Legal
Privacy Policy
Inovo Studios, LLC
Effective Date: October 13, 2026
Last Updated: September 28, 2026
This Privacy Policy applies to meetsabi.com, app.meetsabi.com, the Sabi iPhone app, and the Sabi AI assistant service (collectively, "Sabi" or the "Service"), operated by Inovo Studios, LLC ("Company," "we," "us," or "our"). Sabi was formerly offered under the name "First AI Hire." Until September 2026, Sabi was operated by HLDFST INC; customer accounts and data moved to Inovo Studios, LLC, which now provides the Service. Receipts and card statements may still show HLDFST INC until our payment account transfer completes.
Your use of Sabi is also governed by our Terms of Service. Health data has its own Consumer Health Data Privacy Policy.
Other websites and products (including aiforcompanies.com and 8fig.ai) are covered by the separate policies posted on those sites.
1. Information We Collect
Information you provide
- Contact and account details: name, email, phone number, business information you share during signup or activation, and other email addresses we learn from your Stripe or connected Gmail account.
- Payment information: processed by our payment processor, Stripe, on Stripe Checkout. We do not see or store full card numbers.
- Messages and content: texts you send Sabi, voice messages (we keep the transcript, not the audio), photos and images you send (including meal photos), documents you upload to your library, and anything you ask Sabi to save.
- Support and feedback: bug reports, feature requests, and support messages. If Sabi hits an error while answering you, we automatically file a ticket that includes the first line of your message, with any pasted credentials removed.
- Community posts: posts, photos, and your name and email for the Sabi community, hosted by Tribe Social.
Information from connected accounts
When you choose to connect third-party accounts (for example Gmail, Google Calendar, Zoom, Slack, Stripe, QuickBooks, iCloud, or social platforms), Sabi accesses data from those accounts under the permissions you grant, solely to provide the Service. Depending on which connections and scopes you approve, this can include email content, calendar events, transcripts, files, transactions, and contacts. Most connections are authorized through Composio or Pipedream. When you connect a meeting app such as Zoom, Sabi may save meeting transcripts to your library.
You can revoke a connection at any time from your Sabi dashboard or directly with the third-party provider.
Bank accounts (only if you connect one)
Sabi can read your bank accounts when you ask it to. Sabi uses Plaid Inc. ("Plaid") to connect to your bank. Plaid's own privacy policy governs how Plaid collects and uses your data. Read it at plaid.com/legal/#end-user-privacy-policy.
- How the connection works. When you connect a bank on app.meetsabi.com/connections, you sign in to your bank inside Plaid's secure window. Your bank username and password go to Plaid, or to your bank directly. Sabi never sees or stores them. Plaid gives Sabi a private access key for that connection. Sabi stores that key encrypted on its servers.
- What Sabi reads. Only when you ask a question, Sabi reads from Plaid:
- Your bank's name and the last four digits of each account.
- Account names, types, and balances.
- Transactions for the period you ask about, by default the last 30 days: date, description, merchant, amount, pending status, and category.
- What Sabi keeps. Sabi stores the encrypted access key, your bank's name, and the last four digits of each connected account. Sabi does not keep a separate copy of your transactions. The answers Sabi gives you, including the bank figures in them, stay in your chat history with Sabi.
- Who else sees it. Plaid, which retrieves the data from your bank. The AI model providers that write Sabi's replies, which receive only the data needed for that one request. The infrastructure providers that host Sabi, as processors on Sabi's behalf. Bank data is never used for advertising or marketing, never sold, and never shared with data brokers.
- You stay in control. Choose Disconnect on app.meetsabi.com/connections at any time. Sabi then asks Plaid to remove the connection and deletes the access key. Deleting your Sabi account removes every bank connection and its access key along with the rest of your data. You can also view and remove connections made through Plaid at my.plaid.com.
Information from the Sabi iPhone app
The Sabi iPhone app connects your phone to your assistant. Before it uploads anything, the app tells you what it will upload and who processes it, and asks for your consent; for Apple Health it asks separately for consent to collect and consent to share. iOS then asks you to allow access as well. The app reads only what you allow:
- Signing in: your phone number, so Sabi can find your account and text you a sign-in code (members can use their email address and password instead), plus a random device identifier, the device model, the iOS and app version, a notification token, and which permissions you granted. These let Sabi nudge the app to sync.
- Apple Health: Sabi reads steps, distance for workouts, active energy, workouts, sleep, heart rate (daily average, minimum, and maximum), resting heart rate, heart rate variability, body weight, and nutrition (energy, protein, carbohydrates, fat, and water). Sabi writes the estimated energy, protein, carbohydrates, and fat of meals you log by texting Sabi a photo.
- Reminders: list name, title, notes, due date, and completion state. When you ask, Sabi adds or completes reminders on your phone.
