Drifft

Privacy

Last updated 11 August 2026

Drifft is an accountability app. It works by watching a narrow, specific thing: what is in front of you while a session you started is running. We would rather be precise about that than vague, so this page lists it exactly. The short version: we never see your content, your screen, or your keystrokes. We do see where your attention went, in some detail, because that is what makes the app able to learn anything about how you work.

What Drifft never sees

This list is the important one, so it comes first. Drifft does not record the contents of your screen. It does not capture your keystrokes, and it never reads what you type anywhere outside Drifft itself. It does not read the text of the pages you visit, the messages you write, or the documents you open. It does not watch your files. What you type into Drifft, into a commitment or the brain dump, is a different thing entirely: you handed it over on purpose, it is listed below, and you can delete all of it. On the Mac there are no screenshots at all, and there is no mechanism in the app that could take one. On iPhone the only images that exist are ones you deliberately attach yourself at the end of a session.

What Drifft collects

  • Your account. An email address, or an Apple sign-in. If you use Sign in with Apple with Hide My Email, we only ever see the relay address. If you give a display name, we store that.
  • What you commit to. The commitments you write: the result, your definition of done, your minimum, and your first action. These are your words, stored so they sync across your devices.
  • What you empty out of your head. If you use the brain dump, whatever you type into it, exactly as you typed it, plus which of it you chose to protect. It is stored for the day it belongs to and deleted the next day, along with the commitments that came out of it. One thing outlasts it: a stripped, unreadable fingerprint of each thing you wrote, so Drifft can notice when something keeps coming back and you keep setting it aside. That fingerprint cannot be turned back into your words, and it is deleted when you delete your account.
  • Your sessions. When a session started and ended, whether it was paused, whether you said you were stuck, and how it concluded.
  • What was in front of you, while a session runs. The name of the app, the website host, and the name of the document, file or project you had open. So: "youtube.com", never what you watched. "invoice-q3.pdf", never a word of what it says.
  • How much you were working, not what you wrote. How long you were typing and how many characters were added during a stretch, plus how long you were idle. These are counts and durations. The characters themselves are never captured, sent or stored.
  • How the work went. The outcome you picked, how much of the session was spent in the tools that commitment expects, and how often you came back after drifting.
  • What Drifft learns from all of that. Your typical focus length for a kind of work, which times of day tend to hold, and which apps and sites tend to pull you off. This is derived from the above and is the reason the app gets more useful over time.
  • Proof you attach. Links, notes, counts, or screenshots you choose to add at the end of a session on iPhone, plus evidence pulled from tools you explicitly connect.
  • Basic diagnostics. Enough to tell whether a feature is broken.

The Mac, and the Accessibility permission

The Mac app asks for Accessibility access. That permission is what lets it read the title of the window in front, which is how it knows you are on a video site rather than in your editor, and how it knows which document you are working in. It is the same grant that makes the keyboard shortcut for the assistant card work.

What it is deliberately not used for: there is no keyboard tap, no screen recording, no file watching, and no reading of the contents of any window. Blocking on the Mac is a full screen panel that Drifft draws over the distraction. It is not enforced by macOS itself, so it is friction rather than a lock, and the override is always one tap.

Blocking on iPhone

Blocking uses Apple's Screen Time system. You choose which apps go on the list, and iOS hands Drifft opaque tokens for them. Because of how that system is designed, we cannot see which specific apps you selected, and we never receive your general Screen Time history.

Your calendar, and your to-do lists

If you connect it, Drifft reads today's events so it can suggest what to protect and how long a session fits before your next meeting. It is read only and today only. It never writes to your calendar, never creates anything on your behalf, and there is no screen in Drifft that shows you a merged list.

There is a deliberate split in how event titles are handled, and it is about consent rather than sensitivity. When Drifft uses your calendar on its own, unasked, it reads only the time of your next commitment and never the title. When you ask it a question like "what does my afternoon look like", it reads the titles too, because answering that with "you have a thing at 2" is not privacy, it is a worse product. Those titles are used to answer you and are not stored.

Apple Calendar and Reminders are read on your device. Todoist, on iPhone, is connected through its own OAuth flow using a read-only scope, so write access is refused by Todoist itself rather than left to our good behaviour. You can disconnect any source at any time.

Talking to Drifft

On the Mac you can summon a card with a keyboard shortcut and say what you want. Speech is turned into text on your Mac, by macOS, without going to a server. If your language is not supported for on device recognition, Drifft falls back to sending the audio to a speech provider to be transcribed, and it tells you so rather than doing it quietly. Drifft never listens unless you have summoned the card or pressed the microphone, and it never speaks back: there is no text to speech anywhere in the product.

If you name a witness

You can name someone and send them a link. What they see is deliberately almost nothing: the commitment you named, and one word for how it is going, from a fixed list of eight. Nothing else can reach them, because the record their page reads has no field capable of holding an app, a website, a document, or anything you did. That is a structural limit, not a policy we promise to keep.

We never ask for their phone number and never store one. You send the invite yourself, from your own messages, and you can turn their link off at any time, which stops it working immediately.

Your coach

When the AI coach is switched on, the relevant parts of your commitments, your session state, and what Drifft has learned about how you work are sent to Anthropic to generate a reply. Your data is not used to train anyone's models. Turn the coach off in Settings and the whole app still works: starting, blocking, recovering and recording are all deterministic and never depend on it.

Who else touches your data

We use Supabase for the database and authentication, Anthropic for the coach, a speech provider for the voice fallback described above, and Vercel to host this website. They process data so the product can function. We do not sell your data, and we do not share it with advertisers.

Deleting everything

Settings has two separate options and the difference matters. "Reset app" starts you over locally and keeps your account. "Delete all my data" removes everything we hold for you across every table, including what Drifft learned about how you work, any proof you uploaded, and any witness links you created. It deletes from our servers first, so a failure part way through leaves nothing half removed.

The waitlist

If you join the waitlist on this site we store your email address, roughly where the signup came from, and a one-way hash of your IP address for abuse prevention. The IP address itself is never stored. We use it to email you about access, and nothing else.

Contact

Questions, or a request about your data: hello@drifftapp.com.


Back to Drifft · Terms · Privacy