Legal

Privacy Policy

Last updated: August 15, 2026

1. Information We Collect

SiftMail collects only the information necessary to provide email triage services:

  • Account data: Your email address and OAuth provider (Google or Microsoft).
  • Email content: Sender, subject, headers, and message body. SiftMail processes email content for four purposes: (a) security scoring (phishing, malware, and promotional classification); (b) the Sift Inbox Index, which builds a searchable, structured index of your inbox (e.g., receipts, travel, subscriptions) so you can find buried information by natural language search; (c) the Exposure Index, an automated sensitivity scan described in Section 3 that runs on every incoming message; and (d) the optional Rediscover deep scan (also offered as the one-time Decade Audit), described in Section 8. Email content is processed by automated systems to provide these features. SiftMail does not allow humans to read your email content except in the narrow, disclosed circumstances described in Section 7 (Google API Limited Use Disclosure).
  • Exposure findings: When the sensitivity scan described in Section 3 flags something, SiftMail stores the finding — its type, category, severity, the sender, subject and date of the message it came from, and a masked excerpt of the surrounding text with the sensitive value itself redacted. Where the sensitive information belongs to someone other than you (for example a colleague named in a forwarded document), the finding may record that person's name so you can see whose data you are holding.
  • Contact details: Names, email addresses, phone numbers, and company names appearing in your mail are extracted into a per-user contact directory shown in your SiftMail dashboard.
  • OAuth tokens: Access and refresh tokens are encrypted at rest using AES-256-GCM and used only to access your mailbox on your behalf.
  • Usage data: Actions taken (quarantine, release, feedback), settings, and plan information.

2. How We Use Your Information

  • Score incoming emails for phishing, malware, and promotional content, and surface the results in your dashboard.
  • Build and maintain your Sift Inbox Index — a per-user, searchable, structured index of your inbox (receipts, travel, subscriptions, financial, shipping, events, photos, documents, accounts, dining) so you can find buried information using natural language search.
  • Apply a single security label, Sift/Quarantine, in your Gmail when a message is flagged. This is the only label SiftMail writes to your mailbox. Your Sift Inbox Index collections (receipts, travel, and the rest) live inside the SiftMail dashboard — they are not Gmail labels and nothing is written to your mailbox for them. SiftMail archives a message only when you explicitly choose to archive it.
  • Authenticate your account and operate features you have enabled in your settings.

3. Exposure Index (Sensitivity Scan)

SiftMail runs an automated sensitivity scan over every message it processes — not only the optional deep scan in Section 8, and not only on paid plans. Its purpose is to show you sensitive information sitting forgotten in your own mailbox. This section describes it in full because it is the most personal thing SiftMail does.

What it looks for. Government identifiers and identity data; credentials such as passwords, API keys and password-reset links; financial documents such as tax filings, bank and brokerage statements, salary and equity details; medical and health records; legal and employment-related correspondence; children's personal, school and medical records; and confidential work material such as forwarded internal documents, NDAs and third-party personal data you are holding on someone else's behalf.

What it does not do. The scan detects sensitive material that is actually present in a message. It does not profile you, and it does not attempt to infer characteristics you have not written down — SiftMail does not try to determine your health status, pregnancy, sexual orientation, or whether you are looking for a job.

What is stored. For each finding: the type and category, a severity, the sender, subject and date of the message, any attachment filename involved, and a masked excerpt of the text surrounding the finding — the sensitive value itself is redacted before storage (for example "…SSN ***-**-1234 on file…"). Where the sensitive data belongs to someone other than you, the finding may record that person's name so you can see whose information you are holding.

Who can see it, and how long it lives. Detection is fully automated; findings are stored per-user and are visible only to you, subject to the same human-access restrictions as all other email content (Section 7). Part of the scan uses automated pattern matching only; the remainder uses the AI classification described in Section 6. Exposure findings and the contact directory are deleted along with your other data when you disconnect and do not reconnect, when you delete your account, or immediately on request (Section 9).

4. User Control Over Actions

SiftMail applies one security label — Sift/Quarantine — to your Gmail automatically as part of its core functionality. That label is the only thing SiftMail writes to your mailbox, and it is non-destructive in the strictest sense: quarantining adds a label and nothing else. The message is not moved, not archived, not deleted, and stays in your inbox exactly where it was. You can remove the label at any time from Gmail or from your SiftMail dashboard. Actions that do move mail — archiving a message, releasing a quarantined message, or modifying allow/block rules — occur only when you explicitly initiate them, one message at a time. You can disconnect SiftMail at any time from your dashboard or from your Google Account permissions page.

