Sift Labs LLC · Last updated: September 26, 2026
This policy explains what Sift Labs LLC ("Sift," "we," "us") collects when you use the Sift app and sifthealth.app, how we use it, and the choices you have. Sift Labs LLC is the data controller for this information.
We collect what we need to run Sift: your account, your scans and lists, the focus areas you pick, and how you use the app so we can improve it. We don't sell your personal data, and we never share it with the brands whose products you scan. You can export or delete everything.
Account information. Your email address and name (if provided) via Sign in with Apple or email signup. If you use Sign in with Apple and choose Hide My Email, we receive a private relay address from Apple rather than your real email. Messages we send to that address are forwarded to you by Apple. We use this address for account and service communications and, unless you opt out, occasional updates about new features and Sift’s work (see section 3). You can unsubscribe from those at any time using the link in any email.
Activity in the app. Products you scan, search, save, or list; photos you submit of products; corrections or additions you make to product information; and the health focus areas you select. This is the core of your Sift experience. It powers your history, your lists, and focus-area prioritization.
Subscription status. Whether you have an active Sift+ subscription, trial, or renewal, via our subscription-management provider (RevenueCat). Payments are processed entirely by Apple or Google. We never see or store your card details.
Device and usage data. Device type, OS version, app version, language, crash logs, and analytics events (screens viewed, features used) via PostHog. Our analytics provider derives an approximate location (city and country) from your IP address. We never collect GPS or precise location. Where required by law, analytics beyond what’s strictly necessary runs only with your consent.
Push notification tokens. If you allow notifications, we store a device token so we can send them, for example to tell you a Sift Score you requested has finished calculating. You can turn notifications off at any time in your device settings.
Install attribution. If you install Sift through a creator’s link, our deep-linking provider (ChottuLink) attributes the install so the creator can be credited. This uses device-level signals, not your identity.
What we don’t collect. We don’t collect your precise location, your contacts, or health records. We don’t access your photo library. Photos you take of products inside the app are uploaded so we can identify the product and analyze its ingredients and labels. Camera frames used for barcode scanning are processed to read the code and are not stored. Sift is not connected to HealthKit or Google Fit.
Your selected focus areas (like gut health, hormone balance, or pregnancy and development) are preferences about topics you care about. Selecting a focus area doesn’t tell us anything about your health status, only which topics you want us to flag. But because they’re health-related, some laws (including the EU and UK GDPR, and several US state laws) may treat them as sensitive data. We treat them accordingly: they’re used only to highlight and prioritize relevant ingredient concerns on product pages, they’re never shared with third parties for their own use, and they’re never used for advertising. Where the law requires it, we collect them only with your explicit consent, which you can withdraw at any time in Settings. You can use Sift without selecting any focus area.
We do not sell your personal data, use it for third-party advertising, or share your identity or activity with product brands. Sift’s scores can’t be bought, and neither can your data.
Only service providers acting on our instructions under contract:
We may also disclose information if required by law, to protect rights and safety, or as part of a merger or acquisition (in which case this policy continues to apply to your data and we’ll notify you of any change in controller).
Creators whose links drive installs see aggregate counts and commission amounts, never your identity.
The Sift app does not use cookies. Our website, sifthealth.app, uses a small number of them:
The website uses strictly necessary cookies that keep the site working, such as security and load balancing, and Google Analytics (Google LLC) to understand how visitors use the site in aggregate. Analytics cookies are not used for advertising. In the UK, the EEA, and other places where consent is required, analytics cookies are off by default and only run if you opt in.
Most browsers let you block or delete cookies directly. We do not use advertising or cross-site tracking cookies, and we do not allow third parties to use our site for their own advertising purposes.
Global Privacy Control. Where required by law, including under California law, we honor Global Privacy Control (GPC) signals sent by your browser as a valid request to opt out of any sale or sharing of personal information. Because we do not sell or share personal information, this does not change how we treat your data, but the signal is respected. There is no finalized standard for older “Do Not Track” signals, so we do not respond to those.
We keep your data while your account is active. If you delete your account, personal data is deleted or irreversibly anonymized within 30 days, including copies held in encrypted backups, except records we must keep for legal or accounting reasons (kept no longer than required).
