Skip to content
SiftSum
EN FR
Create account

Effective August 13, 2026

Privacy Policy

This policy describes the data flows in the current SiftSum public beta. It is written to say what the product actually does, including where AI providers and Apple are involved.

Information you provide

SiftSum stores the information needed to run your account and financial journal.

  • Account information: name, email address, password hash, language, and account currency.
  • Financial records: opening balance, receipts and line items, merchants, categories, income, recurring entries, budgets, and adjustments.
  • Assistant content: questions, replies, tool results, and action approvals needed to continue a conversation.
  • Support or privacy messages you choose to send us.

Receipt images and AI processing

When you scan in the iPhone app, the receipt image is held in memory for one request and sent through OpenRouter to the configured reading model. SiftSum does not write the image to disk, a queue, or an application log. The structured draft returned by the model is kept only if you save it.

When you use your own compatible AI client, that client reads the image and sends SiftSum structured fields. The image does not reach SiftSum through that workflow.

Assistant questions and the financial context required to answer them are sent through OpenRouter to the configured model provider. Assistant transcripts are retained for 30 days by default so conversations can continue, then deleted by an automated task.

Technical and purchase information

  • Necessary session and security records may include an IP address, browser or device user agent, session identifier, and recent activity time.
  • Operational logs record request and error information used to secure and repair the service. Receipt image contents are excluded from application logs.
  • App Store purchase records include signed transaction details, product, subscription dates, and a random account token used to match Apple transactions to your SiftSum account.
  • OAuth and app tokens identify authorized clients and can be revoked.

Public-site analytics

The marketing site records first-party product events such as a page view, demo interaction, signup click, and completed web registration. These events may include the page, language, referral host, campaign parameters, and a random identifier that lasts for one page load. The analytics table does not store your IP address, browser user agent, email address, or a cross-site advertising identifier. Raw events are deleted after 30 days.

How information is used

  • Provide, synchronize, secure, and troubleshoot SiftSum.
  • Read receipt images and answer assistant requests you initiate.
  • Calculate balances, trends, budgets, and forecasts.
  • Verify App Store subscriptions and restore purchases.
  • Understand whether the public website and onboarding work, without advertising profiles.
  • Meet legal obligations and investigate abuse or security incidents.

Service providers

Information is shared only as needed with infrastructure and email providers, Cloudflare for delivery and protection, OpenRouter and the configured model provider for AI requests, and Apple for App Store purchases. A connected AI client receives only the access you authorize. Providers may process information outside your province or country under the laws that apply where they operate.

Cookies and local storage

SiftSum uses necessary session, authentication, language, CSRF-security, and application-preference storage. The public marketing analytics described above do not use a persistent analytics cookie and SiftSum does not use advertising trackers.

Retention and deletion

Account and journal information is retained while your account exists. You can permanently delete the account and its associated data from Profile settings. Individual receipt and income deletions may remain recoverable in the product trash until the account is deleted. Security, transaction, or backup records may remain for a limited period where needed for integrity, fraud prevention, or legal obligations.

Your choices and rights

You can update profile information, revoke connected clients, delete records, and delete your account from the product. To request access, correction, deletion, or raise a privacy concern, contact [email protected]. We may need to verify that the request concerns your account.

Changes and contact

This policy will change as the public beta changes. The effective date above will be updated, and material changes will be communicated in the product when appropriate. Privacy questions can be sent to [email protected].

© 2026 SiftSum
Privacy Policy Terms of Use Sign in