5. Data Storage & Security

  • All data is stored in encrypted PostgreSQL databases.
  • OAuth tokens are encrypted at rest with AES-256-GCM.
  • All API traffic is encrypted in transit via TLS.
  • PII is redacted from application logs.
  • We use rate limiting and API key authentication to protect endpoints.

6. Third-Party Services

  • Google OAuth and Gmail API — to authenticate you and access your Gmail mailbox.
  • Microsoft Identity Platform and Microsoft Graph API — to authenticate Outlook users and access their mailbox.
  • Anthropic API — to perform AI classification of email content for security scoring, inbox indexing and the sensitivity scan in Section 3. For security scoring we send headers and the short Gmail preview snippet, and only for messages our own scoring cannot resolve confidently. For inbox indexing and the sensitivity scan we send up to the first 4,000 characters of the message body, once per message. The Rediscover deep scan in Section 8 sends no message content to Anthropic at all. Email content sent to Anthropic is processed under Anthropic's API terms, is used solely to return classification results, and is not used to train AI models.
  • Stripe — for subscription billing and payment processing. SiftMail does not receive or store your full payment card details.
  • Resend — for transactional email delivery (verification, account notifications) and for your daily digest. The digest is an email we send to you, and it contains the senders and subject lines of the messages it summarises.
  • Slack — only if you choose to connect it. When you supply your own Slack incoming-webhook URL, SiftMail posts flagged-message alerts to that webhook containing the sender, subject line and risk score. No data is sent to Slack unless you configure this yourself, and you can remove the webhook at any time.
  • Railway — for application hosting and encrypted database infrastructure.

Each provider is governed by its own privacy policy.

7. Google API Limited Use Disclosure

SiftMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We request the gmail.modify scope because SiftMail's core functions require both reading message content (for security classification and inbox indexing) and modifying labels (for quarantine, organization, and user-initiated archiving). A read-only scope cannot apply labels; a metadata-only scope cannot power the Sift Inbox Index.
  • We do not use Google user data for serving advertisements.
  • We do not allow humans at SiftMail to read your email content except in narrow circumstances expressly permitted by the Google API Services User Data Policy: (a) with your explicit written consent to investigate a specific issue you have reported, (b) to comply with applicable law, or (c) to investigate suspected abuse or security incidents.
  • We do not transfer Google user data to third parties except as necessary to provide the service or as required by law.
  • All Google user data access is limited to the practices explicitly disclosed in this privacy policy.

8. Rediscover Deep Scan (Decade Audit)

SiftMail offers an optional deep scan — surfaced as Rediscover and sold as the one-time Decade Audit — that searches your mailbox as far back as 25 years (bounded by your account history) to surface old media, receipts, and forgotten sensitive documents you may not remember are still in your inbox.

  • What we store (locate, not custody): For each matched message the deep scan persists metadata only — sender, subject, date, category, attachment metadata (filename, type, and count), whether it was classified sensitive, and a message locator (the Gmail message ID) so you can jump back to the original. SiftMail does not copy or store the full message body or the contents of your attachments from the deep scan.
  • Sensitivity classification: The deep scan flags forgotten sensitive documents and records the sensitivity class it detected — including financial (e.g., tax returns, bank/brokerage statements, pay stubs), identity (e.g., passports, driver's licenses, government IDs, Social Security numbers), and medical (e.g., lab results, prescriptions, insurance cards), as well as legal and location-related documents. Detection is fully automated (filename, subject, and metadata patterns); no human at SiftMail reviews your documents.
  • Access & retention: Deep-scan findings are stored per-user, are visible only to you, and are subject to the same Limited Use and human-access restrictions described in Section 7. They are deleted when you disconnect and do not reconnect (within 30 days, per Section 9), when you delete your account, or immediately on request to privacy@siftmail.app.

9. Data Retention & Deletion

You can disconnect your account at any time, which immediately revokes our access to your mailbox and stops further processing of your email. When you disconnect and do not reconnect, your cached email data, Sift Inbox Index, Rediscover deep-scan findings, and scoring history are deleted within 30 days. You may also request immediate, complete data deletion at any time by emailing privacy@siftmail.app.

10. Your Rights

You have the right to access, correct, or delete your personal data. You can disconnect your email provider at any time through the dashboard. For data export or deletion requests, contact us at privacy@siftmail.app.

11. Contact

For privacy-related questions or requests, email us at privacy@siftmail.app.