Your data, explained plainly.
Last updated: 17 September 2026 · Effective: 17 September 2026
Sift is a personal productivity app. When you use it, you trust us with your thoughts, tasks, and finances. This policy explains exactly what we collect, why we collect it, and the rights you have over your information. We've written it in plain English on purpose — no lawyer jargon, no hiding behind small print.
1. Who we are
Sift is operated by an individual trading as Sift, based in the United Kingdom. When this policy says "Sift", "we", "us" or "our", it means that individual.
We are the data controller for the personal information you give us. That means we decide how and why your data is used, and we're responsible for keeping it safe.
You can reach us any time at privacy@heysift.app.
2. What information we collect
Account information
When you sign up, we collect your email address. If you sign in with Google, we also receive a unique ID from Google that links your Google account to your Sift account. We never see your Google password.
Device information
We assign your device a device ID so we know which devices are linked to your account. If you allow notifications, we also collect a push notification token from Firebase (Google's notification service). This is just a technical code — it doesn't contain personal information on its own.
Content you create
This is the heart of Sift — the things you "dump" into the app:
- Text entries — your notes, tasks, financial logs, and any other thoughts you type in.
- Voice recordings — when you use the microphone button, your audio is sent to our servers, transcribed into text via an AI transcription service (OpenRouter), and the original audio file is deleted. We do not keep voice recordings long-term.
- Photos and images — if you photograph a receipt or any other image, that image is uploaded and processed so we can extract useful information from it.
- URLs — if you paste a link, we fetch information from that page to create a useful summary.
Metadata
Each entry is automatically timestamped and tagged with your timezone. This is so your timeline appears in your local time, not server time.
Usage information
We track your daily usage quota (e.g. how many AI-powered entries you've used today) and your subscription tier. We do not use third-party analytics tools, so we don't track which screens you visit or how long you spend in the app.
All tiers use cloud storage
All Sift accounts — including the free tier — store your entries on our cloud servers. This is what allows your data to be safe, synced, and accessible. The difference between tiers is the number of AI-processed entries you get, not where your data lives.
3. How we use your information
To provide the service
We process your content to categorise it (task, expense, note), extract useful data (amounts, dates, labels), and sync it across your devices if you're on a paid plan.
To authenticate you
We use your email address to send a one-time sign-in code. We never send marketing emails unless you've explicitly opted in.
To send you notifications
If you turn on notifications, we use your push token to send task reminders and your weekly summary. You can turn notifications off in your phone's settings at any time.
To generate your weekly summary
For Cloud Brain subscribers, an AI reads your week's entries on Sunday evening and produces a summary of your productivity, spending, and patterns. This is done automatically and the AI is not shown your data for training purposes (see below).
To enforce fair usage
We track how many AI operations you've used to apply the daily quotas on the free plan and to manage subscription limits. All tiers store data on our servers.
We never sell your data. We never use your personal entries for advertising. We never share your content with third parties for their own purposes — only with sub-processors we use to run the service (listed in section 5 below).
4. Our legal reason for processing your data
Under UK and EU law, we must have a lawful reason to use your personal data. Here's ours:
- Contract performance — processing your entries, syncing across devices, and sending your weekly summary are all things we do to fulfil the service you signed up for.
- Legitimate interests — keeping usage counters so free and paid tiers work correctly; detecting fraud or misuse of the service.
- Legal obligation — maintaining billing records as required by UK tax law.
5. Companies we share data with
We use a small number of third-party services to run Sift. These companies only receive data that is necessary for the specific service they provide:
If you use the BYOK (Bring Your Own Key) plan, your AI-related content is sent directly to the AI provider whose API key you supply. You become responsible for that provider's data terms. We do not see or store your API key on our servers.
6. How we protect your data
All your entries stored on our servers are encrypted at rest using AES-256-GCM — a military-grade encryption standard. Each user's data is encrypted with a unique key derived from a master secret, meaning a breach of one user's data does not compromise anyone else's.
All data transferred between the app and our servers is encrypted in transit using TLS (HTTPS). We never transmit your data over an unencrypted connection.
7. How long we keep your data
- Your entries and content — kept for as long as you have an account. If you delete an entry, it is removed from our servers within 30 days.
- Voice recordings — deleted immediately after transcription. We never store your raw audio.
- Your account — if you delete your account, all your data is permanently erased from our systems within 30 days. We keep minimal billing records (not your content) for 7 years as required by UK law.
- Auth codes — one-time sign-in codes expire within minutes and are permanently deleted after use.
8. Your rights
Under UK GDPR and EU GDPR, you have the following rights. You don't need a lawyer to use them — just email us.
You can ask us what data we hold about you and get a copy of it.
If something we hold about you is wrong, you can ask us to correct it.
You can delete your account directly from the app, or ask us to erase your data. We'll comply within 30 days.
You can ask for an export of your data in a machine-readable format so you can take it to another service.
You can object to us processing your data in certain circumstances. If you do this, we'll stop unless we have a compelling legal reason to continue.
If you think we're mishandling your data and we haven't resolved your concern, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
For California residents (CCPA)
California law gives you additional rights: to know what personal information we collect, to delete it, and to opt out of the sale of your personal information. We do not sell personal information. To exercise any right, email us at privacy@heysift.app.
9. Children
Sift is intended for people aged 16 and over. We do not knowingly collect data from anyone under 16. If you think a child has signed up, please contact us at privacy@heysift.app and we will delete the account immediately.
10. International data transfers
Some of our sub-processors (Google, AWS, OpenRouter, Mailgun) may process data outside the UK or EU. When they do, we ensure they have signed appropriate data protection agreements — either Standard Contractual Clauses approved by the UK ICO or an equivalent legal mechanism. This means your data is protected to the same standard wherever it is processed.
11. Changes to this policy
If we make a significant change to how we handle your data, we'll notify you by email before the change takes effect. Minor changes (like fixing typos or clarifying wording) will be made without notice. The "last updated" date at the top of this page always shows when it was last changed.
12. Contact us
For any privacy question, data request, or complaint:
Email: privacy@heysift.app
Operating name: Sift
Country: United Kingdom
Supervisory authority: Information Commissioner's Office (ICO)