SiftReturn to scan

Privacy Policy

Private beta draft. Last reviewed: 24 September 2026.

This notice describes the current product behaviour. It does not claim legal compliance.

What Sift processes and why

Sift reads food-label photos and checks the extracted text for allergens and selected dietary preferences. Results can be incomplete or incorrect.

  • Photos: you choose a photo or capture one with your camera. The browser converts it to JPEG and sends it to Sift's server. Google Gemini receives the image for text transcription and a separate product-name reading. Sift's server then applies local rules. Your saved allergy list is sent to Sift's server for personalisation; the current code does not include that list in Gemini requests.
  • Scan records: when saving succeeds, Supabase stores the extracted text, product name when available, result, allergen matches, reasons, timestamp, scan ID and browser-session ID. Signed-in scans also carry your account ID. Guest scans are saved too. Session-linked scan counts support an internal repeat-use measurement.
  • Accounts and profiles: Supabase processes your email and password for registration and login. Optional allergies, diet choices and custom terms are stored with your account to personalise checks. These choices can reveal health information or religious beliefs. Creating an account attempts to link this tab's guest scans to it.
  • Connection information: the production rate limiter sends your IP address to Supabase and stores hourly counters. Hosting, database and code-delivery providers receive connection information needed to handle requests. Error logs can include provider error details.

Your choices

You can use the saved example without uploading a photo. A photo and your upload agreement are required to run your own scan. Upload only the label: avoid faces, addresses, receipts and other personal or confidential details. Opening the live camera requests browser permission.

An account is optional for scanning. Email and password are required to create one. Allergies and diet preferences are optional. Explicit agreement is requested before saving profile information. Without saved preferences, scans cannot check your personal list.

Storage and deletion

Sift does not write uploaded photos to its scan-history database. It writes a temporary server file and attempts to remove it when processing ends, including on failure. This is not a guarantee of immediate deletion if cleanup fails or a process stops unexpectedly. The page keeps up to three recent photo previews in memory and clears those references when leaving the page.

No automatic expiry is implemented for scan records, profiles or IP counters. Closing a tab, signing out or clearing browser storage does not delete database records. Deleting your account does; see below. Clearing a profile choice changes the current profile only; it does not remove earlier scan records.

You can view saved account scans in History and edit your preferences in Edit profile. Access, correction and consent-withdrawal requests still need a working operator contact and a verified manual process; those are pending below.

Deleting your account

Signed-in users can delete their account from Profile. You are asked for your password and to type a confirmation word first. Deletion is immediate, permanent and cannot be undone. There is no grace period and no way to restore the account afterwards.

When deletion completes, Sift removes from its live records:

  • your account, email address and password record, including the avatar and consent version stored with it;
  • your saved allergies, diet choices and custom terms;
  • every scan record linked to your account, including guest scans that were earlier added to it;
  • guest scans made in the same browser tab that were never added to your account.

Deletion also signs that browser out and clears Sift's tab-session identifier, scan count and account-prompt setting from it. You can create a new account with the same email address afterwards; it starts empty.

What Sift cannot erase. Deleting your account does not reach copies that sit outside Sift's live records:

  • Backups: Supabase keeps database backups under its own schedule. Deleted records can remain in a backup until it rotates out. Sift does not restore deleted accounts from backups.
  • Photo processing: photos already sent to Google Gemini are handled under Google's Gemini API terms, including any retention those terms allow. Sift cannot recall them.
  • Hosting and error logs: Vercel and Supabase request and error logs can include your IP address, request times and provider error details. They expire under each provider's own retention.
  • IP rate-limit counters: these are keyed by IP address, not by account, so deletion cannot identify them. They are not removed.
  • Guest scans from other tabs: guest scans made in a different tab or browser, and never added to your account, are not linked to you and cannot be found or removed by deletion.

Providers and transfers

Sift uses Vercel for hosting, Google Gemini for image reading, Supabase for accounts and database records, and esm.sh to deliver the Supabase browser library. Fonts and app images are served from Sift's own site. This page loads no account library.

Google processes uploaded photos under its own terms. See Google's Gemini API terms.

Browser storage

The inspected app has no advertising trackers or third-party analytics scripts and does not set non-essential cookies. It uses sessionStorage for a tab-session identifier and localStorage for the Supabase login session, a scan count, whether an account prompt was dismissed, and which version of these policies you accepted for photo processing. These support sign-in, guest history, consent and interface behaviour. If you have an account, the accepted consent version is also stored on your Sift account so you are not asked again on another device. Browser settings can clear browser storage, but doing so may sign you out, remove access to guest history, or cause the consent question to be asked again. It does not delete server data.

Operator and data requests

Contact channel: A dedicated contact channel is being set up. For now, feedback can be shared wherever this project was shared with you.

Because no monitored channel is published yet, access, correction, consent-withdrawal and deletion requests cannot be received or verified here. Do not send identity documents or medical information to any address claiming to be Sift until a working channel is named on this page.

Material changes to these practices require this notice to be reviewed and updated before the new processing starts.