Privacy

The filter runs where you do.

Most extensions that read your feed send it somewhere. Sift doesn't need to: the whole cascade of rules, classifier and embeddings runs inside your browser. On the free plan, nothing about what you scroll ever leaves your machine.

Local first

What stays on your device.

Everything, on Free. Concretely:

  • Your preferences and their semantic definitions
  • Every post you see and every decision made about it
  • Your exceptions, overrides and "show anyway" history
  • The models themselves, loaded when needed and unloaded when idle

We can't sell, leak, or subpoena what we never receive. That's not a policy promise; it's an architecture.

No account to misuse

Free works with no sign-up at all. There's no profile to build, no email to hand over, no usage log tied to you, because there's no server in the loop.

Caching, not collecting

The content-hash cache exists so a post is classified once, locally. It stores a hash and a verdict, and it never syncs anywhere unless you turn Pro sync on.

No telemetry by default

Sift ships with analytics off. If we ever add opt-in diagnostics, they'll be off by default, inspectable, and one toggle to kill.

The Pro exception

Cloud checks, spelled out.

Pro's cloud LLM fallback is optional per preference, and it's the only time anything leaves your device. Here is exactly what crosses the wire.

What is sent

A short text excerpt of the ambiguous post, plus the structured definition of the matching preference. No images are uploaded for text checks; no account identity is attached to the request.

What is kept

Nothing, by default. Cloud responses are returned and discarded. We don't build training sets from your posts, and we don't log excerpts.

What is never sent

Your full feed, your browsing history, your other preferences, or your exceptions. Only the specific post that reached layer four, only when you allowed it.

Prefer zero cloud? Free behaves exactly like Pro with cloud checks disabled: uncertain posts simply stay visible with a flag.

Sync

If you choose to sync.

Pro can carry your preferences between devices. Sync payloads are end-to-end encrypted: your data is sealed on-device with a key derived from your account, and our sync server holds ciphertext it cannot read. Disable sync and the copies disappear from our side; local data was never there to begin with.

Deleting

Leaving takes one click.

Uninstalling the extension removes every local trace: preferences, cache, models, reports. If you had Pro, one more click deletes your encrypted sync blob from our servers. No retention window, no "anonymized archives".

Private by architecture, not by apology.

Try it with your network cable's conscience clear: watch the requests: there's nothing to see.