Legal
Privacy & Terms
Last updated: June 12, 2026. Plain-language; written to match how Sift actually works.
The short version
- • Your Solidity code and findings are adjudicated in memory and discarded when the request finishes. We never store them.
- • We keep only what runs the account: your email, a hash of your API key, your plan, and a monthly findings count.
- • Card details go straight to Razorpay/Stripe — we never see or store them.
- • No ad trackers. The only browser storage is your login session and theme choice.
Privacy Policy
What we collect
- Account identity — your email, optional display name, and (if you sign in with Google or GitHub) the provider's account identifier. Used to authenticate you.
- API keys — we store only a one-way hash and a short prefix for display. The full key is shown once at creation and is never recoverable by us.
- Billing state — your plan/tier, and the subscription and customer identifiers returned by our payment processor. We do not receive or store card numbers.
- Usage counts — the number of findings you triage each month, to enforce your plan's allowance.
What we do not store
When you send findings to the hosted triage endpoint, the code context you choose to include is used only to produce a verdict and is discarded the moment the request returns — nothing from the request body is written to our database. Your source code, contracts, and findings are never persisted, logged for training, or shared. The triage engine is open source under the MIT license, so you can verify this for yourself.
Payment processing
Payments are handled by Razorpay (India) and Stripe (international). Your card data is collected and stored by them under their own privacy policies; we receive only your subscription status via cryptographically signed webhooks, which is what sets your plan.
Cookies & browser storage
We don't use advertising or cross-site tracking cookies. Your browser's local storage holds a login session token (to keep you signed in) and your light/dark theme preference. That's it.
Where your data is processed
Our application runs on Render, model inference runs on Modal, and the website is served by Vercel. Requests transit these providers in the course of running the service; none of them receive your stored account data beyond what's needed to operate.
Deleting your data
Email manibajpaiofficial@gmail.com to delete your account and the limited data above. Since we never store your code or findings, there is nothing of yours to purge from past triage requests.
Terms of Service
The service
Sift runs Solidity static-analysis scanners and adds an AI verdict layer that separates likely real vulnerabilities from false positives. The open-source pipeline is provided under the MIT license; the hosted AI triage is provided as a paid and free-tier service through your account.
Your account
You're responsible for keeping your login and API keys secure, and for activity under your account. Don't share keys, resell access, attempt to exceed or circumvent your plan's allowance, or overload the service.
Plans & the free allowance
The free tier includes a capped monthly allowance of hosted AI findings (currently 50/month) so you can try the service; paid plans raise the cap. Allowances, pricing, and plan features may change. Payments are currently processed in test mode during early access.
No warranty — triage is advisory
Sift helps you prioritize scanner output. It is not a security audit and not a guarantee that your code is safe or that every real issue is surfaced. Verdicts are advisory; you remain responsible for reviewing your contracts and for any decisions you make based on Sift's output. The service is provided "as is," without warranties of any kind. To the maximum extent permitted by law, we are not liable for losses arising from use of, or reliance on, the service.
Early-access status
Sift is in early access. Features, limits, and these terms may be updated; material changes will be reflected here with a new "last updated" date. Continued use after a change means you accept it.
Contact
Questions about privacy or these terms? Email manibajpaiofficial@gmail.com.