- Contacts: names, organizations, phone numbers, and email addresses, used to look up a number or email address when you ask and to recognize the people you mention.
Sabi uses this data only to answer your requests and keep your phone up to date. It is stored on Sabi's servers in the United States (DigitalOcean and Supabase). To answer you, the AI providers that run Sabi (Anthropic, xAI through Vercel AI Gateway, and OpenAI) process the parts needed for each request. It is never sold, never used for advertising or marketing, and never shared with data brokers. You can change access at any time in iOS Settings → Privacy & Security → Health, Reminders, or Contacts. Deleting your Sabi account, with Delete my Sabi account in the app or on your account page, deletes the uploaded copy. Health data is also covered by our Consumer Health Data Privacy Policy.
Information collected automatically
- Usage data: features used, tasks run, message counts, credit consumption.
- Device and log data: IP address, device type, browser, pages viewed, and Sabi's activity log (a record of the tools your assistant uses on your behalf).
- Marketing and sign-up data: the ad campaign, UTM tags, or referral link that brought you to Sabi, an analytics visitor ID, and our sales team's notes on when they contacted you or made you an offer.
- Cookies and similar technologies: see the Cookie Notice below.
Information Sabi creates
To be useful, Sabi creates information from what you share and connect:
- Memories: facts Sabi learns about you, your business, your preferences, relationships, and health, including memories you import from ChatGPT, Claude, or 8Fig.Ai.
- Profiles of people and companies you mention (for example a name, title, and where they work).
- Night Shift summaries, drafts, suggestions, and task results; descriptions of images you send; images Sabi generates for you; and nutrition estimates from meal photos.
- Search indexes (numeric embeddings) of your memories, library documents, and support tickets.
Information about other people
Using Sabi involves information about people who aren't Sabi customers: your contacts, the people in your emails, calendar, and meeting transcripts, people in group chats that include Sabi (their handles and messages), and people you mention. We also receive names, emails, and phone numbers from people who fill out our ad forms (for example on Meta) before they sign up, and phone numbers of people who text Sabi without finishing sign-up. You are responsible for having the right to share other people's information with Sabi. Anyone can ask us to access or delete information about them by contacting us at [email protected].
2. How We Use Information
We use information to:
- Provide and operate Sabi, including running the tasks you request or schedule.
- Power Sabi's persistent memory and personalization, including background processing of your connected data ("Night Shift") to prepare summaries, drafts, suggestions, and reminders for you.
- Process payments, subscriptions, and refunds through Stripe.
- Provide support and respond to bug reports and feature requests.
- Send service communications by text and email, and, with your consent where required, marketing communications (opt out anytime via STOP or unsubscribe).
- Monitor usage, prevent fraud and abuse, limit the effect of prompt-injection attempts, reject forged webhooks, and enforce these Terms.
- Improve Sabi, including reviewing de-identified or aggregated usage patterns and a weekly product report for which our team reads the week's customer messages (only summarized content leaves that review). We keep de-identified data in de-identified form and do not try to re-identify it.
- Comply with legal obligations.
AI processing. To answer you, Sabi sends the parts of your messages and connected data needed for each request to these AI providers: Anthropic (Claude) for most replies; xAI (Grok), through Vercel AI Gateway, for some specialist tasks such as health, contacts, calendar, and finance questions; and OpenAI for search indexes, voice-message transcription, and image generation. We do not train AI models on your data. These providers' API terms do not allow them to train on it, and requests through Vercel AI Gateway are routed only to providers with zero-data-retention and no-training agreements. Some providers keep API data for a limited period (typically up to 30 days) for safety and abuse monitoring.
Google user data. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve user-facing features of Sabi that you request, is not used for advertising, and is not transferred except as necessary to provide those features, for security, or to comply with law. We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models. People on our team read Google user data only with your consent, for security purposes, to comply with law, or in aggregated, de-identified form for internal operations.
3. How We Share Information
We do not sell your personal information. We share information only with the parties below, and our service providers may use it only to provide their services to us.
- Service providers and processors:
- Anthropic, xAI (through Vercel AI Gateway), and OpenAI — AI models that generate Sabi's replies, search, transcription, and images (see AI processing above).
- Supabase — database, file storage, and sign-in.
- DigitalOcean — application hosting.
- Stripe — payments.
- Linq — delivers iMessage and text messages (your phone number and message content).
- Composio and Pipedream — authorize and run your connected-app requests.
- Plaid Inc. (San Francisco, CA) — financial data access when you connect a bank; see "Bank accounts" above.
- Mailgun — sends account and billing emails. Apple Push Notification service — notifications to the Sabi iPhone app.
- Sentry — error monitoring: technical details of errors, never session recordings or the text of your conversations with the AI.
- DataFast — product analytics on our website (with consent) and in the dashboard.
