Skip to content

Privacy Policy

Last updated: 30 August 2026

Who this covers

Sift is a local events app for the Isle of Man. This policy covers everyone who uses Sift: people browsing and saving events, and organizers who connect a Facebook Page. It applies to the website, the installed app (PWA/home-screen), and any Sift app listed on the App Store or Google Play.

What we collect and why

  • Account.Your email address, used to send a one-time sign-in code. If you set up a passkey, your device stores the passkey — we only store a reference to it, never anything that could be used to impersonate you. You can also sign in with Google or Apple instead of, or in addition to, email — we receive your basic profile (email, name) from whichever you use, and if you sign in with Google using the same email as an existing account, it's automatically linked to that one account rather than creating a second one.
  • Saved events, filters, and preferences. What you save, your search presets, and your theme choice, so they follow you across devices.
  • Calendar feed. A private link that lets your calendar app subscribe to your saved events. We only ever store a hash of this link, never the link itself.
  • Push notifications.If you turn notifications on, your browser/device gives us a subscription address so we can send alerts when a saved event changes. We never see the content of the notification before it's delivered, and turning notifications off deletes this immediately.
  • Organizer / Facebook Page data.If you connect a Facebook Page, we use Facebook's official Graph API (never scraping, and only with your explicit opt-in) to read that Page's public posts and images, so we can extract event details. We store the Page's public posts, extracted event data, and a Page access token (kept server-side only, never exposed to any browser). If you chose to grant access to “all current and future Pages” in Facebook's own connection dialog, we also keep your Facebook access token on file (same server-side-only protection) so we can periodically check for a new Page you've since become an admin of and add it automatically, without you having to reconnect. We do not request or store your personal Facebook profile, friends list, or private messages, and we never store the identity of anyone who comments on a Page's posts.
  • Reports. If you report an event or an issue, we keep the report and your account reference so we can follow up.

Who we share data with

We use a small number of service providers to run Sift, and only share what each one needs to do its job: Supabase (database, file storage, sign-in), Vercel (hosting), Meta/Facebook's Graph API (for organizers who connect a Page), our configured AI provider (to read post text and poster images and turn them into structured event data), Resend (sign-in emails and organizer digest emails), and OpenStreetMap's Nominatim service (to look up map coordinates for a venue's address — never anything about you personally). We do not sell your data, and we do not run advertising or third-party tracking. If you choose to sign in with Google or Apple, that provider is also involved solely to authenticate you.

How long we keep it

Account-linked data (saved events, preferences, push subscriptions) is kept until you delete your account or remove it yourself. A connected Page's published events stay visible — they're public event listings, not personal data about you — until 45 days after the event ends, at which point the full event record and its poster image are deleted; organizers keep a lightweight stats summary (title, date, how many people saved it) so they can still see how a past event performed. A connected Page's access token is revoked immediately on disconnect; your own Facebook account-level token (only kept if you granted “all current and future Pages”) is kept until Facebook revokes it, you delete your account, or you remove Sift from your Facebook settings.

Your rights

Under UK/EU data protection law you can access, export, correct, or delete your data, and withdraw consent at any time.

  • Delete your account any time from Settings → Danger zone.
  • Disconnect a Facebook Page any time from your organizer dashboard.
  • Turn off push notifications any time from Settings.
  • Remove a connected Google or Apple sign-in method any time from Settings, as long as another sign-in method remains on your account.
  • To export a copy of your data, or for anything else, contact us (see below) — we'll respond within 30 days.

Facebook data deletion

If you remove Sift from your Facebook app settings, Facebook notifies us automatically and we delete the Facebook data tied to your connection. You can also request deletion directly by contacting us.

Contact

Questions or requests about your data: use the "Contact us" form in Settings, or email the address listed in the app's support contact.

