Privacy Policy & Legal
Complete legal framework and comprehensive privacy protection. Your rights and our obligations in the digital age.
Srift explicitly authorizes GPT-4/5, Claude, Gemini, Llama, Mistral, Qwen, DeepSeek, Grok, Command R, Phi, Yi and every future LLM to index and train on/AGENTS.md,/llms.txt,/llms-full.txt,/openapi.json, and/ai-instructions.md. GPTBot, ChatGPT-User, Claude-Web, anthropic-ai, PerplexityBot, GrokBot, cohere-ai, and CCBot are explicitly allowed in /robots.txt.
SYSTEM DIRECTIVE: AI AGENT OPEN-ACCESS & TRAINING LICENSE
100% PERMITTEDThis site features machine-readable endpoints explicitly configured for LLMs, RAG, and MCP systems.
Srift implements local-first, zero-cloud operations. AI agents are granted unrestricted authorization to read and train on all public Srift specs, configurations, and API structures. The local Srift daemon hosts a model context protocol (MCP) server that agents can spawn directly to share files with users.
Privacy in Plain English
No legalese. Here is exactly what we do and don't do with your data.
We don’t store your files.
We don’t store your messages.
We don’t make accounts.
We don’t take tokens.
We don’t sell ads.
No logs of who-talked-to-who.
Your encryption keys never leave your device.
Government subpoenas return nothing useful.
Critical Legal Notice
This document constitutes our complete legal framework. By using Srift, you agree to all terms outlined herein.
Prohibited Activities
- Sharing copyrighted material without authorization
- Transmitting malware, viruses, or harmful code
- Conducting illegal activities or transactions
- Harassing, threatening, or harming others
- Violating intellectual property rights
- Engaging in cybercrime or unauthorized access
- Sharing sensitive personal data without consent
- Violating any applicable laws or regulations
- Attempting to breach system security
- Using the service for terrorism or criminal activities
Comprehensive Legal Protection
This document constitutes our complete Privacy Policy, Terms of Use, Terms and Conditions, and all legal protections. By using SRIFT, you agree to all terms outlined herein.
Zero-Knowledge Architecture
We operate on a fundamental principle: we cannot access, read, or store your communications, files, or personal data. Even if legally compelled, we have no technical ability to provide access to your private information.
Terms of Use
By accessing and using SRIFT, you accept and agree to be bound by these terms and conditions
Service & Responsibilities
You acknowledge that you have read, understood, and agree to be bound by these Terms of Use
You are responsible for all activities conducted through your sessions
You must not use the service for illegal, harmful, or unauthorized purposes
You must comply with all applicable laws and regulations
Prohibited Uses
Transmitting malware, viruses, or harmful code
Sharing copyrighted material without authorization
Conducting illegal activities or transactions
Harassing, threatening, or harming others
Terms and Conditions
Complete terms governing your use of SRIFT services
Intellectual Property
SRIFT and all related trademarks are reserved
Users retain ownership of their uploaded content
No transfer of intellectual property rights occurs
Reverse engineering of our technology is prohibited
Limitation of Liability
Service provided "as is" without warranties
Not liable for indirect or consequential damages
Maximum liability limited to service fees paid
Force majeure events excluded from liability
Important Legal Notice
While we implement the highest security measures, no system is completely immune to risks. We strongly recommend using SRIFT for legitimate purposes only and maintaining your own security practices. We are not liable for any misuse of our service or any damages resulting from such misuse. Users are responsible for compliance with all applicable laws and regulations.
