Siftbird helps you keep your Gmail inbox clean by deciding, for each new email, whether it should stay unread, be marked read, or be archived. This policy explains exactly what we access and store.
What we access
With your permission, Siftbird uses a single Google permission (gmail.modify) to read message metadata and change read/archive labels. If you explicitly turn on the “move junk to Trash” option, it can also move clearly-junk mail to your Trash (recoverable for 30 days). We do not have permission to permanently delete email, send email, or download your data.
What we store
We deliberately store as little as possible:
- Your account identity (name, email, profile image).
- An encrypted Google token so we can act on your inbox on your behalf.
- Your billing status (via Stripe — we never see your card number).
- Your preferences and any sender rules you create.
- An activity log containing only the action taken, a derived category, the sender’s domain, and the opaque Gmail message ID (so you can undo it).
What we do NOT store
We never store the content of your emails — no bodies, no subjects, no attachments, no full sender addresses. We read what we need to make a decision, then discard it. Email content is never used to train any model.
Data Security
We protect the sensitive data described above with the following safeguards:
- Encryption in transit: all traffic between your browser, our servers, and Google or Stripe is sent over TLS (HTTPS).
- Encryption at rest:your Google OAuth tokens are encrypted with AES-256-GCM before they are written to our database, in addition to the database provider’s own disk-level encryption. Tokens are never stored in plaintext.
- Access controls: production data is accessible only to the small number of engineers who operate Siftbird, is never shared with third parties for marketing, and is not accessed by humans except as described above (support, security, legal compliance, or with your consent).
- Data minimization: we intentionally avoid storing email content, so there is nothing sensitive to protect beyond the metadata and tokens listed above.
- Retention & deletion: your Google token and account data are deleted immediately when you disconnect Gmail or delete your account.
Google API Services — Limited Use
Siftbird’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use the Gmail data we access (via the
gmail.modify scope) only to provide and improve Siftbird’s inbox-triage features for you. - We do not transfer or sell this data to others, except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use this data for advertising, and we never use it to train generalized AI/ML models.
- We do not allow humans to read your Gmail data, except: with your explicit consent for specific messages, where necessary for security (such as investigating a bug or abuse), to comply with applicable law, or where the data has been aggregated and anonymized.
Third parties
To classify mail we send minimal metadata (sender, subject, a short snippet) to our model provider (OpenRouter) for the moment of the decision only; it is not retained by us. Payments are processed by Stripe. Hosting is on Vercel.
Your control
You can turn automation off, disconnect Gmail, or delete your account at any time, which removes your stored data. Disconnecting also revokes our access via your Google account settings.
Questions? Email support@siftbird.com.