Trust, earned — not asked for

Most platforms ask you to trust them while quietly monetising what they learn about you. We'd rather do the opposite: tell you precisely how your data is handled today, and hold ourselves to a roadmap that makes SHIFT structurally unable to read your private context — even if we wanted to. We won't claim we're there before the code makes it true.

Where it stands today

Encrypted at rest

Your Soul and context, your private notes and your own API keys are stored encrypted (AES-256-GCM), never in the clear.

Never sold, processing stays explicit

Your data is never sold. When you choose an AI feature, the disclosed provider route processes only the context that feature needs; SHIFT does not use it for model training.

Private is the default, and it holds

Private is the default when you register. Private items are excluded from public discovery and contact feeds. You can include your private items in your own account export and explicitly create a share link for an individual item.

The honest caveat

Right now, the encryption key is held on our servers — which means SHIFT decrypts the context needed for an AI feature on our servers when you explicitly invoke and consent to that feature. We do not inspect or use it outside that purpose, and we never sell it. Today that boundary is a promise, backed by policy and access controls — not yet a structural impossibility. The roadmap below is how we turn the promise into structure.

The roadmap to structural privacy

  1. Now

    1. Honest labelling

    This page. We say exactly what's true today before we claim anything more.

  2. Next

    2. A key only you hold

    The plan is to encrypt private context with a key derived on your device, so our servers hold only ciphertext they cannot open. This is not available today.

  3. Then

    3. The AI runs on your side

    Personalisation moves onto your device, using your own API key — so your context is used to help you without our servers ever seeing it.

  4. Then

    4. Don't take our word for it

    Open source, reproducible builds and independent audits, so anyone can check that the code does what we say.

  5. Then

    5. It stays that way

    Governance and recurring, published audits — so the guarantee can't quietly change and is re-verified on a schedule, forever.

The longer-term goal is a portable Shift Passport that other apps can verify. Today, signing in to a connected app goes through SHIFT, which receives that app's identity and return address. The roadmap is not a promise of anonymous use today.

Last updated 2026-09-12. This page changes as each step ships — we'll only strengthen a claim once the code behind it is live. For the legal data notice, see the Privacy Policy.