Sift · Legal
Privacy Policy for Sift
Sift is a photo cleaner, search and redaction tool for Android, published by AVORA SIA.
The short version
Sift does not collect, transmit, or share any of your data. It cannot.
Sift does not have the Android INTERNET permission. Without
it, the operating system refuses the app a network connection — not as a
policy we promise to follow, but as a rule Android enforces on our behalf.
Your photos, the text found inside them, the places they were taken, and
everything else Sift works out about your library stay on your phone.
You do not have to take our word for it. On this app's Google Play listing, open App permissions → See more. If "Full network access" is not listed, the app cannot reach the internet. You can check the same list on your own device under Settings → Apps → Sift → Permissions, and inside the app under What Sift knows → The permission receipt.
What Sift does with your photos
Everything Sift does happens on your device:
- Reading your library. Sift asks for permission to read photos and videos so it can find duplicates, near-duplicates, blurry shots, memes, story exports, screenshots and large videos. It reads their pixels and their file details. If you grant access to only selected photos (an Android 14+ option), Sift works with exactly those and does not nag for more.
- Finding text and objects. Sift reads the words and recognises objects inside your images so you can search them. This uses Google ML Kit models that are bundled inside the app rather than downloaded, so no image or text ever leaves the phone to be analysed.
- Naming places. If you allow it, Sift reads the location a photo was taken from the photo's own data and matches it against a list of towns and cities included in the app. No lookup service is contacted. Only the place name is stored — never your coordinates.
- Finding things worth covering. Before you share an image, Sift looks for payment card numbers, bank and IBAN-style numbers, long reference numbers, postal addresses, email addresses, phone numbers, vehicle number plates, and faces. Faces are detected as shapes in the frame — Sift does not recognise whose face it is, cannot tell two people apart, and cannot search by person.
All of this is stored in a private database inside the app's own storage, which no other app can read. Deleting Sift deletes it.
Making a safe copy of a photo
When you choose Make safe with Sift from another app's share sheet:
- Sift draws solid opaque rectangles over what you chose to cover. It never blurs or pixelates, because both are sometimes reversible. Once written, the covered pixels are gone from that copy — including for us.
- Your original photo is never modified or deleted. Sift writes a new JPEG into its own private cache and shares that.
- The copy carries no EXIF metadata. Re-encoding the image drops every tag, including the GPS coordinates the original may have carried invisibly.
- Only one safe copy is kept on disk at a time — writing a new one deletes the previous file, so redacted images do not pile up in a cache directory you never look at. Clearing the app's cache or uninstalling removes it.
- Sift then hands that one file to the app you picked in the share sheet, through Android's standard file-sharing mechanism, and grants read access to that single file only. What happens to the image after that is between you and that app — Sift has no part in the sending and could not send it itself.
What Sift stores, and how to erase it
Everything below lives in Sift's own private storage on your device. None of it is transmitted, and no copy of it exists anywhere else.
| What | Why |
|---|---|
| File details from Android's media store (id, size, dates, dimensions, folder) | To notice what changed since the last scan |
| A small fingerprint of each image, and a sharpness score | To group duplicates and spot blurry shots |
| Text found in the image, and object labels | So you can search your library |
| A place name, e.g. "Brighton, GB" — never coordinates | So you can search by where a photo was taken |
| The regions of an image where a face or something sensitive was found | So Protect can offer to cover them |
| Counts of how many photos you have deleted and how many safe copies you have made | To apply the free allowances (200 deletions, 25 safe copies) |
| Whether you have purchased the paid upgrade | So the app knows not to ask again |
You can erase the index at any time in What Sift knows → Delete the whole index, reached from the app's home screen. Uninstalling Sift removes everything, including the purchase flag and the counts.
Deleting photos
When you delete photos with Sift they are moved to Android's own Recently deleted, where the system keeps them for 30 days and you can restore them. Sift asks Android to do this; it does not delete your files directly, and Android shows you its own confirmation before anything moves.
Purchases
Sift offers an optional paid upgrade. Payments are handled entirely by Google Play Billing — AVORA SIA never sees or stores your payment details, and no payment information passes through Sift. Google processes that transaction under Google's Privacy Policy. Sift receives only the fact that a purchase exists, and stores that on your device. The Google Play Store app, not Sift, is what talks to Google over the network — which is why Sift can sell an upgrade while having no internet permission of its own.
Permissions, and why each one exists
| Permission | Why |
|---|---|
Photos and videos (READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, and on Android 11–12 READ_EXTERNAL_STORAGE) |
To find duplicates, blurry images and large files, and to search your library |
Selected photos only (READ_MEDIA_VISUAL_USER_SELECTED) |
Optional. So partial access is a supported way to use Sift, not a broken one |
Media location (ACCESS_MEDIA_LOCATION) |
Optional. To name the place a photo was taken, using an offline list. Android redacts GPS tags without it |
Notifications (POST_NOTIFICATIONS) |
Optional. To show scan progress and tell you when a scan finishes |
Run a foreground service (FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC) |
To finish a scan while you use other apps, with a visible notification the whole time |
Billing (com.android.vending.BILLING) |
For the optional paid upgrade |
Not requested: internet access (INTERNET),
network state (ACCESS_NETWORK_STATE), precise or approximate
location services, contacts, microphone, camera, phone, calendar, or your
accounts. Sift has no login and no account of any kind.
Analytics, advertising and tracking
There is none. Sift contains no advertising, no analytics, no crash reporting, and no tracking, attribution or advertising-identifier software of any kind. There is no account to create and no profile of you anywhere. Sift does not read your advertising ID.
Third-party software inside the app
Sift includes Google ML Kit (text recognition, image labelling and face detection), the Google Play Billing library, and Coil, which draws the photo thumbnails you see in the app. The ML Kit models ship inside the APK and run entirely on the device — they are not a service Sift calls. Coil is configured with its network support absent and its disk cache switched off, so it reads your photos to display them and never writes a copy of one. None of these libraries can send anything from Sift, for the same structural reason as everything else on this page: the app has no network permission.
Children
Sift is not directed at children under 13. It collects no data from anyone, including children, and has no social features, no user-generated content and no communication features.
Your rights
Regulations such as the GDPR and the CCPA give you rights to access, correct, export and delete the personal data a company holds about you. AVORA SIA holds none, so there is nothing for us to retrieve, correct, export, erase or sell — and nothing to opt out of. The data on your own device is under your control, and What Sift knows → Delete the whole index erases it.
If you believe otherwise, write to us at the address below; and if you are in the EU or UK you may also complain to your national data-protection authority. In Latvia, where AVORA SIA is registered, that is Datu valsts inspekcija (dvi.gov.lv).
Changes to this policy
If Sift's behaviour ever changes, this page will be updated before the change is released, and the date at the top will change with it.
Contact
Questions about this policy or the app:
Before submitting Sift to Google Play, replace "to be added" above with AVORA SIA's registered address. A published policy that names a company but gives no address is a common review flag, and Latvian company details are expected to be disclosed. Do not guess it.