Legal

Privacy Policy

We keep this short and honest. Here is exactly what Sift collects, why, and what control you have over it.

Last updated: April 14, 2026

What we collect

We collect only the information needed to make Sift work well for you. This falls into three buckets: account data you give us, learning activity we record as you study, and technical data your device sends automatically.

  • Account data: name, email, password hash, and optional profile details.
  • Learning activity: tracks you follow, answers you submit, flashcard ratings, and streaks.
  • Technical data: device type, browser, IP address, and error logs used to keep the service reliable.

How we use your data

Your learning activity powers the features you come to Sift for — spaced repetition schedules, progress tracking, and personalized review. We also use aggregated, de-identified activity to improve the product over time.

We do not sell your personal data. We do not use your content to train third-party models without your explicit consent.

Who we share it with

We share data only with the service providers we need to run Sift — hosting, email delivery, payment processing, and error monitoring. Each one is bound by a contract that limits their use to providing the service.

We may disclose data if legally required, or to protect the rights, property, or safety of Sift and its users.

Your rights

You can access, export, correct, or delete your data at any time from your account settings. If you delete your account, we remove your personal data within 30 days, except where law requires us to retain it.

  • Access and download a copy of your data.
  • Correct inaccurate information.
  • Delete your account and associated data.
  • Opt out of non-essential communications.

Security

Data in transit is encrypted with TLS. Data at rest is encrypted and access-controlled. We review our security practices regularly — but no service can promise perfect security, so we commit to notifying you promptly if we detect a breach affecting your data.

Children

Sift is not directed at children under 13. If you believe a child under 13 has provided us with personal data, contact us and we will delete it.

Changes to this policy

When we update this policy in ways that materially affect you, we will notify you by email or in-app before the changes take effect. Older versions remain available on request.

Questions?

If anything here isn't clear, reach out and we'll walk you through it.

hello@sift.st