← ONYX SYSTEMS
SIFT — PRIVACY POLICY
August 5, 2026

Privacy Policy for Sift

01

The short version

Sift doesn't have a server. There's no account to create, nothing is uploaded anywhere, and the people who make Sift never see your documents, your categories, or anything else you store in the app. Everything lives in a local database and local files on your own device.

02

What Sift stores, and where

Documents, categories, expiration dates, and AI-summary text (if you ever turn AI summaries on) are stored in a local database on your device.
The actual files you upload or scan are stored on your device's own filesystem (or, in the web preview build, as part of that same local database).
Your PIN, if you turn on App Lock, is stored locally as a salted hash — never as plain text, and never anywhere but your device.
Biometric unlock (Face ID, Touch ID, Windows Hello, Android biometric) is handled entirely by your device's operating system. Sift asks the OS “did this person pass your biometric check?” and gets a yes/no answer back — it never receives, stores, or has access to any biometric data itself.
Forgot your PIN? The same ask-the-OS, get-a-yes/no pattern lets you set a new one, using biometrics or your device's own screen lock. Your PIN is a lock-screen gate, not an encryption key, so resetting it doesn't touch or re-encrypt anything already stored.
03

No analytics, ever

None of this is transmitted to Sift's developer, an analytics service, or any third party. Sift doesn't use analytics, crash reporting, or advertising SDKs of any kind.

04

Permissions Sift asks for, and why

Camera — used only when you choose to scan a document. Pages are turned into a PDF entirely on your device; the images are never sent anywhere else.
Notifications — used only to remind you a document is about to expire. These reminders are scheduled locally; no notification server is involved.
Biometric hardware — used only for the optional App Lock feature.
05

Backup & restore

Sift can export everything it stores into a single backup file, entirely under your control. When you back up, Sift hands that file to you — via your device's share sheet or a save dialog you control — and never uploads it anywhere itself. Restoring works the same way in reverse: you choose a backup file from your own device, and nothing leaves it.

06

Sift Pro purchases

Sift has no ads. A few features — adding more than 10 documents, creating custom categories beyond the 5 built-in ones, and Backup & Restore — require a single one-time purchase called Sift Pro, handled entirely by Apple's or Google's own payment system. Sift never sees your payment method, card number, or any other billing detail. The only thing Sift itself stores locally is a single unlocked/not-unlocked flag — there's no server-side receipt verification, because there's no server.

07

Your device's own backup features

Android and iOS both offer OS-level backup services (Android's Auto Backup, iCloud/Finder backup on iOS). Depending on your settings, these may include Sift's local data as part of your regular phone backup — that's a feature of your device's operating system, between you and your own cloud account, and Sift's developer has no access to it.

08

AI summaries

Sift has an optional AI document-summary feature. It is turned off by default in this version of the app, and nothing is sent to any AI service unless a future version enables it and you explicitly choose to use it on a specific document. If that ever changes, this policy will be updated first to explain exactly what gets sent, to whom, and how to keep it off.

09

Data retention and deletion

Your documents stay on your device for as long as you keep them there. Deleting a document or category in the app removes it from local storage immediately. Uninstalling Sift removes all of its local data from your device, subject to your OS's own backup settings.

10

Children's privacy

Sift is not directed at children under 13 and does not knowingly collect information from anyone, since it doesn't collect information from anyone at all — everything stays on-device.

11

Changes to this policy

If Sift's data practices ever change — most notably if AI summaries are enabled by default, or if any server-backed feature like cloud sync is ever added — this policy will be updated to describe the change before it ships, and the in-app version of this page will reflect the update.

Questions about this policy: konstantin.hordx@gmail.com
Third-party processors: Apple App Store / Google Play — in-app purchase processing only (Sift Pro).
This policy is mirrored in the app's source repository and kept in sync with each release.
/privacy/sift