Privacy Policy
1. Who is responsible (controller)
The controller responsible for the Resift app and this website (tryresift.com / resift.app) is:
[FULL LEGAL NAME]
[STREET AND NUMBER]
[POSTAL CODE AND CITY], Switzerland
Email: privacy@tryresift.com
This policy is written to satisfy the duty to inform under the Swiss Federal Act on Data Protection (FADP/nFADP, Art. 19–21) and, for users in the European Union / EEA, Art. 13–14 of the EU General Data Protection Regulation (GDPR). Where a legal basis is required, we cite both the Swiss and the EU provision.
2. Scope
This policy covers:
- the Resift app for iOS and Android,
- the websites tryresift.com and resift.app (resift.app only redirects to tryresift.com), and
- email correspondence with us.
The rest of this policy is organised by activity: for each one it states what data is involved, why, on what legal basis, and who else receives it.
3. The app: local-first, nothing collected
Resift is a local-first application. Your saved items, decks, shopping runs, statistics, streaks, and settings are stored only on your device, in the app's sandboxed storage. There is:
- no account or registration system,
- no server operated by us that your data is sent to,
- no analytics, advertising, crash-reporting, or tracking SDK embedded in the app,
- no in-app third-party content (no embedded fonts, ads, or remote assets).
As a result, we do not collect, receive, or process any personal data through the app's normal operation — there is nothing to state on data, purpose, or retention, because no processing by us takes place. The corresponding Apple App Privacy label is "Data Not Collected", and the Google Play Data safety declaration (when Resift is offered there) is the equivalent "No data collected."
Deleting the app deletes your data. Retention is entirely under your control.
4. Reminders and notifications
If you allow notifications, Resift schedules its resurfacing nudges locally on your device using the operating system's local-notification facility. No push server — ours or a third party's — is involved, and no data leaves the device for this feature. You control the weekly notification budget in the app's settings and can revoke the notification permission at any time in your OS settings.
5. Links you open from the app
If you save a web link in Resift and open it (or if the app fetches a page title or preview image for a link you saved), your device contacts that third-party website directly, just as a web browser would. That website will see your IP address as part of the normal web request and is responsible for its own data processing. These requests do not pass through any server of ours, and we do not log or receive them.
If you prefer that the app never makes even these user-initiated requests, enable "100% offline mode" in the app's settings — it disables link previews entirely.
6. Purchases
Resift's one-time unlock (if and when offered — see section 4 and 5 of the Terms of Service) is sold through the app store you obtained Resift from:
- Apple App Store: Apple Distribution International Ltd. (or the Apple entity applicable to your region) is the merchant of record. Apple processes your payment data under Apple's privacy policy and handles billing, taxes, and refunds.
- Google Play (when Resift is offered there): Google processes your payment data under Google's privacy policy and handles billing and refunds under the Play terms.
In both cases the purchase is processed by the platform's native billing system (StoreKit / Play Billing) — we use no purchase middleware. We receive only aggregated, anonymised sales reports from the platforms — never your name, payment details, or address. Apple and Google act as independent controllers for the purchase, not as our processors.
7. Device backups and cloud services you control
Your device's operating system may include Resift's local data in device backups — for example an encrypted iCloud or computer backup (iOS), or a Google device backup (Android) — that you control through your Apple or Google account. These backups are governed by your agreement with Apple or Google; we have no access to them and cannot read, restore, or delete them.
8. This website
tryresift.com and resift.app are static websites. They set no cookies, run no analytics or JavaScript, and embed no third-party trackers, fonts, or scripts. That is why this site shows no consent banner — there is nothing to consent to.
The site is delivered by our hosting provider, [HOSTING PROVIDER, e.g. Cloudflare Pages], which technically processes your IP address and request metadata (standard server logs) for the sole purpose of delivering the site securely and defending against abuse. Log retention follows the provider's standard rotation; we do not enrich, analyse, or combine these logs with anything.
Legal basis: our overriding private interest in operating a secure website (Art. 31 para. 1 FADP); for EU/EEA users, legitimate interest (Art. 6(1)(f) GDPR).
9. Contacting us
If you email us (support, privacy, press, or security), we process the personal data you include — your email address and message content — solely to answer your request. We delete correspondence once it is no longer needed, unless a statutory retention duty applies.
Legal basis: our overriding private interest in responding to correspondence (Art. 31 para. 1 FADP); for EU/EEA users, legitimate interest (Art. 6(1)(f) GDPR) or steps prior to entering a contract (Art. 6(1)(b) GDPR).
10. No transfers abroad, no profiling
We do not transfer personal data abroad, because we do not collect it beyond the cases above. We do not use automated decision-making or profiling. Switzerland holds an EU adequacy decision, so any incidental EU↔Swiss data flow (e.g. an email you send us) requires no additional safeguard. If our hosting provider serves this website from infrastructure outside Switzerland/the EEA, that processing is limited to the delivery described in section 8 and is covered by the provider's standard contractual safeguards.
11. Your rights — and their honest limits
Under the FADP (Art. 25 ff.) and — if you are in the EU/EEA — the GDPR (Art. 15–22), you have the right to access, rectification, erasure, restriction of processing, data portability, and objection regarding personal data we process about you.
To be honest about what that means here: for everything you save in the app, we cannot grant access, export, correct, or delete anything — not because we refuse, but because we never have your data. You exercise those rights directly on your device: your content is yours, on your hardware; the app's export and delete functions and, ultimately, deleting the app itself are the effective remedies.
For the little we do hold (email correspondence, section 9), contact privacy@tryresift.com and we will answer within 30 days. You also have the right to complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or in the EU/EEA your local data protection authority.
12. Changes to this policy
If Resift ever changes in a way that affects data handling (for example, an optional sync feature), we will update this policy before the change ships and note it in the changelog. The "last updated" date above always reflects the current version. The German version (Datenschutzerklärung) is kept identical in substance; if the two ever diverge, the version in your language of use applies to you.