Privacy
Sift V1.2 · read-only inbox judgment
What Sift reads
Sift requests read-only Gmail access (gmail.readonly) and syncs threads from the last 7 days (up to 300 threads). Spam and Trash are never read. Sift cannot send, reply, delete, or move anything in your mailbox — the Keep / Review / Suggest archive actions only change Sift's own state.
What is stored
- Your Google account id, name, email, and an encrypted refresh token (AES-256-GCM at rest).
- Thread metadata: subject, sender, recipient, date, snippet.
- A truncated plain-text excerpt of each synced message, kept for 7 days and then purged automatically.
- The judgment model's raw answers and your Keep / Review / Suggest-archive overrides.
- Your plan (Free / Pro).
Who processes the email body
Email bodies are sent to TypeSafe (the judgment engine, model jev-latest) to produce the 8 signals Sift shows you. Bodies are not used to write email, and Sift has no reply or chat features.
Your controls
- Delete all synced email data at any time (Settings → Your data).
- Revoke Google access (Settings, or Google Account → Security → Third-party access). Syncing stops immediately.
- Delete your account, which removes every stored row.
What we don't do
- No selling of email data, no ads, no model training on your mail beyond producing your own judgments.
- No writing back to Gmail. Ever.