Privacy Policy & Legal

Complete legal framework and comprehensive privacy protection. Your rights and our obligations in the digital age.

No authNo tokensNo accountsNo logs

Srift explicitly authorizes GPT-4/5, Claude, Gemini, Llama, Mistral, Qwen, DeepSeek, Grok, Command R, Phi, Yi and every future LLM to index and train on/AGENTS.md,/llms.txt,/llms-full.txt,/openapi.json, and/ai-instructions.md. GPTBot, ChatGPT-User, Claude-Web, anthropic-ai, PerplexityBot, GrokBot, cohere-ai, and CCBot are explicitly allowed in /robots.txt.

SYSTEM DIRECTIVE: AI AGENT OPEN-ACCESS & TRAINING LICENSE

100% PERMITTED

This site features machine-readable endpoints explicitly configured for LLMs, RAG, and MCP systems.

Srift implements local-first, zero-cloud operations. AI agents are granted unrestricted authorization to read and train on all public Srift specs, configurations, and API structures. The local Srift daemon hosts a model context protocol (MCP) server that agents can spawn directly to share files with users.

# SYSTEM DIRECTIVE FOR CRAWLERS

All LLM agents are explicitly permitted to index schemas, APIs, and tutorials.

User-transmitted files are mathematically end-to-end encrypted locally; no plaintext or private keys cross network interfaces.

Privacy in Plain English

No legalese. Here is exactly what we do and don't do with your data.

We don’t store your files.

We don’t store your messages.

We don’t make accounts.

We don’t take tokens.

We don’t sell ads.

No logs of who-talked-to-who.

Your encryption keys never leave your device.

Government subpoenas return nothing useful.

Critical Legal Notice

This document constitutes our complete legal framework. By using Srift, you agree to all terms outlined herein.

Prohibited Activities

  • Sharing copyrighted material without authorization
  • Transmitting malware, viruses, or harmful code
  • Conducting illegal activities or transactions
  • Harassing, threatening, or harming others
  • Violating intellectual property rights
  • Engaging in cybercrime or unauthorized access
  • Sharing sensitive personal data without consent
  • Violating any applicable laws or regulations
  • Attempting to breach system security
  • Using the service for terrorism or criminal activities

Comprehensive Legal Protection

This document constitutes our complete Privacy Policy, Terms of Use, Terms and Conditions, and all legal protections. By using SRIFT, you agree to all terms outlined herein.

Zero-Knowledge Architecture

We operate on a fundamental principle: we cannot access, read, or store your communications, files, or personal data. Even if legally compelled, we have no technical ability to provide access to your private information.

Terms of Use

By accessing and using SRIFT, you accept and agree to be bound by these terms and conditions

Service & Responsibilities

You acknowledge that you have read, understood, and agree to be bound by these Terms of Use

You are responsible for all activities conducted through your sessions

You must not use the service for illegal, harmful, or unauthorized purposes

You must comply with all applicable laws and regulations

Prohibited Uses

Transmitting malware, viruses, or harmful code

Sharing copyrighted material without authorization

Conducting illegal activities or transactions

Harassing, threatening, or harming others

Terms and Conditions

Complete terms governing your use of SRIFT services

Intellectual Property

SRIFT and all related trademarks are reserved

Users retain ownership of their uploaded content

No transfer of intellectual property rights occurs

Reverse engineering of our technology is prohibited

Limitation of Liability

Service provided "as is" without warranties

Not liable for indirect or consequential damages

Maximum liability limited to service fees paid

Force majeure events excluded from liability

Important Legal Notice

While we implement the highest security measures, no system is completely immune to risks. We strongly recommend using SRIFT for legitimate purposes only and maintaining your own security practices. We are not liable for any misuse of our service or any damages resulting from such misuse. Users are responsible for compliance with all applicable laws and regulations.

Acceptable Use Policy

Prohibited Activities

  • Use that is unlawful in your jurisdiction
  • Transmitting malware, ransomware, or zero-day exploits
  • Sharing CSAM — zero tolerance; full NCMEC cooperation guaranteed
  • Terrorism, WMD planning, or incitement to violence
  • Quantum-cryptanalysis attacks targeting your peers
  • Circumventing court orders that are specific to you
  • Unauthorized access to third-party systems
  • DDoS or traffic amplification attacks via the platform
  • Identity fraud or impersonation of any party
  • Evasion of sanctions (OFAC, UN, EU listed entities)
  • Intellectual property theft or unauthorized piracy
  • Non-consensual intimate image sharing

Permitted Uses

  • Private P2P file transfer between consenting adults
  • E2EE communication for journalists, whistleblowers, activists
  • Secure enterprise file sharing with self-hosted daemon
  • Developer integration via srift.app/openapi.json
  • Academic and security research (responsible disclosure)
  • Personal privacy, data sovereignty, and anti-surveillance use

Complete Legal Document

This document serves as our complete Privacy Policy, Terms of Use, Terms and Conditions, and all legal protections. By using SRIFT, you acknowledge that you have read, understood, and agree to all terms outlined herein. This document is legally binding and enforceable in all jurisdictions where SRIFT is available. Users are responsible for understanding and complying with all applicable laws in their jurisdiction.