Products you submit, correct, or enhance (photos of packaging, the ingredient and label information extracted from them, and any other product details you provide) become part of Sift’s shared product database. When you delete your account, we remove the link between those contributions and you. The product information itself stays in the database in de-identified form, so it keeps benefiting other users.
Aggregate, de-identified data (for example, “how many users scanned this product”) may be retained, because it no longer identifies you.
If you unsubscribe from our emails, we keep a record of that request for as long as we operate the Service, so that we don’t email you again. This record contains only your email address and the fact that you opted out.
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. You can delete your account and data directly in Settings → Account, unsubscribe from emails using the link in any message, and turn off push notifications in your device settings. For anything else, contact us at team@sifthealth.app. We respond within the timelines your local law requires, and we never discriminate against you for exercising privacy rights.
Automated processing. Sift highlights and prioritizes ingredient concerns on product pages based on the focus areas you select. This affects the order in which ingredient information appears. It does not produce legal or similarly significant effects, and it never determines access to your account, your subscription, or any service. If you’d like a person to look at how something was flagged for you, email us and we will.
Residents of Ireland, the EEA, and the UK may lodge a complaint with their supervisory authority: in Ireland, the Data Protection Commission; in the UK, the Information Commissioner’s Office.
If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have specific rights under your state’s privacy law. Some rights vary by state, and some may be limited in circumstances the law allows.
The categories below follow the classification used in California law. This table covers the past twelve months.
Sensitive personal information. The only sensitive personal information we hold is the health-related focus areas you choose to select. They are used only to highlight and prioritize relevant ingredient concerns on product pages. We do not use or disclose them for any purpose other than providing the Service, and we do not use them to infer characteristics about you. You can change or clear your focus areas at any time in Settings.
We have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve months, and we do not do so now. We do not sell the personal information of anyone, including consumers under 16.
Email team@sifthealth.app, or use the controls in Settings → Account, which handle access and deletion directly.
Verification. We’ll verify your identity before acting on a request, usually by confirming control of the email address on the account. We use information provided in a request only to verify identity and fulfill the request.
Authorized agents. You may designate an agent to make a request on your behalf. We may ask the agent for written, signed proof of authorization, and may ask you to confirm it directly.
Appeals. If we decline your request, you may appeal by emailing team@sifthealth.app with “Appeal” in the subject line. We’ll respond in writing with our decision and the reasons for it within the timeframe your state’s law requires. If we deny the appeal, you may complain to your state attorney general.
California Civil Code § 1798.83 lets California residents ask, once a year and free of charge, about personal information disclosed to third parties for their own direct marketing purposes. We do not disclose personal information for that purpose. Requests may be sent to team@sifthealth.app.
We process your personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. We rely on your express consent where the law requires it, and on implied consent where it can reasonably be inferred from the circumstances, for example using your account email to send communications about the Service. You may withdraw consent at any time, subject to legal and contractual limits, by contacting team@sifthealth.app. In limited circumstances the law permits processing without consent, including for fraud detection and prevention, to comply with a subpoena or court order, or where collection is clearly in your interest and consent cannot be obtained in a timely way. You may lodge a complaint with the Office of the Privacy Commissioner of Canada.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy is our APP 5 notice: it describes what we collect, why, where it comes from, and who else receives it. If you choose not to provide the personal information we need, we may be unable to create or maintain your account, deliver the Service, or respond to your requests. You may request access to or correction of your personal information at team@sifthealth.app, and you may complain to the Office of the Australian Information Commissioner if you believe we have breached the Australian Privacy Principles.
We handle personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles. You have the right to request access to and correction of the personal information we hold about you, at team@sifthealth.app. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner. Where we transfer personal information outside New Zealand, we do so only to recipients bound by comparable safeguards, as required by Information Privacy Principle 12.
Sift operates from the United States, and your data is processed there and in the countries where our providers operate. Where data moves out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, the EU–US Data Privacy Framework. Copies of the relevant safeguards are available on request at team@sifthealth.app.
Sift is not directed at children under 13 (or the higher minimum age of digital consent in your country), and we don’t knowingly collect their data. If you believe a child has created an account, contact us and we’ll delete it.
We use encryption in transit, access controls, and industry-standard practices to protect your data. No system is perfectly secure; if a breach affects you, we’ll notify you as required by law.
We’ll post updates here and, for material changes, notify you in the app or by email before they take effect. The date at the top shows when this policy was last revised.