About this policy
This is a conservative launch draft intended to describe the service as it works today. It should be reviewed by qualified counsel before broad commercial launch.
This Privacy Policy applies to sift.mx’s website, member dashboard, email-forwarding service, payment challenges, and related support. By using sift.mx, you acknowledge the practices described here.
Information we process
Account and authentication data
We process your email address, account identifier, verification status, profile details you provide, authentication-provider identifiers, sessions, IP address, device or user-agent information, magic-link records, and two-factor authentication settings. Backup codes are encrypted.
Alias and forwarding data
We process your sift.mx alias, encrypted private forwarding address, delivery preferences, selected cover amount, block and whitelist rules, and verification state.
Email data
To route a message, we process sender and recipient identities, subject and message identifiers, timestamps, authentication results, delivery status, and the raw message—including its body and attachments. Raw quarantined messages are encrypted at rest but must be decrypted server-side for forwarding.
Payment and credit data
We process credit balances, ledger entries, cover amounts, fees, Stripe customer or checkout references, transaction status, and reconciliation records. Stripe processes card details; sift.mx does not receive or store full card numbers.
Logs and communications
We process security events, audit records, error and performance logs, support emails, and the information you choose to send us.
Why we use information
- Create and secure accounts, sessions, aliases, and forwarding destinations.
- Authenticate, quarantine, classify, charge for, block, and forward messages according to recipient rules.
- Maintain reply privacy by proxying replies through opaque sift.mx addresses.
- Process credit purchases, apply platform fees, maintain balances, and reconcile payments.
- Detect spam, fraud, abuse, loops, backscatter, and security incidents.
- Provide support, diagnose failures, comply with law, and improve reliability.
Where information is processed
We use service providers to run sift.mx. Cloudflare provides email routing, workers, object storage, queues, security, and observability. Neon provides managed PostgreSQL. Stripe processes card payments. Google processes sign-in information only when you select Google sign-in.
These providers process information under their own terms and privacy practices. Data may be processed in countries other than the one where you live. We may also disclose information when legally required, to protect the service or its users, or as part of a business reorganization subject to appropriate protections.
We do not sell personal information. We do not give Stripe message bodies, attachments, private forwarding addresses, or contact rules.
Retention
- Delivered raw message content is removed from quarantine storage as part of delivery.
- Unpaid quarantined content expires within seven days. Terminal content is normally removed by the scheduled purge within an hour.
- Payment challenge tokens expire after 72 hours.
- Reply proxy tokens expire after 90 days.
- Session, account, delivery metadata, rules, ledger, payment, security, and audit records are kept while needed to operate the account, preserve transaction integrity, resolve disputes, prevent abuse, and meet legal obligations.
- Backups and provider logs may persist for a limited period after deletion.
Cookies and sessions
sift.mx uses first-party cookies and similar browser storage needed to sign you in, maintain a session, protect requests, and preserve security state. We do not currently describe any third-party advertising-cookie program. Blocking essential cookies may prevent account features from working.
Your controls
The dashboard lets you update your forwarding destination, cover amount, sender rules, and two-factor settings. You may ask us to access, correct, or delete personal information, subject to identity verification and records we must retain for transaction, security, or legal reasons.
Privacy rights vary by location. To make a request, contact hello@sift.mx. We may need to verify that you control the relevant account.
Security and children
We use technical and organizational safeguards intended to protect information, including encryption of quarantined content and sensitive fields. No service can guarantee absolute security. See our Security page for the practical details and limits of our design.
sift.mx is not directed to children, and we do not knowingly invite children who cannot legally consent to this processing to create accounts. Contact us if you believe a child has provided information improperly.
Changes and contact
We may update this policy as sift.mx changes. We will publish the revised policy with a new effective date and provide additional notice when appropriate. Questions and requests can be sent to hello@sift.mx.