Legal

Privacy Policy

This policy explains what Siftum collects, why we use it, and the choices available to you.

Effective September 4, 2026

Who we are

Siftum is a shopping assistant operated by Ditat Advisory LLC in the United States. This policy applies to siftum.com and the Siftum shopping agent.

Information we collect

  • Account and verified email information supplied through Clerk.
  • Shopping conversations, product references, and agent session history.
  • Subscription status, usage allowances, and Stripe customer identifiers.
  • Request counts, model token totals, and technical error diagnostics.
  • Account-linked interaction counts, such as starter choices, refinements, likes, skips, and merchant-link clicks.
  • Basic device, browser, network, and security information in service logs.

Stripe processes payment card details. Siftum does not receive or store your full card number. Likes and skips shown as session-only preferences are not saved as a persistent preference profile. Interaction analytics do not contain your prompts, product identifiers, product titles, or merchant URLs. Application error reports contain only error categories, not raw error messages or stack traces.

How we use information

We use information to authenticate users, answer shopping requests, retrieve products, operate subscriptions and limits, prevent abuse, troubleshoot failures, understand service usefulness and cost, and comply with legal obligations. We do not sell personal information or use it for targeted advertising.

Service providers and merchants

We use Clerk for authentication, Stripe for billing, Neon for application data, Vercel and AI Gateway for hosting and model access, Eve for the agent runtime, and Shopify for catalog results. When you follow a product or checkout link, the merchant receives information under its own privacy terms.

Retention and security

We retain data while your account is active and as reasonably needed to run the service, resolve disputes, secure the product, and meet legal obligations. We use access controls and managed infrastructure to protect data, but no online service can guarantee absolute security.

Interaction analytics are automatically deleted after 90 days. Aggregated application error categories are deleted after 30 days without a new occurrence. Billing, usage audit records, conversations, and infrastructure logs have separate operational and legal retention requirements.

Your choices

You can manage billing through the Stripe portal. To request access, correction, or deletion of account data, email support@siftum.com. We may need to verify your identity and retain records required by law.

Children and changes

Siftum is not directed to children under 13. We may update this policy as the service changes and will post the revised effective date here.