Sift
← Back to home
LEGAL

Privacy Policy

Sift Labs LLC  ·  Last updated: September 26, 2026

This policy explains what Sift Labs LLC ("Sift," "we," "us") collects when you use the Sift app and sifthealth.app, how we use it, and the choices you have. Sift Labs LLC is the data controller for this information.

THE SHORT VERSION

We collect what we need to run Sift: your account, your scans and lists, the focus areas you pick, and how you use the app so we can improve it. We don't sell your personal data, and we never share it with the brands whose products you scan. You can export or delete everything.

1. What we collect

Account information. Your email address and name (if provided) via Sign in with Apple or email signup. If you use Sign in with Apple and choose Hide My Email, we receive a private relay address from Apple rather than your real email. Messages we send to that address are forwarded to you by Apple. We use this address for account and service communications and, unless you opt out, occasional updates about new features and Sift’s work (see section 3). You can unsubscribe from those at any time using the link in any email.

Activity in the app. Products you scan, search, save, or list; photos you submit of products; corrections or additions you make to product information; and the health focus areas you select. This is the core of your Sift experience. It powers your history, your lists, and focus-area prioritization.

Subscription status. Whether you have an active Sift+ subscription, trial, or renewal, via our subscription-management provider (RevenueCat). Payments are processed entirely by Apple or Google. We never see or store your card details.

Device and usage data. Device type, OS version, app version, language, crash logs, and analytics events (screens viewed, features used) via PostHog. Our analytics provider derives an approximate location (city and country) from your IP address. We never collect GPS or precise location. Where required by law, analytics beyond what’s strictly necessary runs only with your consent.

Push notification tokens. If you allow notifications, we store a device token so we can send them, for example to tell you a Sift Score you requested has finished calculating. You can turn notifications off at any time in your device settings.

Install attribution. If you install Sift through a creator’s link, our deep-linking provider (ChottuLink) attributes the install so the creator can be credited. This uses device-level signals, not your identity.

What we don’t collect. We don’t collect your precise location, your contacts, or health records. We don’t access your photo library. Photos you take of products inside the app are uploaded so we can identify the product and analyze its ingredients and labels. Camera frames used for barcode scanning are processed to read the code and are not stored. Sift is not connected to HealthKit or Google Fit.

2. A note on focus areas

Your selected focus areas (like gut health, hormone balance, or pregnancy and development) are preferences about topics you care about. Selecting a focus area doesn’t tell us anything about your health status, only which topics you want us to flag. But because they’re health-related, some laws (including the EU and UK GDPR, and several US state laws) may treat them as sensitive data. We treat them accordingly: they’re used only to highlight and prioritize relevant ingredient concerns on product pages, they’re never shared with third parties for their own use, and they’re never used for advertising. Where the law requires it, we collect them only with your explicit consent, which you can withdraw at any time in Settings. You can use Sift without selecting any focus area.

3. How we use your information

  • Provide the Service: accounts, scan history, lists, sync across devices
  • Personalize: highlight and prioritize ingredient concerns based on your focus areas
  • Operate subscriptions: manage trials, renewals, and entitlements via RevenueCat
  • Send service communications: receipts, password resets, security notices, and important account or policy updates
  • Send push notifications you’ve allowed, such as letting you know when a Sift Score you requested is ready
  • Send occasional updates about new features, ingredient research, and Sift’s impact. These may rarely mention Sift+. Every one includes a one-click unsubscribe link, and unsubscribing has no effect on your account or subscription.
  • Improve Sift: aggregate analytics, crash diagnostics, feature usage
  • Credit creators: attribute installs from creator links
  • Comply with law and enforce our Terms

We do not sell your personal data, use it for third-party advertising, or share your identity or activity with product brands. Sift’s scores can’t be bought, and neither can your data.

4. Who we share it with

Only service providers acting on our instructions under contract:

PROVIDERPURPOSE
Supabase & Amazon AWSApp infrastructure and data storage
RevenueCatSubscription status and entitlements
PostHogUsage analytics and crash reporting
ChottuLinkInstall attribution for creator links
Postmark (ActiveCampaign, LLC)Service email delivery
Apple and GooglePush notification delivery to your device
OpenAI, Google, and OpenRouterAI processing. Photos you submit and the text on product packaging are sent to these providers to identify the product and extract ingredients and labels. Analysis is then generated using Sift’s own research-based ingredient database and scoring framework. These providers process data on our behalf and are not permitted to use it for their own purposes.