- Tribe Social and Storj — host community posts and photos.
- Engineering and support tools — Cognition (Devin), Anthropic (Claude Code), Slack, and GitHub, which our team uses to investigate problems. Access to customer content is limited, and support and engineering access is recorded in an access log. Slack reports and our code repositories receive only summarized or made-up example content.
- Advertising and marketing partners, on our marketing website only, and only if you accept those cookies: Google (Tag Manager and Analytics), Meta, Hyros, Instantly, Trybe, and ClickMagick receive identifiers and page activity to measure and improve our ads. AI For Companies, our marketing partner, runs the tag manager and ad-attribution domains (aiforcompanies.com) and the sign-up pages at 8fig.ai, so it receives the visitor data those tags and pages collect. Some state laws call this "sharing" for cross-context behavioral advertising. You can decline or withdraw it in Cookie Preferences, and we honor Global Privacy Control. We never use data from your Sabi account, connected apps, or iPhone for advertising.
- Video and form providers: Vimeo, Vidalytics, and the host of our background videos load with the pages of our website that contain them; HighLevel/RainFlow loads when you open a form.
- Third-party services you connect: when Sabi performs actions you direct (for example, creating a calendar event or drafting an email in your inbox).
- Professional advisors and authorities: where required by law, to protect rights and safety, or in connection with a corporate transaction, such as the 2026 move of Sabi from HLDFST INC to Inovo Studios, LLC (with notice where required).
- With your direction or consent: for example, testimonials you approve.
4. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data. Highlights:
- Data separation. Every record is tied to a customer account. In your dashboard, database Row Level Security returns only your own rows. Our servers filter every query by customer, and automated tests check that tables holding device data (such as health, contacts, and reminders) can't be read or written from a browser or signed-in client.
- Staff access. Our staff have no dashboard access to your messages, memories, library files, tasks, or connection details. When an engineer needs to look at your data to help you or fix a problem, access is limited, and support and engineering access is recorded in an access log with who, when, what kind of data, and why.
- Credentials. For Gmail, Google Calendar, and most other tools, Sabi connects through OAuth via Composio or Pipedream, so we never see your passwords. App passwords (such as iCloud or email), API keys, MCP keys, and device tokens are encrypted in Supabase Vault with authenticated encryption; the connection record keeps only a fingerprint. Keys are never sent back to your browser (except a Pebble token shown to its owner for setup) and are kept out of our activity logs.
- Pasted secrets. If you paste an API key, token, private key, or a password inside a link into a message, Sabi detects common credential formats and removes them before the message is stored or sent to an AI model.
- Approval gate. You can set an approval rule so Sabi won't send an email or text to someone else until you approve it. The gate is enforced by code outside the AI, not by instructing the model. Slack and Discord messages aren't covered by approval rules yet.
- Least-privilege design. Sabi is a set of specialists (email, calendar, and so on) routed by a parent controller, and each specialist gets only the tools for its job. A response-safety check flags replies that claim an action Sabi didn't actually run.
- Signed webhooks and rate limiting. Inbound events from Stripe, iMessage and SMS (Linq), Slack, Composio, Pipedream, and Meta are signature-verified before Sabi acts on them. Sign-in, data export, incoming text, and device webhook endpoints are rate-limited.
- Encryption in transit and at rest. TLS is enforced everywhere. Customer data is stored encrypted. Production secrets are stored as encrypted environment variables on DigitalOcean and are not committed to code.
- Error monitoring. Sentry alerts us to errors. It doesn't record your screen or session and doesn't receive the text of your conversations with the AI, though error details can include limited technical information.
- Activity log. Sabi keeps a record of the tools your assistant runs for you, so we can explain what happened and why.
Compliance posture. Sabi runs on infrastructure providers with their own SOC 2 reports (Supabase, Stripe, DigitalOcean). Inovo Studios has begun a SOC 2 Type 2 program; no report has been issued yet. We are not currently certified for HIPAA or ISO 27001. If your business requires formal security documentation (DPA, sub-processor list, vendor security questionnaire), contact us at [email protected].
No system is 100% secure, and you use the Service at your own risk. Notify us immediately of any suspected unauthorized access.
5. Your Choices and Rights
- Messaging: reply STOP (or STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE, or OPT OUT) to stop automated messages and broadcasts from Sabi (Sabi still answers texts you send her); reply HELP or INFO for help.
- Marketing email: use the unsubscribe link in any message.
- Connections: revoke any connected account from your Sabi dashboard, or directly with the provider, at any time.
- Memory: view and delete Sabi's stored memories from your dashboard.
- Export: download your Sabi data any time from your account page, on any plan: memories, conversations, tasks, contacts, reminders, health data, connected-app names, and library text.
- Deletion: delete your account yourself on your account page or in the Sabi iPhone app, or ask us at [email protected]. See Data Retention below for what we remove and what we keep.