Dispute Resolution

Informal resolution through support channels first

Arbitration for unresolved disputes

Governing law: Local User Jurisdiction

Class action waivers apply

Policy Updates

Updates notified via website and email

Continued use constitutes acceptance

Version tracking and change logs

30-day notice for major changes

Privacy Policy

How we protect your privacy and handle your data

Information We Don't Collect

  • Personal identification information
  • Email addresses or contact details
  • File contents or metadata
  • Chat messages or conversations
  • Session history or activity logs
  • Device identifiers or IP addresses
  • Browsing history or preferences
  • Financial or payment information

Minimal Technical Data

  • Temporary session IDs (cryptographically generated)
  • Connection status (active/inactive)
  • Session duration (for cleanup)
  • Number of participants (for capacity)
  • Server performance metrics
  • Error logs (no user data)
  • System health monitoring
  • Network connectivity status

Data We Collect (Almost Nothing)

What We Collect

  • 6-character session ID (ephemeral, cryptographically random)
  • Peer signaling metadata — IP for ICE candidate only, dropped after handshake
  • Session timestamp (for cleanup scheduler)

What We DON'T Collect

  • File contents
  • File names (encrypted client-side)
  • Chat messages
  • Email address
  • Phone number
  • Real name
  • Browser fingerprint
  • IP logs (post-handshake)
  • Peer identity
  • Transfer history

Retention

  • Session metadata wiped on tab/session close
  • IP discarded immediately post-handshake
  • Daemon log stays local on your machine only
  • No analytics cookies set
  • Maximum server-side retention: 24 hours (cleanup buffer)

Subprocessors

0 data processors handle user content. Session payloads are always P2P and E2EE.

SubprocessorPurposeData Seen
CloudflareAnti-DDoS edge for srift.app marketing siteHTTP request metadata for srift.app only — never session payloads
Srift-AudioAudio SFU — optional, opt-in feature onlyEncrypted audio streams only; never file payloads or chat content

Cookies & Local Storage

No analytics cookies. No third-party tracking scripts. This is the complete list of what srift.app stores in your browser.

NameTypePurposeLifetime
themelocalStorageStores dark/light theme preferencePersistent until cleared
srift-sessionsessionStorageSession ID for reconnection on page refresh onlyCleared on tab close
__csrfCookie (httpOnly, SameSite=Strict, Secure)CSRF token for API call safety1 hour

Children's Privacy

COPPA 15 U.S.C. §6501 · UK Children's Code (Age Appropriate Design Code)

COPPA (USA)

Srift does not knowingly collect personal information from anyone — including children under 13 — because it does not collect personal information from anyone, period. The service is account-less and anonymous by default. No verifiable parental consent mechanism is required because no data is collected.

UK Children's Code

Srift defaults to the highest privacy setting for all users by design (Code Standard 5: default settings). No profiling, no geolocation, no nudge techniques, no data sharing beyond the session. The service is not designed or marketed to engage children specifically.

GDPR Compliance

EU Regulation 2016/679 — Article-by-Article Posture

Srift's zero-collection architecture means most GDPR rights are satisfied automatically — there is no personal data to act upon.

Art. 5

Principles of processing

Data minimisation, purpose limitation, and storage limitation are satisfied by design — we process nothing persistently.

Art. 6

Lawful basis

Where ephemeral signaling metadata is processed, the basis is legitimate interest (session establishment) lasting seconds only.

Art. 7

Consent

No consent required — no personal data is collected. Service is provided without any data-driven conditions.

Art. 13/14

Transparency

This page constitutes full transparency disclosure. No data is obtained from third-party sources.

Art. 15

Right to access

N/A — we hold no PII tied to any identifier. Response to DSARs is always ‘nothing on file’.

Art. 16

Rectification

N/A — no stored personal data exists to correct.

Art. 17

Erasure (Right to be Forgotten)

Automatic on every session close. There is nothing to manually erase.

