Sikka Privacy Policy
Effective 18 July 2026 · applies to usesikka.com, demo.usesikka.com, and the Sikka reveal app at /app
The short version: when you connect Gmail, your emails are fetched and read entirely in your browser. Sikka's servers never receive, store, or see your email content, statements, passwords, or tokens — the app is technically incapable of sending them to us. Disconnecting wipes everything from your device and revokes Sikka's access to your Google account.
1 · What the Sikka app does
Sikka analyses your card spending to show what verified rewards cards would have earned on it. The analysis runs on your device: your browser downloads the Sikka page and code from our server, and from that point the financial computation happens locally.
2 · Google user data: what we access and why
If you choose to connect Gmail, the app asks Google for these OAuth scopes:
openidandemail— to confirm which Google account granted access, shown back to you in the app.gmail.readonly— read-only access your browser uses to find financial emails (bank transaction alerts, e-statements, reward summaries) and statement PDF attachments. Read-only means the app can never send, modify, delete, or label your mail.
The Gmail search is limited to financial senders and financial subjects; your browser fetches only those messages.
3 · Where your data goes — and where it can't
- Your OAuth token stays in your browser. Sikka uses Google's token-in-fragment flow: the access token is delivered by Google directly to the page in your browser and is never transmitted to Sikka's servers. So the app can restore your session after a reload, the token and your raw Google email address are kept in the same encrypted on-device vault described below. For limited-alpha access, the browser sends only a one-way SHA-256 digest of the normalized address to a fixed cohort-check endpoint; the raw address and token are never sent.
- Email content stays in your browser. Message bodies and PDF statements are parsed on-device and immediately discarded. Only derived fields — merchant names, amounts, card last-4 digits, points counts — are kept, encrypted (AES-GCM via your browser's WebCrypto), in your browser's local storage. The encryption key is generated by your browser as non-extractable: it cannot be exported by any code, ours included, and can never leave your browser. Raw content is never persisted, never transmitted.
- The app has a tightly bounded network surface. The /app page ships a Content-Security-Policy that allows connections only to Google's own domains (accounts.google.com, oauth2.googleapis.com, www.googleapis.com) and the exact first-party cohort-check path described above. Our build pipeline scans the shipped code for any other destination and fails if one appears; our test suite asserts the same. Statement passwords you type are used on-device to unlock the PDF and are never stored or sent anywhere.
- Sikka's servers receive no Gmail content or credentials. Apart from the cohort digest, what our servers see from the app is the ordinary web traffic of serving you the page and its code — never your email content, attachments, raw address, passwords, or tokens.
4 · Limited Use disclosure
Sikka's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide the user-facing feature you asked for — your on-device rewards report.
- We do not transfer Google user data to anyone, sell it, or share it. Gmail content and OAuth credentials never leave your device; the limited-alpha cohort digest is used only by Sikka to answer that access check and is not retained.
- We do not use Google user data for advertising of any kind.
- No human at Sikka reads your Gmail content or OAuth credentials — architecturally we cannot, because they never reach us.
- We do not use Google user data to train AI or machine-learning models — generalized or otherwise.
5 · Retention and deletion
Everything the app derives from your Gmail lives encrypted in your own browser's storage. Pressing Disconnect & wipe deletes all of it and revokes the app's Google access token. Clearing your browser's site data deletes the local data, but it cannot contact Google to revoke access; review or revoke Sikka separately at myaccount.google.com/permissions. There is no server-side copy to delete, and access tokens expire on their own within about an hour.
6 · Data we do hold on our servers
- App usage counts: when the reveal app's page loads, our server counts the request (date, approximate country from the network request, and which access mode served it) — counts only, no IP address stored, and never any email, statement content, or reward figure. The cohort access-check likewise records only a fragment of the one-way digest described above, to count unique users.
- Chat concierge (optional): if you type a question into the app's Chat tab, that typed question — together with your card names, their markets, and coarse monthly totals — is sent to Sikka's server at the fixed
/app/assistendpoint, and from there to our AI processor, OpenRouter, solely to answer you. Never your statements, transactions, merchants, tokens, or passwords — the app remains technically incapable of sending those. If you never use Chat or its research buttons, nothing is sent. Answers produced this way are labelled in the app as AI answers, distinct from Sikka's verified figures. - Demo contact details (public demo): to try the public demo you enter your name, email, and phone at the gate; those contact details — plus the approximate country from the network request — are sent to Sikka's server at the fixed
/app/leadendpoint and stored, so we can follow up. Optional feedback you leave at the end goes the same way to/app/feedback. These contact details are the only thing we store from the demo — never your statements, transactions, card numbers, passwords, or reward figures, which stay on your device. - Waitlist: if you join the waitlist we store the email address you give us, and use it only to contact you about access to Sikka.
- WhatsApp assistant: if you message Sikka on WhatsApp we store your number, the card names, balances, or recurring bills you tell us about, and conversation history needed to answer you. Statements you send there are parsed on our servers: the parsed transaction summary is kept for your reports, and the raw file is not retained after parsing. If the optional WhatsApp AI-analysis feature is enabled for your account, and only after you accept the current WhatsApp consent disclosure, a statement PDF/image or card image you upload may be sent to our configured AI processor, OpenRouter, solely to perform the analysis you requested. This processor path applies only to WhatsApp uploads; Gmail content is never sent to it. A password-protected PDF is held encrypted until you unlock it, exhaust the attempts, or its short unlock window expires. Expired files cannot be opened and are physically deleted on the next access or scheduled retention cleanup; the password you type is used once to unlock and is never stored. The WhatsApp assistant has no access to your Gmail.
- No trackers in the app: the Sikka app contains no third-party advertising or analytics trackers — the same build gate that blocks data exfiltration blocks them too. The marketing website (usesikka.com pages, not the app) uses Microsoft Clarity to understand how visitors use the site; Clarity may set cookies and record page interactions there. See Microsoft's privacy statement. Your Gmail content and statements never touch those pages.
7 · Your rights
UAE PDPL and equivalent laws give you rights of access, correction, and erasure over personal data we hold. After an erasure, we retain only a minimal suppression record — a derived user key and deletion time — so delayed provider or system retries cannot recreate the records you asked us to delete. It is not used to provide recommendations, contact you, or market to you. For anything in section 6 — or any privacy question — contact us and we will respond within 30 days.
8 · Contact
Sikka FZ-LLC, Dubai, UAE · sid@usesikka.com
9 · Changes
If this policy changes, the new version appears here with a new effective date. We will never weaken the on-device guarantees above without asking for your consent again.