We may also disclose information if required by law, to protect rights and safety, or as part of a merger or acquisition (in which case this policy continues to apply to your data and we’ll notify you of any change in controller).

Creators whose links drive installs see aggregate counts and commission amounts, never your identity.

5. Cookies and website tracking

The Sift app does not use cookies. Our website, sifthealth.app, uses a small number of them:

The website uses strictly necessary cookies that keep the site working, such as security and load balancing, and Google Analytics (Google LLC) to understand how visitors use the site in aggregate. Analytics cookies are not used for advertising. In the UK, the EEA, and other places where consent is required, analytics cookies are off by default and only run if you opt in.

Most browsers let you block or delete cookies directly. We do not use advertising or cross-site tracking cookies, and we do not allow third parties to use our site for their own advertising purposes.

Global Privacy Control. Where required by law, including under California law, we honor Global Privacy Control (GPC) signals sent by your browser as a valid request to opt out of any sale or sharing of personal information. Because we do not sell or share personal information, this does not change how we treat your data, but the signal is respected. There is no finalized standard for older “Do Not Track” signals, so we do not respond to those.

6. Legal bases (Ireland, the EEA, and the UK)

  • Contract: account, scans, lists, sync, subscriptions. Needed to provide the Service you signed up for
  • Legitimate interests: app security, service improvement, fraud prevention, basic analytics, and sending updates about the Service to people who already use it. You can unsubscribe from those updates at any time, and you can object to processing based on legitimate interests (see section 8).
  • Consent: focus areas where treated as special-category data, optional analytics and cookies, and push notifications. Withdrawable at any time
  • Legal obligation: tax, accounting, and lawful requests

7. Retention

We keep your data while your account is active. If you delete your account, personal data is deleted or irreversibly anonymized within 30 days, including copies held in encrypted backups, except records we must keep for legal or accounting reasons (kept no longer than required).

Products you submit, correct, or enhance (photos of packaging, the ingredient and label information extracted from them, and any other product details you provide) become part of Sift’s shared product database. When you delete your account, we remove the link between those contributions and you. The product information itself stays in the database in de-identified form, so it keeps benefiting other users.

Aggregate, de-identified data (for example, “how many users scanned this product”) may be retained, because it no longer identifies you.

If you unsubscribe from our emails, we keep a record of that request for as long as we operate the Service, so that we don’t email you again. This record contains only your email address and the fact that you opted out.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. You can delete your account and data directly in Settings → Account, unsubscribe from emails using the link in any message, and turn off push notifications in your device settings. For anything else, contact us at team@sifthealth.app. We respond within the timelines your local law requires, and we never discriminate against you for exercising privacy rights.

Automated processing. Sift highlights and prioritizes ingredient concerns on product pages based on the focus areas you select. This affects the order in which ingredient information appears. It does not produce legal or similarly significant effects, and it never determines access to your account, your subscription, or any service. If you’d like a person to look at how something was flagged for you, email us and we will.

Residents of Ireland, the EEA, and the UK may lodge a complaint with their supervisory authority: in Ireland, the Data Protection Commission; in the UK, the Information Commissioner’s Office.

9. United States: state privacy rights

If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have specific rights under your state’s privacy law. Some rights vary by state, and some may be limited in circumstances the law allows.

Categories of personal information we collect

The categories below follow the classification used in California law. This table covers the past twelve months.

CATEGORYEXAMPLESCOLLECTED
A. IdentifiersName, email address, IP address, device and account identifiersYes
B. Personal information under the California Customer Records statuteName and contact informationYes
C. Protected classification characteristicsAge, gender, race, national origin, marital statusNo
D. Commercial informationSubscription and purchase records held via our app store providersYes
E. Biometric informationFingerprints, voiceprints, facial geometryNo
F. Internet or other network activityIn-app activity: scans, searches, saved lists, features usedYes
G. Geolocation dataApproximate location (city and country) derived from your IP address by our analytics provider. We do not collect GPS or precise location.Yes
H. Audio, electronic, visual, or similar informationPhotos you take of products in the app are uploaded and stored so we can identify the product and analyze its ingredients and labels. Camera frames used only for barcode scanning are not stored.Yes
I. Professional or employment informationJob title, work historyNo
J. Education informationStudent recordsNo
K. InferencesWe do not build a profile from your activity. Your focus areas are explicit selections you make, used only to highlight relevant ingredients on product pages.No
L. Sensitive personal informationHealth-related focus areas you choose to selectYes