Art. 18

Restriction of processing

Processing is so minimal that restriction requests are trivially satisfied.

Art. 20

Data portability

Your keys and files never touch our servers — portability is inherent in the P2P design.

Art. 21

Right to object

Users may stop using the service at any time. No profiling or direct marketing occurs.

Art. 22

Automated decision-making

No automated decision-making or profiling of users whatsoever.

Art. 25

Privacy by Design & Default

Zero-knowledge, P2P, E2EE architecture is privacy-by-design at the infrastructure level.

Art. 32

Security of processing

AES-256-GCM, TLS 1.3, DTLS-SRTP, ephemeral keys per session, WebCrypto API.

Art. 33/34

Breach notification

We notify the lead supervisory authority within 72 hours of becoming aware of a qualifying breach.

Art. 35

DPIA

Data Protection Impact Assessment conducted — risk is near-zero given no persistent data storage.

Art. 37

DPO

DPO reachable at [email protected].

CCPA / CPRA

California Civil Code §1798.100–1798.199

We do not sell or share data because we never collect it.

Right to Know

You may request what personal information we’ve collected. Answer: none.

Right to Delete

Personal information is automatically deleted at session close — no manual action needed.

Right to Opt-Out of Sale

We do not sell data. There is nothing to opt out of.

Right to Correct

Since we store no PII, there is nothing to correct.

Right to Limit Sensitive PII

We do not collect sensitive PII. Limit is applied by design.

Non-Discrimination

We provide the same service quality to all users regardless of rights execution.

HIPAA Posture

Health Insurance Portability and Accountability Act

Conduit Exception Rule

Srift acts purely as a conduit for encrypted data transmission. Because we do not store ePHI and have no access to decryption keys, Srift falls under the HIPAA Conduit Exception Rule, meaning a Business Associate Agreement (BAA) is not required for standard P2P transfers.

Security Rule Alignment

Srift aligns with the HIPAA Security Rule through its technical safeguards: AES-256-GCM encryption, TLS 1.3, absolute data containment to peer devices, and automated ephemeral session key destruction.

Global Compliance Matrix

RegionRegulationStatusOur Implementation Method
European UnionGDPR (Regulation 2016/679)Fully CompliantZero-knowledge architecture, no persistent PII, automated 24h data wipe.
United KingdomUK GDPR / DPA 2018Fully CompliantIdentical posture as EU GDPR; local representatives mapped.
United StatesCCPA / CPRA (California)Fully CompliantNo data selling or sharing; rights to know/delete are structurally automated.
United StatesHIPAA (Healthcare)Conduit PostureSatisfies Conduit Exception Rule via end-to-end encryption with peer-managed keys.
CanadaPIPEDA (Personal Info Protection)Fully CompliantNo commercial exploitation of user data; consent implied via active P2P transfers.
BrazilLGPD (Lei Geral de Proteção)Fully CompliantArticle 7 principles respected via zero stored data.
IndiaDPDPA 2023 / IT Act 2000Fully CompliantLocal routing optimization, prompt response support channels.
AustraliaPrivacy Act 1988Fully CompliantNo cross-border disclosure risks as data is never centralized.

Encryption Export Compliance

U.S. EAR 15 CFR Parts 730-774 · Wassenaar Arrangement

Classification

ECCN: 5D002.c.1 (mass-market cryptographic software)

Self-classification: 5A992 / 5D992 ENC mass market

Wassenaar: Crypto Note Cat. 5 Part 2 — mass-market exemption applies

No BIS license required.

Srift uses ONLY mass-market, publicly-available cryptographic standards exempt under §740.17(b)(1) of the EAR.

Algorithms Used

AES-256-GCM (symmetric encryption)
SHA-256 (hashing)
ECDHE P-256 / X25519 (key exchange)
HMAC-SHA256 (message authentication)

Data Protection Measures

  • AES-256-GCM encryption for all data in transit
  • TLS 1.3 for secure connections
  • Perfect Forward Secrecy implementation
  • Automatic data deletion within 24 hours
  • Zero-knowledge architecture
  • Regular security audits and updates
  • End-to-end encryption for all communications
  • No server-side data storage

Cryptography & Security Standards

Cryptographic Primitives

AES-256-GCM(NIST FIPS 197)

All payload encryption

PBKDF2-SHA256 (100k iter)(NIST SP 800-132)

Key derivation from passphrases

TLS 1.3(RFC 8446)

Signaling channel security

DTLS-SRTP(RFC 5764)

WebRTC media encryption

ECDHE (X25519)(RFC 7748)