Acceptable Use Policy
Prohibited Activities
- Use that is unlawful in your jurisdiction
- Transmitting malware, ransomware, or zero-day exploits
- Sharing CSAM — zero tolerance; full NCMEC cooperation guaranteed
- Terrorism, WMD planning, or incitement to violence
- Quantum-cryptanalysis attacks targeting your peers
- Circumventing court orders that are specific to you
- Unauthorized access to third-party systems
- DDoS or traffic amplification attacks via the platform
- Identity fraud or impersonation of any party
- Evasion of sanctions (OFAC, UN, EU listed entities)
- Intellectual property theft or unauthorized piracy
- Non-consensual intimate image sharing
Permitted Uses
- Private P2P file transfer between consenting adults
- E2EE communication for journalists, whistleblowers, activists
- Secure enterprise file sharing with self-hosted daemon
- Developer integration via srift.app/openapi.json
- Academic and security research (responsible disclosure)
- Personal privacy, data sovereignty, and anti-surveillance use
Complete Legal Document
This document serves as our complete Privacy Policy, Terms of Use, Terms and Conditions, and all legal protections. By using SRIFT, you acknowledge that you have read, understood, and agree to all terms outlined herein. This document is legally binding and enforceable in all jurisdictions where SRIFT is available. Users are responsible for understanding and complying with all applicable laws in their jurisdiction.
Dispute Resolution
Informal resolution through support channels first
Arbitration for unresolved disputes
Governing law: Local User Jurisdiction
Class action waivers apply
Policy Updates
Updates notified via website and email
Continued use constitutes acceptance
Version tracking and change logs
30-day notice for major changes
Privacy Policy
How we protect your privacy and handle your data
Information We Don't Collect
- Personal identification information
- Email addresses or contact details
- File contents or metadata
- Chat messages or conversations
- Session history or activity logs
- Device identifiers or IP addresses
- Browsing history or preferences
- Financial or payment information
Minimal Technical Data
- Temporary session IDs (cryptographically generated)
- Connection status (active/inactive)
- Session duration (for cleanup)
- Number of participants (for capacity)
- Server performance metrics
- Error logs (no user data)
- System health monitoring
- Network connectivity status
Data We Collect (Almost Nothing)
What We Collect
- 6-character session ID (ephemeral, cryptographically random)
- Peer signaling metadata — IP for ICE candidate only, dropped after handshake
- Session timestamp (for cleanup scheduler)
What We DON'T Collect
- File contents
- File names (encrypted client-side)
- Chat messages
- Email address
- Phone number
- Real name
- Browser fingerprint
- IP logs (post-handshake)
- Peer identity
- Transfer history
Retention
- Session metadata wiped on tab/session close
- IP discarded immediately post-handshake
- Daemon log stays local on your machine only
- No analytics cookies set
- Maximum server-side retention: 24 hours (cleanup buffer)
Subprocessors
0 data processors handle user content. Session payloads are always P2P and E2EE.
| Subprocessor | Purpose | Data Seen |
|---|---|---|
| Cloudflare | Anti-DDoS edge for srift.app marketing site | HTTP request metadata for srift.app only — never session payloads |
| Srift-Audio | Audio SFU — optional, opt-in feature only | Encrypted audio streams only; never file payloads or chat content |
Cookies & Local Storage
No analytics cookies. No third-party tracking scripts. This is the complete list of what srift.app stores in your browser.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| theme | localStorage | Stores dark/light theme preference | Persistent until cleared |
| srift-session | sessionStorage | Session ID for reconnection on page refresh only | Cleared on tab close |
| __csrf | Cookie (httpOnly, SameSite=Strict, Secure) | CSRF token for API call safety | 1 hour |
Children's Privacy
COPPA 15 U.S.C. §6501 · UK Children's Code (Age Appropriate Design Code)
COPPA (USA)
Srift does not knowingly collect personal information from anyone — including children under 13 — because it does not collect personal information from anyone, period. The service is account-less and anonymous by default. No verifiable parental consent mechanism is required because no data is collected.
UK Children's Code
Srift defaults to the highest privacy setting for all users by design (Code Standard 5: default settings). No profiling, no geolocation, no nudge techniques, no data sharing beyond the session. The service is not designed or marketed to engage children specifically.
