Privacy Policy for Cift

Last Updated: October 29, 2025
Effective Date: October 29, 2025

Introduction

Cift is a privacy-first task and event management app. Your data stays on your device. This privacy policy explains how Cift protects your information.


What Cift Does NOT Do


How Your Data Stays Private

On Your Device

Voice Input

Local Storage Only


Temporary Processing by OpenAI

When you create tasks or events, Cift sends your text to OpenAI's API for intelligent parsing and categorization.

What This Means:

OpenAI Privacy & Policies:


What Data Passes Through Cift's Backend

Cift's backend server acts as a secure proxy between your device and OpenAI:

Data Flow:

  1. You create a task/event on your device
  2. Text is sent via HTTPS to Cift's server
  3. Cift's server forwards it to OpenAI for processing
  4. OpenAI returns structured data (task details, categories, etc.)
  5. Cift's server sends the result back to your device
  6. Your device encrypts and saves the data locally

Backend Privacy Measures:


Data Security

Security Measure Implementation
Encryption at Rest AES-256-GCM on device
Encryption in Transit HTTPS/TLS 1.3
Key Storage iOS Keychain (hardware-backed)
Server Storage None - processed in memory only
Rate Limiting 1000 requests per 15 minutes (prevents abuse)

Your Rights and Control

Access Your Data

All your data is on your device. You can view, edit, and manage it anytime in the app.

Export Your Data

Delete Your Data

Manage Permissions


Third-Party Services

OpenAI

Apple Services

No Other Third Parties: Cift does not use analytics, crash reporting, or advertising services.


Children's Privacy

Cift does not knowingly collect information from children under 13. The app is designed to store all data locally on the user's device.

If you are a parent or guardian and believe your child has used the app, you can simply delete the app to remove all data.


International Users

Cift's backend server is hosted in the United States. When you use AI features, your task/event text is temporarily transmitted to the US for processing.

Your data is protected by:


Changes to This Privacy Policy

Cift may update this privacy policy occasionally. Changes will be communicated through:

Continued use of Cift after changes indicates acceptance of the updated policy.


Data Retention

Data Type Retention Period
On Your Device Until you delete it or uninstall the app
Cift's Server Not stored (processed in memory only)
OpenAI Processing Temporary (per OpenAI's API data retention policy)
Backups Encrypted data may be in your iCloud/iTunes backups

Legal Compliance

GDPR (European Users)

Cift respects your rights under the General Data Protection Regulation:

CCPA (California Users)

Data Processing Basis


Security Incident Response

In the unlikely event of a security breach:

  1. Affected users will be notified promptly
  2. Steps to protect your data will be communicated
  3. The issue will be resolved immediately

Note: Since Cift does not store your data on servers, the risk of a server breach affecting your data is minimal.


Contact Information

If you have questions about this privacy policy or Cift's privacy practices:

Email: ciftdev@gmail.com


Technical Details for Transparency

Encryption Specifications

Network Security

Data Format


Summary

Cift prioritizes your privacy:


By using Cift, you agree to this privacy policy.