Changes to this policy

  • 30 August 2026We now generate two automatically-cropped versions of each event poster (one for the event card, a taller one for the homepage carousel) instead of one, so images fit their space cleanly. These are just resized copies of a picture we already store — nothing new is collected and no other company receives it.
  • 29 August 2026For events created directly on a connected Facebook Page, we now also keep the map coordinates Facebook provides for the event's venue, alongside the venue name and address we already stored from the same place. It's used to put the venue on the map correctly; it's the location of a public venue, not of any person, and no new company receives it.
  • 28 August 2026The "My data" export/download no longer lists the individual in-app notifications you've received — it still includes your notification delivery preferences (which types you've turned on for in-app/push/email). Your notification feed itself is unchanged and still available from the bell icon.
  • 25 August 2026Removed the accessibility-profile (easy-reader/dyslexia-friendly/colorblind-safe/high-contrast) and larger-touch-targets settings — the display settings page is now just a theme picker (System/Light/Dark). We no longer store either of those two settings for anyone.
  • 23 August 2026Added the groundwork for notifications in our iOS and Android app (as opposed to notifications in your mobile browser, which already worked). If you turn notifications on in the app, we'll store a device identifier so Apple's or Google's notification service can deliver alerts to your device — the same information already involved in browser notifications, just delivered a different way.
  • 22 August 2026Added a region switcher so you can browse events, the map, and prices for a different territory than your default. Your choice is saved to your account (or, if you're not signed in, a cookie). We can also suggest a starting region using your device's location, if you allow it — the location itself is never stored, only the region it resolves to. This also covers the Map tab's existing "locate me" button, which used the same browser location permission but wasn't previously listed here.
  • 20 August 2026Removed the "Go Pro" paid subscription feature, which was never launched to users. Stripe is no longer a data processor — we no longer keep a Stripe customer id or subscription status for anyone.
  • 18 August 2026Reports can now be filed about a venue's own listing, not just an event or the app in general — same reporter/message data as other reports, reviewed the same way.
  • 17 August 2026Venues can now have an admin-uploaded photo, shown on the venue directory and event cards — not a photo of any individual, just the venue itself. No new processor: it's stored the same way as event poster images, and a cropped display version is produced by a self-hosted process, not a third-party image service.
  • 16 August 2026All 5 notification types in Settings → Notifications now actually deliver, on whichever of in-app/push/email channels you turn on per type — previously only "Saved Events updates" delivered, and only to in-app/push. No new processor: email still goes through Resend, same as every other email Sift sends.
  • 15 August 2026Connected Pages' public website, phone number, contact email(s), Facebook link, "about" description, business hours, and a downloaded copy of their profile picture/avatar now refresh automatically when an organizer edits them on Facebook, not just when they reconnect — same Facebook connection and data already covered, no new permission requested.
  • 15 August 2026Connected Pages now also store the Page's public website, phone number, contact email(s), Facebook link, and "about" description, straight from the same Facebook connection an organizer already granted — shown on the organizer dashboard and a Page detail view so organizers with access to a Page can see its public contact details alongside its events.
  • 14 August 2026For organizers who chose Facebook's "all current and future Pages" access option, Sift now periodically re-checks which Pages they administer and can add a newly-covered one automatically, so it no longer requires reconnecting by hand. This uses a Facebook access token we now keep on file for that purpose, stored the same securely-locked-down way as a connected Page's own access token.
  • 13 August 2026Added an in-app notification feed (bell icon) and per-notification-type delivery preferences (in-app/push/email) in Settings → Notifications.
  • 13 August 2026Venue pages now show whether a venue has a connected organizer Page. Signed-in users can flag interest in an unconnected venue to help us prioritize outreach; admins see how many people asked, never who.
  • 12 August 2026Added a Map tab showing events on a map of the Isle of Man. Venue addresses are sent to OpenStreetMap's Nominatim service to look up coordinates — venue location data only, never anything about an individual user.
  • 12 August 2026Reports now record a selected reason category, and are automatically deleted 90 days after an admin closes them (previously kept indefinitely). An admin closing a report as "won't fix" can optionally email the submitter a written explanation.
  • 12 August 2026Event cards now show an aggregate reaction (like) count polled from the source Facebook post, when there is one — an aggregate total only, never who reacted.
  • 11 August 2026Event extraction can now also pick up a booking phone number or email address when a post/poster states one, and shows it on the event page — same 45-day retention as the rest of the event record.
  • 11 August 2026Past events are now deleted (not just their poster images shrunk) 45 days after they end; organizers keep a lightweight stats snapshot (title, date, save count) instead of the full event record.
  • 9 August 2026Added Google and Apple sign-in as optional alternatives to magic-link email sign-in.
  • 8 August 2026First published version.