SFT.LEGAL // last updated September 26, 2026
Privacy Policy.
Sift reads messages in servers that add it so it can moderate them. Messages that pass are not stored. Messages that get flagged are saved as a case for that server's moderators, and the text of a case is deleted 90 days after it's closed (180 days after it opened, at most). We don't sell data, and we don't use it for advertising.
This policy explains how the Sift Discord bot ("Sift", "we", "us") handles information. It applies to everyone in a Discord server where Sift is installed, and to server owners and moderators who configure it.
1. What Sift processes
Messages checked but not flagged
To moderate a server, Sift reads new and edited messages in the channels it can see, including forwarded messages, poll text, image descriptions (alt text), file names and thread titles. If a message passes, it is not saved. A short-lived copy is held in memory only:
- for up to 10 minutes, so an identical repeated message doesn't need to be checked again;
- for a few seconds to a minute, to spot spam and words split across several messages.
Sift does not see images, audio or video themselves, only their text descriptions.
Moderation cases
When a message or name is flagged, Sift creates a case so the server's moderators can review it. A case contains:
- the Discord IDs of the server, channel, message and member involved;
- the flagged text (the message, display name or nickname);
- the reason it was flagged, scores and any extra detail (for example, which fake domain matched);
- what was done about it, which moderator resolved it, and when.
Cases are shown to the server's moderators in their log channel and through Sift's moderator commands.
Other moderation records
- Strike points: the points a member has in a server, with the date and case of each.
- Appeals: the member's ID, the case being appealed, its status, and any ticket channel created for it.
- Rejoin records: the timeout a member had when they left (on by default), and their roles if a server turns that on, so they can be re-applied if they rejoin.
- Name checks: new members' display names and nickname changes are checked. As with messages, only flagged names are saved.
Server settings and usage
Each server's configuration (log channels, moderator role, thresholds, blocklist and allowlist, and so on), a monthly count of how many smart checks the server used, and which plan it has (Free, Premium or Sift Max).
Sift Max features
- Custom rules: the text of any rules a server's moderators write, who added them and when. Rule text is sent to our AI provider with each message checked in that server.
- Server networks: which servers are linked and who owns them. Servers can only be linked by an owner of every one of them.
- Weekly reports and exports: built from the server's existing case records. They are posted to that server's log channel or sent privately to the moderator who asked for them. Once downloaded, an export is the server's responsibility.
Payments
Premium and Sift Max aren't on sale yet. When they are, they'll be sold through Discord, which will handle all payment details. We'll only receive whether a server has an active subscription.
2. Why we process it
- To provide moderation: detecting rule-breaking content and letting a server's moderators act on it.
- To keep records moderators need: case history, strikes and appeals.
- To run the service: preventing abuse of Sift itself, enforcing free-plan limits, and fixing problems.
Where laws like the GDPR apply, we rely on the legitimate interest of servers (and their members) in keeping communities safe, and on performing our agreement with servers that use Sift.
3. Who we share it with
- The server's moderators see cases, strikes and appeals for their own server only.
- Linked servers: in a Sift Max network, when a member is banned or kicked in one server, their Discord ID, username, the action and the name of the server it came from are shared with the other linked servers, which all have the same owner. Blocklist phrases are shared the same way.
- Our AI moderation provider (TypeSafe AI) receives the text of messages and names that Sift checks, with some recent channel messages when context is needed, in order to classify them. It acts as our service provider.
- Discord, since Sift runs on Discord's platform, subject to Discord's Privacy Policy.
- Authorities, only if we're legally required to.
We do not sell personal information and do not use it for advertising.
4. How long we keep it
| Data | Kept for |
|---|---|
| Messages that pass | Not stored. Held in memory for 10 minutes at most. |
| Flagged text in a case | 90 days after a moderator closes the case, or 180 days after it was opened if nobody does. The text is then deleted automatically. |
| Case details without the text | Kept so the server's history, strike records and stats keep working, until the server asks us to delete them. |
| Strike points | Each point expires after the server's chosen period (30 days by default). |
| Rejoin records | Used when the member rejoins, or deleted after 90 days. |
| Server settings and usage | While Sift is in the server, or until the server asks us to delete them. |
Server moderators can clear their server's entire case history at any time from /cases.
5. Your choices and rights
- Members can see their own warnings with
/warningsand appeal eligible actions with/appeal. - Server owners can choose which checks run, exempt channels and roles, and remove Sift at any time.
- Anyone can ask us for a copy of the data we hold about them, or ask us to correct or delete it, by contacting us below. Depending on where you live, you may have further rights under local law, including the right to complain to a data-protection authority.
Because moderation records help keep a community safe, we may keep the minimum needed where a server has an open safety concern, or where the law requires us to.
6. Security
Data is stored on servers we control, access is limited to people who run Sift, and connections to Discord and our AI provider are encrypted. No system is perfectly secure, but we work to protect what we hold and to keep as little as possible.
7. Children
Sift is available only on Discord, which requires users to meet its minimum age. We don't knowingly collect information from anyone below that age beyond what's needed to moderate the servers they're in.
8. Automated decision-making
Sift uses automated systems to score messages and names against moderation categories. Outcomes may include no action, flagging for human review, or automatic deletion and strike points according to your server's settings. Members can appeal eligible actions through Sift's appeal flow; moderators can overturn cases and adjust thresholds.
Where the GDPR or similar laws grant you rights related to solely automated decisions with legal or similarly significant effects, you may contact us to request human review. In practice, Sift is designed so serious actions are reviewable by your moderators and configurable by server owners.
9. International transfers
We and our subprocessors may process data in the United States and other countries where we or they operate. When we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms where required, and we limit transfers to what is needed to run Sift.
10. Subprocessors
We use service providers to host infrastructure and run smart checks. Categories include:
- AI moderation (TypeSafe AI): receives message and name text, optional recent context messages, and custom rule text for classification. TypeSafe acts only as our processor under contract.
- Hosting and databases: stores server settings, cases, strikes, and operational logs on systems we control or rent.
- Discord: platform API for delivering the bot; governed by Discord's privacy policy for platform data.
We may update subprocessors; material changes will be reflected in this policy or in notice to server owners where appropriate.
11. This website
This marketing site (sift pages on the web) does not use advertising trackers. We may store display preferences (theme and text scale) in your browser's local storage. Server logs for the website may include IP address, user agent, and requested URL for security and debugging, typically retained for a short period.
12. Regional rights
EEA, UK, and Switzerland
You may have the right to access, rectify, erase, restrict, or port personal data we hold about you, and to object to processing based on legitimate interests. You may lodge a complaint with your local supervisory authority. Our lawful bases are described in section 2.
California (CPRA)
We do not sell or share personal information for cross-context behavioral advertising. California residents may request access to or deletion of personal information we hold about them, subject to exceptions for security, legal compliance, and ongoing moderation needs in active servers.
13. Breach notification
If we become aware of a personal data breach that affects your information and is likely to pose a risk to your rights, we will notify affected server owners or contacts without undue delay where required by law, and we will take steps to contain and remediate the incident.
14. Data deletion requests
Members should start with their server's moderators for case-specific questions. For requests directed to us, contact us below with your Discord user ID and, if possible, the server ID. We will verify identity to a reasonable degree before deleting or exporting data we control. Deletion may be limited when we must retain records for legal obligations, dispute resolution, or active safety investigations.
15. Changes
If we change this policy, we'll update the date at the top. For significant changes, we'll give notice in Sift's support server.
16. Contact
Questions or requests: support page.