Sensitive personal information. The only sensitive personal information we hold is the health-related focus areas you choose to select. They are used only to highlight and prioritize relevant ingredient concerns on product pages. We do not use or disclose them for any purpose other than providing the Service, and we do not use them to infer characteristics about you. You can change or clear your focus areas at any time in Settings.

Sale and sharing

We have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve months, and we do not do so now. We do not sell the personal information of anyone, including consumers under 16.

Your rights

  • Know whether we process your personal data, and access it
  • Correct inaccuracies
  • Obtain a portable copy of data you provided to us
  • Delete your personal data
  • Opt out of sale, sharing, targeted advertising, or profiling with legal or similarly significant effects (we do none of these)
  • Limit the use and disclosure of sensitive personal information (California)
  • Obtain the categories of third parties to whom we disclose personal data
  • Not be discriminated against for exercising any of these rights

How to make a request

Email team@sifthealth.app, or use the controls in Settings → Account, which handle access and deletion directly.

Verification. We’ll verify your identity before acting on a request, usually by confirming control of the email address on the account. We use information provided in a request only to verify identity and fulfill the request.

Authorized agents. You may designate an agent to make a request on your behalf. We may ask the agent for written, signed proof of authorization, and may ask you to confirm it directly.

Appeals. If we decline your request, you may appeal by emailing team@sifthealth.app with “Appeal” in the subject line. We’ll respond in writing with our decision and the reasons for it within the timeframe your state’s law requires. If we deny the appeal, you may complain to your state attorney general.

California “Shine the Light”

California Civil Code § 1798.83 lets California residents ask, once a year and free of charge, about personal information disclosed to third parties for their own direct marketing purposes. We do not disclose personal information for that purpose. Requests may be sent to team@sifthealth.app.

10. Canada, Australia, and New Zealand

Canada

We process your personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. We rely on your express consent where the law requires it, and on implied consent where it can reasonably be inferred from the circumstances, for example using your account email to send communications about the Service. You may withdraw consent at any time, subject to legal and contractual limits, by contacting team@sifthealth.app. In limited circumstances the law permits processing without consent, including for fraud detection and prevention, to comply with a subpoena or court order, or where collection is clearly in your interest and consent cannot be obtained in a timely way. You may lodge a complaint with the Office of the Privacy Commissioner of Canada.

Australia

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy is our APP 5 notice: it describes what we collect, why, where it comes from, and who else receives it. If you choose not to provide the personal information we need, we may be unable to create or maintain your account, deliver the Service, or respond to your requests. You may request access to or correction of your personal information at team@sifthealth.app, and you may complain to the Office of the Australian Information Commissioner if you believe we have breached the Australian Privacy Principles.

New Zealand

We handle personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles. You have the right to request access to and correction of the personal information we hold about you, at team@sifthealth.app. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner. Where we transfer personal information outside New Zealand, we do so only to recipients bound by comparable safeguards, as required by Information Privacy Principle 12.

11. International transfers

Sift operates from the United States, and your data is processed there and in the countries where our providers operate. Where data moves out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, the EU–US Data Privacy Framework. Copies of the relevant safeguards are available on request at team@sifthealth.app.

12. Children

Sift is not directed at children under 13 (or the higher minimum age of digital consent in your country), and we don’t knowingly collect their data. If you believe a child has created an account, contact us and we’ll delete it.

13. Security

We use encryption in transit, access controls, and industry-standard practices to protect your data. No system is perfectly secure; if a breach affects you, we’ll notify you as required by law.

14. Changes to this policy

We’ll post updates here and, for material changes, notify you in the app or by email before they take effect. The date at the top shows when this policy was last revised.

15. Contact

Sift Labs LLC
4957 Lakemont Blvd SE, Ste C-4
PMB #381
Bellevue, WA 98006
team@sifthealth.app
© 2026 Sift. All rights reserved.
Terms of Use Back to home →