in AWS. Embedding requests are processed by OpenRouter in the United States. If you are in the EEA or the UK, this means your query text is transferred outside your region while it is being processed.

Your rights

Depending on where you live you may have the right to access, correct, port, or delete personal data we hold, to object to processing, and to complain to a supervisory authority. Because the public skills hold no personal data, in most cases there is nothing to return or erase. For API customers we hold an account record and billing history, and those rights apply in full.

To exercise a right, or to ask what we hold, write to [email protected]. We answer within 30 days.

Children

These services are not directed at children under 13, and we do not knowingly collect their data. The GPT is written to be suitable for general audiences.

Not medical advice

Sally provides educational information with sources attached. It does not diagnose, does not prescribe, and is not a substitute for care from a qualified clinician. If something may be urgent, seek medical help rather than asking Sally.

Attribution of third party data

Nutrition figures come from Open Food Facts, licensed under ODbL 1.0. Supplement product records come from the NIH Dietary Supplement Label Database. The quality grades are A1C's own assessment and are not endorsed by the NIH.

Changes

We will update this page when our data handling changes and will move the effective date above. Material changes will be announced at console.a1c.io.

Contact

A1C, operator of Sally AI. [email protected]

Back to Sally Skills