Legal
Privacy Policy
Last updated: August 15, 2026
1. Information We Collect
SiftMail collects only the information necessary to provide email triage services:
- Account data: Your email address and OAuth provider (Google or Microsoft).
- Email content: Sender, subject, headers, and message body. SiftMail processes email content for four purposes: (a) security scoring (phishing, malware, and promotional classification); (b) the Sift Inbox Index, which builds a searchable, structured index of your inbox (e.g., receipts, travel, subscriptions) so you can find buried information by natural language search; (c) the Exposure Index, an automated sensitivity scan described in Section 3 that runs on every incoming message; and (d) the optional Rediscover deep scan (also offered as the one-time Decade Audit), described in Section 8. Email content is processed by automated systems to provide these features. SiftMail does not allow humans to read your email content except in the narrow, disclosed circumstances described in Section 7 (Google API Limited Use Disclosure).
- Index entries: The Sift Inbox Index does not only read your mail, it stores what it extracts. For a message it recognises — a receipt, an order, a booking, a subscription charge — SiftMail keeps the sender and sender name, the subject, the date, a Gmail snippet, a short title, the category it assigned, and the structured details it read out of the message: the amount, currency, subtotal, tax and shipping, the merchant and a normalised merchant name, the purchase date, any location named, and whether the message had attachments and their file types. This is how search for "what did I spend at that hardware store in March" works at all. SiftMail records the totals of a purchase and never what you bought — no product names, quantities or per-item prices are requested from the classifier or kept in your index. SiftMail does not store the message body itself; it stores these extracted fields and the Gmail message ID so you can open the original.
- Exposure findings: When the sensitivity scan described in Section 3 flags something, SiftMail stores the finding — its type, category, severity, the sender, subject and date of the message it came from, and a masked excerpt of the surrounding text with the sensitive value itself redacted. Where the sensitive information belongs to someone other than you (for example a colleague named in a forwarded document), the finding may record that person's name so you can see whose data you are holding.
- Contact details: Names, email addresses, phone numbers, and company names appearing in your mail are extracted into a per-user contact directory shown in your SiftMail dashboard.
- OAuth tokens: Access and refresh tokens are encrypted at rest using AES-256-GCM and used only to access your mailbox on your behalf.
- Usage data: Actions taken (quarantine, release, feedback), which screens of the dashboard you open, settings, and plan information. Screen names only — never the mail shown on them.
2. How We Use Your Information
- Score incoming emails for phishing, malware, and promotional content, and surface the results in your dashboard.
- Build and maintain your Sift Inbox Index — a per-user, searchable, structured index of your inbox (receipts, travel, subscriptions, financial, shipping, events, photos, documents, accounts, dining) so you can find buried information using natural language search.
- Apply a single security label, Sift/Quarantine, in your Gmail when a message is flagged. This is the only label SiftMail writes to your mailbox. Your Sift Inbox Index collections (receipts, travel, and the rest) live inside the SiftMail dashboard — they are not Gmail labels and nothing is written to your mailbox for them. Archiving is a separate thing you start yourself — never something SiftMail does to new mail as it arrives. Section 4 says exactly when it happens, what it shows you before it writes anything, and how to undo it.
- Authenticate your account and operate features you have enabled in your settings.
3. Exposure Index (Sensitivity Scan)
SiftMail runs an automated sensitivity scan over every message it processes — not only the optional deep scan in Section 8, and not only on paid plans. Its purpose is to show you sensitive information sitting forgotten in your own mailbox. This section describes it in full because it is the most personal thing SiftMail does.
What it looks for. Government identifiers and identity data; credentials such as passwords, API keys and password-reset links; financial documents such as tax filings, bank and brokerage statements, salary and equity details; medical and health records; legal and employment-related correspondence; children's personal, school and medical records; and confidential work material such as forwarded internal documents, NDAs and third-party personal data you are holding on someone else's behalf.
What it does not do. The scan detects sensitive material that is actually present in a message. It does not profile you, and it does not attempt to infer characteristics you have not written down — SiftMail does not try to determine your health status, pregnancy, sexual orientation, or whether you are looking for a job.
What is stored. For each finding: the type and category, a severity, the sender, subject and date of the message, any attachment filename involved, and a masked excerpt of the text surrounding the finding — the sensitive value itself is redacted before storage (for example "…SSN ***-**-1234 on file…"). Where the sensitive data belongs to someone other than you, the finding may record that person's name so you can see whose information you are holding.
Who can see it, and how long it lives. Detection is fully automated; findings are stored per-user and are visible only to you, subject to the same human-access restrictions as all other email content (Section 7). Part of the scan uses automated pattern matching only; the remainder uses the AI classification described in Section 6. Exposure findings and the contact directory are deleted along with your other data when you disconnect and do not reconnect, when you delete your account, or immediately on request (Section 9).
4. User Control Over Actions
Quarantine. SiftMail applies one security label — Sift/Quarantine — to your Gmail automatically as part of its core functionality. That is the only label SiftMail writes to your mailbox, and it is non-destructive in the strictest sense: quarantining adds a label and nothing else. The message is not moved, not archived, not deleted, and stays in your inbox exactly where it was. You can remove the label at any time from Gmail or from your SiftMail dashboard.
Archiving. SiftMail never archives mail on its own as it arrives. Archiving happens in a cleanup you start, and before anything is written you are shown the exact count and have to confirm it — "Archive 13,400 messages?", with that figure counted from your own mailbox. It runs in bulk, not one message at a time, which is precisely why the number is put in front of you first. Archived mail stays in Gmail under All Mail and search still finds it, and the entire run can be reversed from the Cleanup tab. Archiving frees no Google storage.
