Privacy and GDPR
The honest answer: GDPR is a legal framework, so no tool can hand you a certificate that says "compliant". What a tool can do is remove the risk in the first place. Sift does that by design. The file you clean is processed entirely in your browser and is never uploaded, so Sift never receives the customer data inside it. If we never hold your data, there is nothing on our side to store, transfer across borders, expose in a breach, or hand over. That is the strongest privacy position a data tool can take, and it is verifiable, not just promised.
Open Sift and clean a list, free →
Most compliance worry with a data tool comes from one fact: you have to upload your list to it. The moment a spreadsheet of names, emails, and phone numbers leaves your device, you have to trust another company to store it safely, delete it when they say they will, keep it in an allowed region, and sign a data processing agreement that makes all of that binding. Sift avoids the entire problem by never receiving the file.
Sift is a static web app with no backend. When you drop in a CSV or Excel file, every step, profiling, cleaning, deduplication, mapping, scoring, and export, runs locally in your browser using your own device's processing. Your rows and cell values are never sent to a server, because there is no server to send them to.
The one place Sift does act as a data controller is the email address you choose to give it, covered below. Everything about the file you are cleaning stays with you.
There are exactly three things Sift collects, and none of them is your file:
What Sift never does:
Sift's analytics are configured to write nothing to cookies, local storage, or session storage for tracking. Unique visits are counted by a privacy-preserving server-side hash rather than a client-side identifier. Because no tracking cookie or identifier is ever set, there is no ePrivacy consent banner to show and nothing to opt out of. Your email address is never sent to the analytics tool. The only thing Sift keeps in your browser's local storage is your own saved cleaning pipelines, which stay on your device.
Because your file data never reaches us, there is nothing on our side to show, correct, or delete about the spreadsheets you clean. For the email address you may have given us, you have the usual rights: to see what we hold, correct it, or have it deleted. Email privacy@siftdata.app and we will act on it. The full detail is in the privacy policy.
The best part of this design is that you can check it in about two minutes rather than trusting a claim: