SCIFText
Privacy
SCIFText forwards messages you choose to send onward. It is not a second mailbox, and it is not an end-to-end encrypted messenger. Email delivery is handled by the mail service configured for the site (Mailgun or Postal). Push delivery is handled by Firebase.
What the server stores
Your account email, a hash of your password, the forwarding addresses you add, and the phone's Firebase push token. The server uses those to sign you in, to know where to send mail, and to deliver a reply back to the phone. A password reset stores only a hash of the one-time link, and that row expires after an hour. Google or Apple sign-in, when you use it, also stores that provider's account id and the email the provider says is verified.
What the server does not keep
Message text is passed through to email, and a reply is passed back to the phone. The server does not keep a message archive. Short-lived operational logs may include message text, addresses, or a push token while a problem is being diagnosed.
What leaves the server
Forwarded messages are sent through the configured mail service (Mailgun or Postal) from an address on that service's domain. Replies posted back are turned into a push notification so the phone can send the SMS. Google Play and Firebase are part of that path.
Contact
Questions about this policy: privacy@sciftext.com.