Privacy Policy
Last updated: September 30, 2026
SiftSafe is a Chrome extension that helps you review Gmail cleanup candidates and move selected messages to Gmail Trash. This page explains what we collect and what we deliberately do not.
Gmail access
Gmail OAuth tokens stay inside the Chrome extension on your device. They are never sent to SiftSafe servers. Scanning and cleanup call Google APIs directly from the extension.
What we do not store
The SiftSafe Product API and its database do not store email subjects, bodies, HTML, sender or recipient addresses, Gmail message IDs, thread IDs, attachments, or raw decision payloads that contain email content.
What we may store
Aggregate operational telemetry (counts, durations, model/policy versions, error categories, cost signals), installation-bound license status for Deep Clean billing, and WAFFO event IDs needed for webhook idempotency. Billing is separate from Google authorization.
Decision processing
Classification uses a minimized, sanitized decision state. Failures fail closed to Review — never automatic Trash. Jev cannot mutate Gmail.
Processing providers and local retention
Sanitized classification features are sent through our Product API on a privately managed server and Vercel AI Gateway to TypeSafe Jev. Features can include a sender domain, redacted subject features, age, locale and protection signals. Complete message bodies and Gmail access tokens are not sent by default. Provider processing terms and configuration must pass our vendor review before public launch.
Scan metadata and recovery records stay in this browser. Inactive records expire after 30 days; recent cleanup activity preserves the associated recovery records for that window. Cleanup runs when SiftSafe is opened. Uninstalling the extension or resetting local data removes local Undo history.
Your controls
Use Settings to reset local mailbox data or disconnect Gmail. Reset preserves your installation license identity. To revoke SiftSafe access completely, remove it from your Google account connections. Neither action changes messages in Gmail.
WAFFO processes billing separately and may collect payment and billing details on its checkout page. We keep installation-bound entitlement and order/event references, not payment card details. Contact us for billing-data access or deletion requests; records required for accounting or dispute handling may need to be retained.
Pseudonymous daily API quota counters include short-lived hashes of network addresses and installation identifiers. Raw IP addresses and mailbox payloads are not stored in these counters.
Questions about privacy: privacy@siftsafe.pro.