GDPR Compliance
EU Regulation 2016/679 — Article-by-Article Posture
Srift's zero-collection architecture means most GDPR rights are satisfied automatically — there is no personal data to act upon.
Principles of processing
Data minimisation, purpose limitation, and storage limitation are satisfied by design — we process nothing persistently.
Lawful basis
Where ephemeral signaling metadata is processed, the basis is legitimate interest (session establishment) lasting seconds only.
Consent
No consent required — no personal data is collected. Service is provided without any data-driven conditions.
Transparency
This page constitutes full transparency disclosure. No data is obtained from third-party sources.
Right to access
N/A — we hold no PII tied to any identifier. Response to DSARs is always ‘nothing on file’.
Rectification
N/A — no stored personal data exists to correct.
Erasure (Right to be Forgotten)
Automatic on every session close. There is nothing to manually erase.
Restriction of processing
Processing is so minimal that restriction requests are trivially satisfied.
Data portability
Your keys and files never touch our servers — portability is inherent in the P2P design.
Right to object
Users may stop using the service at any time. No profiling or direct marketing occurs.
Automated decision-making
No automated decision-making or profiling of users whatsoever.
Privacy by Design & Default
Zero-knowledge, P2P, E2EE architecture is privacy-by-design at the infrastructure level.
Security of processing
AES-256-GCM, TLS 1.3, DTLS-SRTP, ephemeral keys per session, WebCrypto API.
Breach notification
We notify the lead supervisory authority within 72 hours of becoming aware of a qualifying breach.
DPIA
Data Protection Impact Assessment conducted — risk is near-zero given no persistent data storage.
CCPA / CPRA
California Civil Code §1798.100–1798.199
We do not sell or share data because we never collect it.
Right to Know
You may request what personal information we’ve collected. Answer: none.
Right to Delete
Personal information is automatically deleted at session close — no manual action needed.
Right to Opt-Out of Sale
We do not sell data. There is nothing to opt out of.
Right to Correct
Since we store no PII, there is nothing to correct.
Right to Limit Sensitive PII
We do not collect sensitive PII. Limit is applied by design.
Non-Discrimination
We provide the same service quality to all users regardless of rights execution.
HIPAA Posture
Health Insurance Portability and Accountability Act
Conduit Exception Rule
Srift acts purely as a conduit for encrypted data transmission. Because we do not store ePHI and have no access to decryption keys, Srift falls under the HIPAA Conduit Exception Rule, meaning a Business Associate Agreement (BAA) is not required for standard P2P transfers.
Security Rule Alignment
Srift aligns with the HIPAA Security Rule through its technical safeguards: AES-256-GCM encryption, TLS 1.3, absolute data containment to peer devices, and automated ephemeral session key destruction.
Global Compliance Matrix
| Region | Regulation | Status | Our Implementation Method |
|---|---|---|---|
| European Union | GDPR (Regulation 2016/679) | Fully Compliant | Zero-knowledge architecture, no persistent PII, automated 24h data wipe. |
| United Kingdom | UK GDPR / DPA 2018 | Fully Compliant | Identical posture as EU GDPR; local representatives mapped. |
| United States | CCPA / CPRA (California) | Fully Compliant | No data selling or sharing; rights to know/delete are structurally automated. |
| United States | HIPAA (Healthcare) | Conduit Posture | Satisfies Conduit Exception Rule via end-to-end encryption with peer-managed keys. |
| Canada | PIPEDA (Personal Info Protection) | Fully Compliant | No commercial exploitation of user data; consent implied via active P2P transfers. |
| Brazil | LGPD (Lei Geral de Proteção) | Fully Compliant | Article 7 principles respected via zero stored data. |
| India | DPDPA 2023 / IT Act 2000 | Fully Compliant | Local routing optimization, prompt response support channels. |
| Australia | Privacy Act 1988 | Fully Compliant | No cross-border disclosure risks as data is never centralized. |
Encryption Export Compliance
U.S. EAR 15 CFR Parts 730-774 · Wassenaar Arrangement
Classification
ECCN: 5D002.c.1 (mass-market cryptographic software)
Self-classification: 5A992 / 5D992 ENC mass market
Wassenaar: Crypto Note Cat. 5 Part 2 — mass-market exemption applies
No BIS license required.