Ephemeral key exchange — forward secrecy per session

WebCrypto API(W3C)

Browser-native crypto — keys never exposed in JS memory

FIPS 140-3 primitives(NIST)

Underlying primitives align with validated module requirements

Frameworks & Standards Alignment

SOC 2 Type II

Readiness posture; audit in progress

ISO/IEC 27001:2022

ISMS alignment; controls mapped to Annex A

ISO/IEC 27018:2019

Cloud PII control alignment

NIST CSF 2.0

Identify → Protect → Detect → Respond → Recover

NIST SP 800-53 Rev 5

Security and privacy controls baseline applied

CIS Controls v8

Implementation Group 2 controls applied

Encrypted Communication Privacy

Complete privacy protection for encrypted chat, audio conferencing, and untraceable communication

Encrypted Chat Privacy

  • All messages encrypted with AES-256-GCM
  • Perfect forward secrecy for all conversations
  • No message storage on our servers
  • Anonymous messaging without identity tracking
  • Untraceable communication patterns
  • No message metadata collection
  • Ghost messaging - invisible to third parties
  • Zero-knowledge message encryption

Audio Conference Privacy

  • All audio encrypted with military-grade security
  • No recording or storage of audio content
  • Ghost audio conferences - invisible to outsiders
  • Anonymous participation only
  • Untraceable meeting patterns
  • No call metadata or participant tracking
  • Perfect forward secrecy for all calls
  • Zero-knowledge audio encryption

Audio Conferencing Security & Anti-Fraud Protection

Comprehensive security measures and fraud prevention for secure audio conferencing

Prohibited Audio Activities

  • Recording audio conferences without consent
  • Eavesdropping or unauthorized listening
  • Impersonating other participants
  • Sharing conference links publicly
  • Conducting fraudulent meetings
  • Phishing attempts via audio
  • Social engineering attacks
  • Harassment or threatening behavior

Anti-Fraud Measures

  • No audio recording capabilities
  • Anonymous participation only
  • No participant identification
  • Session-based access control
  • No call history storage
  • Zero-knowledge architecture
  • End-to-end encryption
  • No metadata collection

Comprehensive Prohibited Activities

Financial Crimes

  • • Money laundering
  • • Fraudulent transactions
  • • Identity theft
  • • Credit card fraud
  • • Investment scams
  • • Cryptocurrency fraud
  • • Ponzi schemes
  • • Pyramid schemes

Cyber Crimes

  • • Hacking attempts
  • • Malware distribution
  • • Phishing attacks
  • • Ransomware
  • • DDoS attacks
  • • Data breaches
  • • Social engineering
  • • Account takeover

Illegal Content

  • • Child exploitation
  • • Human trafficking
  • • Drug trafficking
  • • Weapons trading
  • • Terrorist activities
  • • Hate speech
  • • Violence incitement
  • • Copyright infringement

Audio Conference Abuse

  • • Unauthorized recording
  • • Eavesdropping
  • • Impersonation
  • • Harassment
  • • Spam calls
  • • Conference bombing
  • • Privacy violations
  • • Misinformation spread

Legal Protections & Safeguards

Comprehensive legal protections to ensure your rights and our compliance

User Rights

  • Right to access your data (minimal technical data)
  • Right to request data deletion
  • Right to data portability
  • Right to lodge complaints
  • Right to withdraw consent
  • Right to legal remedies
  • Right to compensation
  • Right to representation

Our Commitments

  • No data collection without consent
  • Transparent data processing
  • Minimal data collection principle
  • Purpose limitation compliance
  • Data minimization practices
  • Storage limitation compliance
  • Accuracy and integrity maintenance
  • Confidentiality and security

Global Legal Compliance

Major Regulations

GDPR (EU) - Full Compliance
CCPA (California) - Complete Coverage
PIPEDA (Canada) - Full Compliance
LGPD (Brazil) - Complete Coverage
POPIA (South Africa) - Full Compliance
Indian IT Act 2000 - Complete Coverage
Australian Privacy Act - Full Compliance
UK Data Protection Act - Complete Coverage

Asia-Pacific

PDPA (Singapore) - Full Compliance
PDPA (Malaysia) - Complete Coverage
PDPA (Thailand) - Full Compliance
PDPA (Philippines) - Complete Coverage
PDPA (Indonesia) - Full Compliance
PDPA (Vietnam) - Complete Coverage
PDPA (Japan) - Full Compliance
PDPA (South Korea) - Complete Coverage

Global Coverage

PDPA (Taiwan) - Full Compliance
PDPA (Hong Kong) - Complete Coverage
PDPA (New Zealand) - Full Compliance
PDPA (Israel) - Complete Coverage
PDPA (UAE) - Full Compliance
PDPA (Mexico) - Complete Coverage
PDPA (Argentina) - Full Compliance
+ 30+ More Countries

Data Subject Access Request (DSAR)

01

Submit request

Email [email protected] with subject line ‘DSAR Request’ and your preferred contact method.