Recurring maintenance is a separate, opt-in setting, off by default. It stays off until you enable it and take it out of its preview mode, in which it reports what it would do and changes nothing. Once you have done both, it archives promotional, bulk and no-reply mail on a schedule without asking again each time — that is what turning it on means. Those three categories are the only ones it can archive.
Trash. One screen can move mail to Trash: the storage screen, whose whole purpose is to free Google storage, which archiving does not do. It is never automatic, never triggered by a classification, and never part of a cleanup or a maintenance run — you pick the messages yourself and confirm each batch, capped at 200 at a time. At the moment you confirm, SiftMail re-reads every one of those messages from Gmail and refuses any draft or anything you have starred, even if it looked selectable when the page loaded. Mail moved to Trash stays in Gmail's Trash for 30 days, where "Move to inbox" puts it back; that is why this is the one action SiftMail does not record its own undo for.
Releasing a quarantined message, or changing your allow and block rules, happens only when you ask for it. You can disconnect SiftMail at any time from your dashboard or from your Google Account permissions page.
5. Data Storage & Security
- All data is stored in encrypted PostgreSQL databases.
- OAuth tokens are encrypted at rest with AES-256-GCM.
- All API traffic is encrypted in transit via TLS.
- PII is redacted from application logs.
- We use rate limiting and API key authentication to protect endpoints.
6. Third-Party Services
- Google OAuth and Gmail API — to authenticate you and access your Gmail mailbox.
- Microsoft Identity Platform and Microsoft Graph API — to authenticate Outlook users and access their mailbox.
- Anthropic API — to perform AI classification of email content for security scoring, inbox indexing and the sensitivity scan in Section 3. For security scoring we send headers and the short Gmail preview snippet, and only for messages our own scoring cannot resolve confidently. For inbox indexing and the sensitivity scan we send up to the first 4,000 characters of the message body, once per message. The Rediscover deep scan in Section 8 sends no message content to Anthropic at all. Email content sent to Anthropic is processed under Anthropic's API terms, is used solely to return classification results, and is not used to train AI models.
- Stripe — for subscription billing and payment processing. SiftMail does not receive or store your full payment card details.
- Resend — for transactional email delivery (verification, account notifications) and for your daily digest. The digest is an email we send to you, and it contains the senders and subject lines of the messages it summarises.
- Slack — only if you choose to connect it. When you supply your own Slack incoming-webhook URL, SiftMail posts flagged-message alerts to that webhook containing the sender, subject line and risk score. No data is sent to Slack unless you configure this yourself, and you can remove the webhook at any time.
- Railway — for application hosting and encrypted database infrastructure.
Each provider is governed by its own privacy policy.
7. Google API Limited Use Disclosure
SiftMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We request the
gmail.modifyscope because SiftMail's core functions require both reading message content (for security classification and inbox indexing) and writing labels. Quarantine adds theSift/Quarantinelabel and leaves the message where it is. Archiving is a separate action that happens only when you choose it: it removes theINBOXlabel and nothing else, it runs in bulk once you confirm an exact count — section 4 describes it — and the whole run is reversible. The same scope powers Trash, which you explicitly confirm, which is capped at 200 messages per call, and which sends mail to Gmail's own Trash. A read-only scope cannot write labels; a metadata-only scope cannot power the Sift Inbox Index. - We do not use Google user data for serving advertisements.
- We do not allow humans at SiftMail to read your email content except in narrow circumstances expressly permitted by the Google API Services User Data Policy: (a) with your explicit written consent to investigate a specific issue you have reported, (b) to comply with applicable law, or (c) to investigate suspected abuse or security incidents.
- We do not transfer Google user data to third parties except as necessary to provide the service or as required by law.
- All Google user data access is limited to the practices explicitly disclosed in this privacy policy.
8. Rediscover Deep Scan (Decade Audit)
SiftMail offers an optional deep scan — surfaced as Rediscover and sold as the one-time Decade Audit — that searches your mailbox as far back as 25 years (bounded by your account history) to surface old media, receipts, and forgotten sensitive documents you may not remember are still in your inbox.
- What we store (locate, not custody): For each matched message the deep scan persists metadata only — sender, subject, date, category, attachment metadata (filename, type, and count), whether it was classified sensitive, and a message locator (the Gmail message ID) so you can jump back to the original. SiftMail does not copy or store the full message body or the contents of your attachments from the deep scan.
- Sensitivity classification: The deep scan flags forgotten sensitive documents and records the sensitivity class it detected — including financial (e.g., tax returns, bank/brokerage statements, pay stubs), identity (e.g., passports, driver's licenses, government IDs, Social Security numbers), and medical (e.g., lab results, prescriptions, insurance cards), as well as legal and location-related documents. Detection is fully automated (filename, subject, and metadata patterns); no human at SiftMail reviews your documents.
- Access & retention: Deep-scan findings are stored per-user, are visible only to you, and are subject to the same Limited Use and human-access restrictions described in Section 7. They are deleted when you disconnect and do not reconnect (within 30 days, per Section 9), when you delete your account, or immediately on request to privacy@siftmail.app.
9. Data Retention & Deletion
You can disconnect your account at any time, which immediately revokes our access to your mailbox and stops further processing of your email. When you disconnect and do not reconnect, your cached email data, Sift Inbox Index, Rediscover deep-scan findings, and scoring history are deleted within 30 days. You may also request immediate, complete data deletion at any time by emailing privacy@siftmail.app.
10. Your Rights
You have the right to access, correct, or delete your personal data. You can disconnect your email provider at any time through the dashboard. For data export or deletion requests, contact us at privacy@siftmail.app.
11. Contact
For privacy-related questions or requests, email us at privacy@siftmail.app.