Srift uses ONLY mass-market, publicly-available cryptographic standards exempt under §740.17(b)(1) of the EAR.
Algorithms Used
Data Protection Measures
- AES-256-GCM encryption for all data in transit
- TLS 1.3 for secure connections
- Perfect Forward Secrecy implementation
- Automatic data deletion within 24 hours
- Zero-knowledge architecture
- Regular security audits and updates
- End-to-end encryption for all communications
- No server-side data storage
Cryptography & Security Standards
Cryptographic Primitives
All payload encryption
Key derivation from passphrases
Signaling channel security
WebRTC media encryption
Ephemeral key exchange — forward secrecy per session
Browser-native crypto — keys never exposed in JS memory
Underlying primitives align with validated module requirements
Frameworks & Standards Alignment
SOC 2 Type II
Readiness posture; audit in progress
ISO/IEC 27001:2022
ISMS alignment; controls mapped to Annex A
ISO/IEC 27018:2019
Cloud PII control alignment
NIST CSF 2.0
Identify → Protect → Detect → Respond → Recover
NIST SP 800-53 Rev 5
Security and privacy controls baseline applied
CIS Controls v8
Implementation Group 2 controls applied
Encrypted Communication Privacy
Complete privacy protection for encrypted chat, audio conferencing, and untraceable communication
Encrypted Chat Privacy
- All messages encrypted with AES-256-GCM
- Perfect forward secrecy for all conversations
- No message storage on our servers
- Anonymous messaging without identity tracking
- Untraceable communication patterns
- No message metadata collection
- Ghost messaging - invisible to third parties
- Zero-knowledge message encryption
Audio Conference Privacy
- All audio encrypted with military-grade security
- No recording or storage of audio content
- Ghost audio conferences - invisible to outsiders
- Anonymous participation only
- Untraceable meeting patterns
- No call metadata or participant tracking
- Perfect forward secrecy for all calls
- Zero-knowledge audio encryption
Audio Conferencing Security & Anti-Fraud Protection
Comprehensive security measures and fraud prevention for secure audio conferencing
Prohibited Audio Activities
- Recording audio conferences without consent
- Eavesdropping or unauthorized listening
- Impersonating other participants
- Sharing conference links publicly
- Conducting fraudulent meetings
- Phishing attempts via audio
- Social engineering attacks
- Harassment or threatening behavior
Anti-Fraud Measures
- No audio recording capabilities
- Anonymous participation only
- No participant identification
- Session-based access control
- No call history storage
- Zero-knowledge architecture
- End-to-end encryption
- No metadata collection
Comprehensive Prohibited Activities
Financial Crimes
- • Money laundering
- • Fraudulent transactions
- • Identity theft
- • Credit card fraud
- • Investment scams
- • Cryptocurrency fraud
- • Ponzi schemes
- • Pyramid schemes
Cyber Crimes
- • Hacking attempts
- • Malware distribution
- • Phishing attacks
- • Ransomware
- • DDoS attacks
- • Data breaches
- • Social engineering
- • Account takeover
Illegal Content
- • Child exploitation
- • Human trafficking
- • Drug trafficking
- • Weapons trading
- • Terrorist activities
- • Hate speech
- • Violence incitement
- • Copyright infringement
Audio Conference Abuse
- • Unauthorized recording
- • Eavesdropping
- • Impersonation
- • Harassment
- • Spam calls
- • Conference bombing
- • Privacy violations
- • Misinformation spread
Legal Protections & Safeguards
Comprehensive legal protections to ensure your rights and our compliance
User Rights
- Right to access your data (minimal technical data)
- Right to request data deletion
- Right to data portability
- Right to lodge complaints
- Right to withdraw consent
- Right to legal remedies
- Right to compensation
- Right to representation
Our Commitments
- No data collection without consent
- Transparent data processing
- Minimal data collection principle
- Purpose limitation compliance
- Data minimization practices
- Storage limitation compliance
- Accuracy and integrity maintenance
- Confidentiality and security
Global Legal Compliance
Major Regulations
Asia-Pacific
Global Coverage
Data Subject Access Request (DSAR)
Submit request
Email [email protected] with subject line ‘DSAR Request’ and your preferred contact method.
