Privacy Policy

Your data, explained plainly.

Last updated: 17 September 2026  ·  Effective: 17 September 2026

Sift is a personal productivity app. When you use it, you trust us with your thoughts, tasks, and finances. This policy explains exactly what we collect, why we collect it, and the rights you have over your information. We've written it in plain English on purpose — no lawyer jargon, no hiding behind small print.

1. Who we are

Sift is operated by an individual trading as Sift, based in the United Kingdom. When this policy says "Sift", "we", "us" or "our", it means that individual.

We are the data controller for the personal information you give us. That means we decide how and why your data is used, and we're responsible for keeping it safe.

You can reach us any time at privacy@heysift.app.

2. What information we collect

Account information

When you sign up, we collect your email address. If you sign in with Google, we also receive a unique ID from Google that links your Google account to your Sift account. We never see your Google password.

Device information

We assign your device a device ID so we know which devices are linked to your account. If you allow notifications, we also collect a push notification token from Firebase (Google's notification service). This is just a technical code — it doesn't contain personal information on its own.

Content you create

This is the heart of Sift — the things you "dump" into the app:

Metadata

Each entry is automatically timestamped and tagged with your timezone. This is so your timeline appears in your local time, not server time.

Usage information

We track your daily usage quota (e.g. how many AI-powered entries you've used today) and your subscription tier. We do not use third-party analytics tools, so we don't track which screens you visit or how long you spend in the app.

All tiers use cloud storage

All Sift accounts — including the free tier — store your entries on our cloud servers. This is what allows your data to be safe, synced, and accessible. The difference between tiers is the number of AI-processed entries you get, not where your data lives.

3. How we use your information

To provide the service

We process your content to categorise it (task, expense, note), extract useful data (amounts, dates, labels), and sync it across your devices if you're on a paid plan.

To authenticate you

We use your email address to send a one-time sign-in code. We never send marketing emails unless you've explicitly opted in.

To send you notifications

If you turn on notifications, we use your push token to send task reminders and your weekly summary. You can turn notifications off in your phone's settings at any time.

To generate your weekly summary

For Cloud Brain subscribers, an AI reads your week's entries on Sunday evening and produces a summary of your productivity, spending, and patterns. This is done automatically and the AI is not shown your data for training purposes (see below).

To enforce fair usage

We track how many AI operations you've used to apply the daily quotas on the free plan and to manage subscription limits. All tiers store data on our servers.

We never sell your data. We never use your personal entries for advertising. We never share your content with third parties for their own purposes — only with sub-processors we use to run the service (listed in section 5 below).

4. Our legal reason for processing your data

Under UK and EU law, we must have a lawful reason to use your personal data. Here's ours:

5. Companies we share data with

We use a small number of third-party services to run Sift. These companies only receive data that is necessary for the specific service they provide:

Google Firebase (push notifications) and Google Sign-In (optional). Google processes data under its own privacy policy and Data Processing Agreements compliant with UK/EU law.
OpenRouter Routes your content to large language models (LLMs) for classification, summarisation, and voice transcription. OpenRouter acts as an intermediary and may use various underlying model providers depending on the task. Your content is processed under their data agreements and is not used to train models.
Mailgun Delivers your sign-in code email. Mailgun receives your email address for this purpose only. Mailgun is GDPR-compliant.
Amazon Web Services Stores photos and media you upload (AWS S3). Your files are stored encrypted. AWS is GDPR-compliant and we use European data regions.

If you use the BYOK (Bring Your Own Key) plan, your AI-related content is sent directly to the AI provider whose API key you supply. You become responsible for that provider's data terms. We do not see or store your API key on our servers.

6. How we protect your data

All your entries stored on our servers are encrypted at rest using AES-256-GCM — a military-grade encryption standard. Each user's data is encrypted with a unique key derived from a master secret, meaning a breach of one user's data does not compromise anyone else's.

All data transferred between the app and our servers is encrypted in transit using TLS (HTTPS). We never transmit your data over an unencrypted connection.

7. How long we keep your data

8. Your rights

Under UK GDPR and EU GDPR, you have the following rights. You don't need a lawyer to use them — just email us.

Right to access

You can ask us what data we hold about you and get a copy of it.

Right to correction

If something we hold about you is wrong, you can ask us to correct it.

Right to erasure ("right to be forgotten")

You can delete your account directly from the app, or ask us to erase your data. We'll comply within 30 days.

Right to portability

You can ask for an export of your data in a machine-readable format so you can take it to another service.

Right to object

You can object to us processing your data in certain circumstances. If you do this, we'll stop unless we have a compelling legal reason to continue.

Right to complain

If you think we're mishandling your data and we haven't resolved your concern, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

For California residents (CCPA)

California law gives you additional rights: to know what personal information we collect, to delete it, and to opt out of the sale of your personal information. We do not sell personal information. To exercise any right, email us at privacy@heysift.app.

9. Children

Sift is intended for people aged 16 and over. We do not knowingly collect data from anyone under 16. If you think a child has signed up, please contact us at privacy@heysift.app and we will delete the account immediately.

10. International data transfers

Some of our sub-processors (Google, AWS, OpenRouter, Mailgun) may process data outside the UK or EU. When they do, we ensure they have signed appropriate data protection agreements — either Standard Contractual Clauses approved by the UK ICO or an equivalent legal mechanism. This means your data is protected to the same standard wherever it is processed.

11. Changes to this policy

If we make a significant change to how we handle your data, we'll notify you by email before the change takes effect. Minor changes (like fixing typos or clarifying wording) will be made without notice. The "last updated" date at the top of this page always shows when it was last changed.

12. Contact us

For any privacy question, data request, or complaint:

Email: privacy@heysift.app
Operating name: Sift
Country: United Kingdom
Supervisory authority: Information Commissioner's Office (ICO)