- Health data: see our Consumer Health Data Privacy Policy for your rights over health data.
- Cookies: manage via the choices in the Cookie Notice below.
California residents (CCPA/CPRA): You have the right to know, access, correct, and delete personal information we hold about you, the right to opt out of "sale" or "sharing" (we do not sell or share as defined), the right to limit use of sensitive personal information (we use it only to provide the Service), and the right not to be discriminated against for exercising your rights. Submit requests to [email protected] with "Privacy Request" in the subject. We will verify your identity before responding and respond within 45 days (or within the timeframe required by law, if shorter). You may use an authorized agent as permitted by law.
Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Texas, Utah, Virginia, and others) have similar rights and may use the same contact to exercise them, including the right to appeal a refusal.
UK and EU residents: New Sabi accounts are available in the United States and Canada. If you are an existing customer in the UK or EU, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent at any time. We process your data to provide the Service under our contract with you, for our legitimate interests in securing and improving Sabi, and with your consent for health data and non-essential cookies. Contact us at [email protected] to use these rights. You can also complain to your local data protection authority.
6. Data Retention
We retain personal information for as long as your Sabi account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Messages, memories, library files, tasks, health data, connection records, and the activity log are kept while your account is active, unless you delete them sooner.
When you delete your account, we immediately:
- delete your account, its data across our database, your library files (task photos are removed with the task), and your login;
- revoke the tokens for your connected apps and delete any stored keys;
- cancel your subscription and delete your customer record at Stripe (Stripe keeps invoices and payment records as required by law);
- delete your posts in the Sabi community (we remove your community account and comments on request);
- remove the text of your support tickets, including titles and summaries, along with your contact email and draft replies.
What we keep after deletion, and for how long:
- A copy of your data export, available to you by download link for 30 days.
- A deletion record: your name, email, and phone number for 90 days, then erased; the account ID, reason, and what was deleted are kept.
- Support ticket ids, status, and category, without your words or contact details.
- Billing records held by Stripe, and data in our providers' backups until they roll off on their standard schedules.
- Data our AI providers may retain for a limited period (typically up to 30 days) for safety and abuse monitoring.
If someone texts Sabi but never finishes signing up, we delete that unfinished sign-up after 90 days.
7. Children
Sabi is for adults 18 and older. We do not knowingly collect personal information from children under 18. If you believe a child has provided us information, contact us and we will delete it.
8. International Users
Sabi is offered to people in the United States and Canada; text-based sign-up and pairing need a US or Canada number. We operate from the United States and process data in the United States, where laws may differ from where you live. Existing customers in the UK and EU, see "UK and EU residents" above.
9. Changes to This Policy
We will post updates here with a new effective date. For material changes, we will notify you by email or text at least 14 days before they take effect. If you keep using Sabi after changes take effect, the updated policy applies.
10. Contact
Inovo Studios, LLC
6339 Charlotte Pike #738
Nashville, TN 37209 US
Support: https://meetsabi.com/support
Cookie Notice
Effective Date: October 13, 2026
We and our providers use cookies, pixels, and similar technologies on meetsabi.com and app.meetsabi.com. On our marketing website, nothing in the analytics, advertising, or functional categories loads until you make a choice. Video players are the exception: they load with the page regardless of your choice.
Types we use
- Strictly necessary (always on): sign-in and security cookies for the dashboard and checkout, and your cookie choice, which is saved in your browser.
- Analytics and performance (only if you accept): Google Analytics, loaded through Google Tag Manager, and DataFast.
- Advertising (only if you accept): Meta Pixel, Hyros, Instantly, Trybe, and ClickMagick, some loaded through Google Tag Manager and ad-attribution domains run by our marketing partner, AI For Companies. They share identifiers and page activity with ad platforms to measure our ads.
- Functional (only if you accept, or when you click to load): embedded forms (HighLevel/RainFlow).
- Video players (load regardless of your choice): Vimeo and Vidalytics players and the host of our background videos (assets.cdn.filesafe.space) load with the pages that contain them and may set their own cookies.
In the Sabi dashboard (app.meetsabi.com), we use DataFast product analytics and Sentry error monitoring to operate the Service. Sentry does not record sessions.
Your choices
- Use Cookie Preferences (in our website footer) to accept or decline each category. Withdrawing a category removes its cookies, such as Google Analytics, DataFast, Meta, and Hyros cookies.
- If your browser sends Global Privacy Control, advertising stays off and analytics is off unless you turn it on yourself.
- Adjust your browser settings to block or delete cookies.
- Opt out of interest-based advertising via industry tools such as aboutads.info/choices and optout.networkadvertising.org.
- You can also opt out of targeted advertising by emailing [email protected] with "Cookie Opt-Out" in the subject.