Trust, earned — not asked for
Most platforms ask you to trust them while quietly monetising what they learn about you. We'd rather do the opposite: tell you precisely how your data is handled today, and hold ourselves to a roadmap that makes SHIFT structurally unable to read your private context — even if we wanted to. We won't claim we're there before the code makes it true.
Where it stands today
Encrypted at rest
Your Soul and context, your private notes and your own API keys are stored encrypted (AES-256-GCM), never in the clear.
Never sold, processing stays explicit
Your data is never sold. When you choose an AI feature, the disclosed provider route processes only the context that feature needs; SHIFT does not use it for model training.
Private is the default, and it holds
Private is the default when you register. Private items are excluded from public discovery and contact feeds. You can include your private items in your own account export and explicitly create a share link for an individual item.
The honest caveat
Right now, the encryption key is held on our servers — which means SHIFT decrypts the context needed for an AI feature on our servers when you explicitly invoke and consent to that feature. We do not inspect or use it outside that purpose, and we never sell it. Today that boundary is a promise, backed by policy and access controls — not yet a structural impossibility. The roadmap below is how we turn the promise into structure.
The roadmap to structural privacy
- Now
1. Honest labelling
This page. We say exactly what's true today before we claim anything more.
- Next
2. A key only you hold
The plan is to encrypt private context with a key derived on your device, so our servers hold only ciphertext they cannot open. This is not available today.
- Then
3. The AI runs on your side
Personalisation moves onto your device, using your own API key — so your context is used to help you without our servers ever seeing it.
- Then
4. Don't take our word for it
Open source, reproducible builds and independent audits, so anyone can check that the code does what we say.
- Then
5. It stays that way
Governance and recurring, published audits — so the guarantee can't quietly change and is re-verified on a schedule, forever.
The longer-term goal is a portable Shift Passport that other apps can verify. Today, signing in to a connected app goes through SHIFT, which receives that app's identity and return address. The roadmap is not a promise of anonymous use today.
Last updated 2026-09-12. This page changes as each step ships — we'll only strengthen a claim once the code behind it is live. For the legal data notice, see the Privacy Policy.