Privacy
Short version: Sift talks only to Google, keeps everything on your Mac, and collects nothing.
What leaves your Mac
Only the requests needed to read and send your mail, made directly to Google over TLS. Sift has no backend, no analytics endpoint, no crash reporter, and no ads.
What stays on your Mac
- A local SQLite database with your mailbox, search index, attachments, and drafts.
- Your Gmail app password or OAuth refresh token, stored in the macOS Keychain.
- Logs and diagnostics, which are written locally and never uploaded.
Remote images
Like most mail clients, Sift loads remote images by default so messages look the way they were designed. If you prefer, set Settings → Privacy → Remote images to Never and they will be blocked before they reach the renderer.
Credentials
Sift authenticates with an app password or an OAuth refresh token. Tokens are held in the Keychain and only ever sent to Google. The local database never stores them.
Deleting your data
Removing an account deletes its Keychain entry and every row associated with it in the local database. Uninstalling the app and deleting its application support folder removes everything else.
Questions
Open an issue on GitHub if anything here is unclear.