Privacy Policy

Last updated 7 August 2026

This policy explains what data Sift collects, why we collect it, who we share it with, and how you can get it deleted. It applies to the Sift web application at app.siftinfluencers.com and this marketing site.

Sift is operated by Yagna Patel, a sole proprietor, at 87, 2nd A Cross Road, KHB Colony, 5th Block, Koramangala, Bengaluru, Karnataka 560095, India. If you have a question about anything here, email support@siftinfluencers.com.

What we collect

Four kinds of data, for different reasons.

  • Account data. Your email address, and the workspace you belong to. We use magic-link sign-in, so we never collect or store a password.
  • Creator data you bring. Lists you upload, and the public profile information we gather about those creators — handles, bios, public contact addresses, follower and engagement metrics, and post content. This is data about third parties that you have chosen to process using Sift.
  • Google account data, only if you connect one. See the dedicated section below.
  • Usage data. Page views and basic product analytics, so we can tell which parts of the product are used.

Google user data

Connecting a Google account is optional. Sift works without it. You only need to connect one if you want to send creator outreach from your own address.

When you connect a Google account, Sift requests these scopes:

  • openid and https://www.googleapis.com/auth/userinfo.email — to identify which Google account you connected and display it back to you.
  • https://www.googleapis.com/auth/gmail.send — to send the outreach emails you compose and approve in Sift.

Sift cannot read your email. The gmail.send scope permits sending only. We do not request, and could not exercise, permission to read, search, download, or delete messages in your mailbox. We do not have access to your inbox, your drafts, your contacts, or your Google Drive.

What we store as a result of the connection:

  • Your Google account email address, so you can see which account is connected.
  • An OAuth refresh token, encrypted at rest with AES-256-GCM. This is what lets Sift send on your behalf without asking you to sign in again. It is never exposed to your browser and is never logged.
  • A record of each message Sift sent for you — recipient, subject, body, and the Gmail message and thread identifiers — so the product can show your outreach history and thread follow-ups correctly.

We never use Google user data to train machine learning models, and we never sell it or transfer it to third parties for advertising, credit assessment, or resale.

You can disconnect at any time from settings inside Sift. Disconnecting revokes the token with Google and deletes it from our database. You can also revoke Sift’s access directly at myaccount.google.com/permissions.

Sift’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use data

To run the product: authenticating you, qualifying and scoring the creators on your list, sending the outreach you compose, and showing you the results. To bill you. To email you about your account and about problems with runs you started. To debug and improve the product.

We do not sell your data. We do not use your creator lists to build a shared or resold database, and one customer’s data is not exposed to another.

Who we share it with

We use a small set of vendors to run Sift. Each processes only what it needs:

  • Supabase — database and authentication.
  • Vercel — application hosting and analytics.
  • Dodo Payments — subscription billing. Card details go to them directly; we never see or store them.
  • Resend — transactional email from Sift to you. This is separate from outreach, which is sent through your own Google account.
  • OpenRouter — the language models used to qualify creators against your brief.
  • Apify — collection of public creator profile data.

We may also disclose data if legally required, or to a successor entity in a merger or acquisition, in which case this policy continues to apply until you are given notice of a replacement.

Retention and deletion

We keep your data while your account is active. If you delete your account, or ask us to, we delete your workspace data within 30 days, except where we have to keep records for legal or accounting reasons — billing records typically for seven years.

Google tokens are deleted immediately when you disconnect, not after 30 days.

To request deletion, email support@siftinfluencers.com from your account address.

Security

Data is encrypted in transit over TLS and at rest by our database provider. Google refresh tokens receive a second layer of application-level AES-256-GCM encryption, so they remain unreadable even to someone holding a database dump. Access between workspaces is enforced at the database level by row-level security, not only in application code.

No system is perfectly secure. If we discover a breach affecting your data, we will tell you.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Email support@siftinfluencers.com and we will action it within 30 days.

Note that much of the creator data in your workspace is personal data about people who are not Sift customers. Where you decide what to collect and who to contact, you are the controller of that data and we act as your processor. Your obligations to those people are covered in our Terms of Service.

International transfers

Our vendors operate in several countries, so your data may be processed outside the country where you live, including in the United States and the European Union.

Children

Sift is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.