Sifta
Now accepting early access

Is It Safe to Let AI Read Your Email? A Transparent Answer

It's a fair question — and the most important one you should ask before connecting any AI tool to your inbox. Your email contains contracts, financial data, personal conversations, and relationships that matter. This page gives you specific, first-person answers: which OAuth scopes Sifta requests, which AI models process your email, exactly what data is stored, and how to revoke access permanently in under 30 seconds.

Get Early Access

Sound Familiar?

×

Most AI tool privacy policies are written in legal language designed to protect the company, not inform you. After reading five paragraphs you still don't know what actually happens to your emails.

×

You've heard about companies training AI models on user data without explicit consent. Your private emails are not training data you want to donate to anyone.

×

Giving an app access to your inbox feels irreversible — like once it's in, you can't really undo it. You want to know you can take control back instantly.

How Sifta Fixes This

Sifta requests only the OAuth scopes it needs. For Gmail: gmail.readonly (read emails), gmail.modify (archive on your behalf), gmail.compose (allows creating and sending draft replies when you explicitly request it), and userinfo.email. For Outlook: Mail.ReadWrite, User.Read, offline_access, openid, and email. The gmail.compose and Mail.ReadWrite scopes technically allow Sifta to send email, but the application only ever does so on your explicit instruction.

Email classification and the summaries sent to you via iMessage are generated by OpenAI's GPT-4.1-mini model. A lightweight noise-detection pass uses GPT-4.1-nano to filter obvious spam before classification runs. Conversational agent responses — when you send a message back to Sifta in iMessage — use Anthropic's Claude Haiku. Both providers' API terms prohibit using your data to train their general models.

You can revoke Sifta's access to your inbox in under 30 seconds from your Google Account or Microsoft account settings — no need to contact Sifta first. The moment the OAuth permission is removed, Sifta stops monitoring your inbox. Full data deletion is available by emailing support@joinsifta.com.

What You Get

OAuth-based connection — your password is never shared with Sifta

Minimum required scopes only — no permissions beyond what the product needs

Your email is never used to train AI models (OpenAI and Anthropic API terms both prohibit this)

Row-level security — your data is isolated from all other Sifta users at the database level

Revoke access in 30 seconds from Google or Microsoft account settings

Full data deletion available by emailing support@joinsifta.com

Frequently Asked Questions

What email permissions does Sifta actually request? +

For Gmail, Sifta requests: gmail.readonly (to read emails), gmail.modify (to archive emails when you instruct it to), gmail.compose (to draft replies you request), and userinfo.email (to identify your account). For Outlook: Mail.ReadWrite (read, archive, and draft), User.Read (identify your account), offline_access (maintain the connection), openid, and email. Sifta never requests permission to send email autonomously — every send action requires your explicit approval.

Which AI models process my email? +

Sifta uses two providers. Email classification and the 2-3 sentence summaries delivered to you via iMessage are generated by OpenAI's GPT-4.1-mini. A lightweight noise-detection pass uses OpenAI's GPT-4.1-nano to filter clear spam and newsletters before the main classifier runs. When you send a message back to Sifta in iMessage — asking it to search your inbox, explain a thread, or take an action — those conversational replies are generated by Anthropic's Claude Haiku model. Both providers' API usage terms prohibit using customer API inputs to train their general models.

Is my email content stored by Sifta? +

Yes. Sifta stores email metadata and body text in a Supabase PostgreSQL database to enable features like inbox search, agent context, and multi-turn conversations. All database tables have row-level security (RLS) enabled — your data is only accessible to your authenticated account and cannot be queried by any other user. Your Google and Microsoft OAuth tokens are stored in encrypted form.

Are my emails used to train AI models? +

No. OpenAI's API data usage policy prohibits using inputs submitted via the API to train OpenAI models without explicit opt-in. Anthropic's policy likewise prohibits using API inputs for training without consent. Sifta has not opted in to either program. Your emails are not used to train any AI model.

Can Sifta send emails from my account without my permission? +

The gmail.compose scope grants Sifta technical permission to create and send emails from your Gmail account. The Mail.ReadWrite scope grants the equivalent for Outlook. Sifta's application code uses these scopes only when you explicitly instruct it to draft or send a reply — the AI will not initiate any send action on its own. If you are concerned, you can review your authorised scopes at any time in your Google Account or Microsoft account settings and revoke access entirely.

How do I revoke Sifta's access to my email? +

For Gmail: visit myaccount.google.com, click Security, then 'Third-party apps with account access', find Sifta, and click Remove Access. For Outlook: visit account.microsoft.com, click Privacy, then 'Apps and services that can access your data', find Sifta, and remove it. Access is revoked immediately — Sifta stops monitoring your inbox the moment the OAuth permission is removed.

What happens to my stored email data if I cancel? +

When you cancel, Sifta stops monitoring your inbox. Your email data (body text, metadata, AI summaries) remains in Sifta's database with row-level security isolation intact until you request deletion. To permanently delete your account and all associated data, email support@joinsifta.com. Revoking OAuth access through Google or Microsoft settings stops inbox monitoring independently of — and immediately, without waiting for — account deletion.

Who inside Sifta can see my emails? +

Your email data is processed by automated systems (the AI classifier and conversational agent). Human Sifta employees do not access your email content during normal operations — row-level security at the database layer enforces this technically, not just by policy. If you report a specific support issue and voluntarily share an email excerpt as part of that report, the support team member handling your case may see what you have explicitly provided.

Related Reading

Transparent AI email intelligence. Connect in 2 minutes, revoke in 30 seconds.

Sifta is in early access at $49/month. Works with Gmail and Outlook — setup takes 2 minutes.

Get Early Access