Privacy Policy
Effective Date: August 15, 2026
Unsift ("we," "our," or "the app") is a gift card scanning and management app developed by VakBridge Inc. This Privacy Policy explains how we collect, use, and protect your information when you use our app.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Display name (if provided)
- Authentication provider (Email, Google, or Apple)
Gift Card Metadata (Cloud-Stored)
When you scan a gift card, the following non-sensitive information is stored in our cloud database:
- Merchant name (e.g., "Amazon," "Starbucks")
- Card balance/amount
- Expiration date
- Barcode format type
- Date added
Sensitive Card Data (Device-Only)
The following sensitive information is stored exclusively on your device using your phone's secure hardware (iOS Keychain or Android Keystore) and is never transmitted to our servers:
- Card numbers
- PINs
- Claim codes
- Access codes
- Barcode values
Card Photos (Processed for Extraction)
When you scan a gift card, the photo is sent over an encrypted connection to Google's Gemini API to identify the fields printed on the card. This happens on every scan and is required for the app to read your card — it is not tied to the optional "Help Us Improve" setting.
The photo is sent through our own server, so your device never contacts Google directly and our API credentials are never exposed. We do not store your card photo: it is not written to our database or file storage, and no copy is kept after the scan.
Google does not use these images to train its models. Images are temporarily retained on Google's servers for up to 7 days for abuse monitoring, after which they are deleted automatically. You may contact us to request earlier deletion.
Anonymous Training Data (Optional)
If you opt in to "Help Us Improve," we collect anonymized scan data to improve our card recognition accuracy. This data is not linked to your account and includes:
- OCR text from scanned images
- Detected vs. confirmed merchant names
- Which fields were successfully detected (without the actual values)
- Scanned card images (anonymized)
- Extraction quality records — when we test a new extraction method we record whether the methods agreed on each field and which matched what you saved. These records contain merchant names and agreement results only, never card numbers, PINs, or codes, and are not linked to your account
Crash Reports
We use Firebase Crashlytics to collect anonymous crash reports to improve app stability. These reports include device type, OS version, and crash stack traces. They do not include any card data.
2. How We Use Your Information
- Provide the service: Store and display your gift card information across sessions
- Improve card recognition: Use anonymous training data (if opted in) to improve OCR accuracy
- Fix bugs: Use crash reports to identify and resolve app issues
- Authenticate you: Verify your identity to protect your data
- Read your cards: Send your card photo for automated field extraction so the merchant, card number, and codes can be filled in for you
3. How We Protect Your Information
- Sensitive card data (numbers, PINs, codes) is encrypted using your device's hardware-backed secure storage (iOS Keychain / Android Keystore) and never leaves your device
- Cloud data is encrypted in transit (TLS) and at rest (Google Cloud infrastructure)
- Biometric authentication (Face ID, Touch ID, Fingerprint) protects access to sensitive card details
- Firestore security rules ensure each user can only access their own data
4. Third-Party Services
We use the following third-party services:
- Firebase Authentication - User sign-in and account management (Firebase Privacy)
- Cloud Firestore - Cloud storage for non-sensitive card metadata
- Firebase Crashlytics - Anonymous crash reporting
- Firebase Storage - Anonymous training image storage (opt-in only)
- Google ML Kit - On-device text recognition and barcode scanning only — the image never leaves your phone for this step
- HF Spaces NER API - When you scan a card, the raw OCR text (which may include card numbers and PINs) is sent over HTTPS to our named-entity recognition model hosted on Hugging Face Spaces for real-time field extraction. The server processes the text immediately and does not log or store request bodies. This service is operated by VakBridge Inc.
- Google Sign-In - Optional authentication method
- Apple Sign-In - Optional authentication method (iOS only)
- Google Gemini API - Card photos are sent through our server to Google's Gemini API for real-time field extraction on each scan. Images are not used to train Google's models and are retained for a maximum of 7 days before automatic deletion. This call is made server-side by Vakbridge.
5. Data Sharing
We do not sell, trade, or share your personal information with third parties. Your data is only shared with Google's Gemini API via card images for processing and Firebase/Google Cloud as our infrastructure provider to operate the service.
6. Your Rights and Choices
- Opt out of data collection: You can disable anonymous training data collection at any time in Settings > Privacy & Data
- Delete your cards: You can delete individual gift cards from the app at any time. This removes both cloud metadata and on-device sensitive data
- Delete your account: You can request full account deletion by contacting us at the email below. We will delete all associated data from our servers
- Access your data: You can view all your stored card information within the app at any time
7. Data Retention
- Account data: Retained as long as your account is active. Deleted upon account deletion request
- Card metadata: Retained until you delete the card or your account
- Sensitive card data: Stored on your device only. Lost if you uninstall the app or switch devices
- Anonymous training data: Retained indefinitely to improve the service. Cannot be linked back to you
- Crash reports: Retained for 90 days
8. Children's Privacy
Unsift is not directed at children under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided personal information, we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Effective Date" at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact Us