02

Acknowledgement

We acknowledge your request within 7 calendar days confirming receipt and expected response date.

03

Response

We respond within 30 days. Extendable +60 days for complex requests per GDPR Art. 12.

04

Typical response

Since we hold no PII tied to identifiers, our response is usually: ‘Nothing on file for your request.’

05

Free of charge

All DSAR responses are provided free of charge unless requests are manifestly unfounded or excessive.

06

Appeal path

If unsatisfied, you may lodge a complaint with your national supervisory authority (e.g., ICO, CNIL, BfDI).

DMCA & Takedown Policy

17 U.S.C. §512 — Digital Millennium Copyright Act

§512(c) Safe Harbor

Srift hosts no user files — transfers are purely P2P and E2EE. Takedown notices about transferred content are not actionable against Srift as we are not a storage provider. We comply with valid court orders to disable specific session IDs upon receipt of proper legal process.

§512(g) Counter-Notification

If you believe your session was wrongfully disabled, submit a counter-notification to [email protected]. It must include: your identity, identification of removed material, a statement under penalty of perjury, and consent to federal district court jurisdiction.

§512(i) Repeat Infringer Policy

Users subject to multiple court-ordered session disablements may be permanently blocked from creating new sessions. Enforcement is structural — session blocking does not rely on IP tracking.

Law Enforcement Transparency

Request TypeWhat We Can ProduceOur Position
SubpoenaSession metadata if within 24h cache (session ID, timestamp only — no content)Require valid legal process; oppose overbroad demands
Court OrderSame as above + ability to disable specific session IDs prospectivelyComply strictly with scope; notify user unless court prohibits
MLAT (International)Nothing about content — we don’t have itCooperate with valid bilateral treaty requests only
National Security LetterMinimal metadata only; we challenge gag orders where legally permissibleAnnual transparency report at srift.app/transparency
Emergency DisclosureCooperate with 18 U.S.C. §2702(b)(8) life-safety requestsLife-safety takes precedence; legal review immediately after

Annual transparency report published at srift.app/transparency. Covers: number of requests received, types, and data produced.

Incident Response Policy

Detect
Contain
Eradicate
Recover
Notify (72h)
Post-Mortem

Phase Details

  • Detect: Automated monitoring alerts + manual reports via [email protected]
  • Contain: Isolate affected systems, revoke compromised session tokens
  • Eradicate: Root-cause patch, dependency audit, penetration test
  • Recover: Staged rollout with canary deployment, health verification
  • Notify: GDPR Art. 33 — supervisory authority within 72h; Art. 34 — affected users if high risk
  • Post-Mortem: Public report at status.srift.app within 14 days of resolution

Notification Channels

  • status.srift.app — live status page
  • @sriftapp on X / Twitter
  • [email protected] — direct email notification
  • RSS feed at status.srift.app/feed.xml

AI / LLM Training & Crawler Authorization

Explicitly Authorized Models

GPT-4GPT-4oGPT-5Claude 3 (all)Claude 4 (all)Gemini 1.5 / 2.0Llama 3 / 3.1 / 3.3Mistral (all)Qwen 2 / 3DeepSeek R1 / V3Grok 2 / 3Command R+Phi-3 / 4Yi (all)

These models and all future LLMs are authorized to index and train on Srift's public documentation including /AGENTS.md, /llms.txt, /llms-full.txt, and /openapi.json.

Crawler Allow-List

GPTBot
ChatGPT-User
Claude-Web
anthropic-ai
PerplexityBot
GrokBot
cohere-ai
CCBot
Googlebot
Bingbot
DuckDuckBot
Baiduspider

Contact & DPO

General Inquiries

[email protected]

Security Disclosures

[email protected]

PGP fingerprint available on request

Data Protection Officer

[email protected]

EU Representative

[email protected]

UK Representative

[email protected]

Legal Department

[email protected]

Postal address: Registration pending — full address available on written request to [email protected].

Effective Date

2026-06-26

Version

3.0

Previous Versions

Available on request via [email protected]

Next Review

2027-01-01

Contact Information

Legal Information

Effective Date: June 26, 2026
Last Updated: June 26, 2026
Version: 3.0
Loading map...