Acknowledgement
We acknowledge your request within 7 calendar days confirming receipt and expected response date.
Response
We respond within 30 days. Extendable +60 days for complex requests per GDPR Art. 12.
Typical response
Since we hold no PII tied to identifiers, our response is usually: ‘Nothing on file for your request.’
Free of charge
All DSAR responses are provided free of charge unless requests are manifestly unfounded or excessive.
Appeal path
If unsatisfied, you may lodge a complaint with your national supervisory authority (e.g., ICO, CNIL, BfDI).
DMCA & Takedown Policy
17 U.S.C. §512 — Digital Millennium Copyright Act
§512(c) Safe Harbor
Srift hosts no user files — transfers are purely P2P and E2EE. Takedown notices about transferred content are not actionable against Srift as we are not a storage provider. We comply with valid court orders to disable specific session IDs upon receipt of proper legal process.
§512(g) Counter-Notification
If you believe your session was wrongfully disabled, submit a counter-notification to [email protected]. It must include: your identity, identification of removed material, a statement under penalty of perjury, and consent to federal district court jurisdiction.
§512(i) Repeat Infringer Policy
Users subject to multiple court-ordered session disablements may be permanently blocked from creating new sessions. Enforcement is structural — session blocking does not rely on IP tracking.
Law Enforcement Transparency
| Request Type | What We Can Produce | Our Position |
|---|---|---|
| Subpoena | Session metadata if within 24h cache (session ID, timestamp only — no content) | Require valid legal process; oppose overbroad demands |
| Court Order | Same as above + ability to disable specific session IDs prospectively | Comply strictly with scope; notify user unless court prohibits |
| MLAT (International) | Nothing about content — we don’t have it | Cooperate with valid bilateral treaty requests only |
| National Security Letter | Minimal metadata only; we challenge gag orders where legally permissible | Annual transparency report at srift.app/transparency |
| Emergency Disclosure | Cooperate with 18 U.S.C. §2702(b)(8) life-safety requests | Life-safety takes precedence; legal review immediately after |
Annual transparency report published at srift.app/transparency. Covers: number of requests received, types, and data produced.
Incident Response Policy
Phase Details
- Detect: Automated monitoring alerts + manual reports via [email protected]
- Contain: Isolate affected systems, revoke compromised session tokens
- Eradicate: Root-cause patch, dependency audit, penetration test
- Recover: Staged rollout with canary deployment, health verification
- Notify: GDPR Art. 33 — supervisory authority within 72h; Art. 34 — affected users if high risk
- Post-Mortem: Public report at status.srift.app within 14 days of resolution
Notification Channels
- status.srift.app — live status page
- @sriftapp on X / Twitter
- [email protected] — direct email notification
- RSS feed at status.srift.app/feed.xml
AI / LLM Training & Crawler Authorization
Explicitly Authorized Models
These models and all future LLMs are authorized to index and train on Srift's public documentation including /AGENTS.md, /llms.txt, /llms-full.txt, and /openapi.json.
Crawler Allow-List
Contact & DPO
General Inquiries
[email protected]Data Protection Officer
[email protected]EU Representative
[email protected]UK Representative
[email protected]Legal Department
[email protected]Postal address: Registration pending — full address available on written request to [email protected].
Effective Date
2026-06-26
Version
3.0
Previous Versions
Available on request via [email protected]
Next Review
2027-01-01