Last updated: 13 August 2026.
Sight is published by TAPTAKE BİLİŞİM (contact@taptake.net). Questions, requests and complaints: info@usesight.app.
Sight does not record what you browse. There is no history, no list of pages visited, no analytics, no advertising, and no third party receives anything about you except the mail provider that delivers messages you asked for.
What leaves your phone is the small amount needed to make a waiting period survive a reinstall, and the email addresses of the people you chose to be told when you ask to turn filtering off.
A device identifier. Android's ANDROID_ID,
specific to this phone and to this app's signing key, or on iOS an identifier
created for this installation and kept in the device's keychain. It is sent so
a waiting period can be held against something that survives the app's data
being cleared. Without it, reinstalling would end a wait, and the wait is the
point.
How long your device thinks a wait has left. A duration in milliseconds. Never a date, never a time of day. The countdown deliberately never reads a clock, so there is no clock reading to send.
Email addresses you enter, if you choose to name anyone. At most three.
A token this device was issued, on each request, so the server can tell your device from someone else's.
Your IP address is visible to the server, as it is to every server you connect to. It is used to limit how often one address can register a new device, and it appears in the request log.
Photographs are examined on your phone. The model that examines them is downloaded to the device and runs there. No image and no score for an image is uploaded, and none is written to storage.
Like any browser, Sight keeps cookies and site storage, because no site can be logged into without them.
It does not keep a cache of the images and video it filters. That cache existed and was removed: the media it held was from the sites being filtered, which is precisely the content that may be withheld, and keeping a recoverable copy of a picture the filter refused to show is not filtering. The cost is that scrolling back re-downloads.
No browsing history is kept anywhere, by design and from the first version.
| What | Why | How long |
|---|---|---|
| Device identifier | So a wait survives a reinstall | Until you ask for it to be deleted |
| When a wait ends | The wait itself | Cleared when the wait ends or is cancelled |
| A SHA-256 hash of the device's token | Authentication. The token itself is never stored, so a copy of the database yields no working credentials | Until replaced or deleted |
| Email addresses you entered | Asking the recipient whether they agree, and sending the messages you asked for once they do | Until you remove them, or until the recipient does |
| Whether the recipient agreed, and when | So nothing is sent to somebody who has not | Deleted with the address |
| A random secret per address | So the recipient can agree, and can remove themselves, without involving you | Deleted with the address |
| Addresses that removed themselves | So they cannot be listed again by anyone | Kept until they ask for it to be deleted |
| Delivery records: address, event, time, attempts, last error | Retrying a failure, and giving up on one that will never succeed | 12 months, deleted by the server itself |
Nothing here is shared, sold, or used to build a profile.
Your IP address is not stored. Registration is rate limited by address, so one is held in memory for a few minutes to count requests, and it is never written to the database or to a log. The server's own log records the status, method and path of a request and nothing that identifies who made it.
The machine in front of the server is a separate matter and an honest policy has to say so: a reverse proxy keeps its own access log, which does contain IP addresses, and how long it keeps them is set by whoever runs it rather than by this application. That is a question for the operator named at the top of this page.
Read this part carefully, because it concerns somebody who is not you.
If you enter someone's email address, and they agree, we send them a short message when you ask to turn filtering off, and another if you change your mind. The message says that someone who asked them to know has done so. It never names a site, a category, or anything you looked at.
They did not sign up for this. You typed their address. So:
They are asked first, once. The only message that reaches a new address is an invitation: it explains that somebody listed them, what they would receive, and how to agree. Nothing else is sent unless they open the link and say yes.
Silence is a refusal. No reminder follows an invitation that goes unanswered, and nothing further is ever sent to that address. In the app you can see who has agreed and who has not, so you know whether anyone would actually be told.
Every message can end it, in one click. Each carries a link that removes that address, including the invitation itself. It needs nothing from them beyond opening it: no account, no reply, no confirmation, and you are not asked and not told. Their mail client will also show its own unsubscribe button, because the messages carry the standard header for it.
Removal is immediate and final. The address and its secret are deleted, and any message still queued to them is dropped rather than sent. Nothing is ever sent to that address again, by you or by anyone else.
Somebody can still type it into the form afterwards, and it will sit in their list looking exactly like an address that was asked and never answered. That is deliberate. Refusing to store it told the person who typed it that their save had failed, and it turned the reply into an answer to "has this address refused Sight?" for anyone who cared to ask. Listed and silent gives away nothing and delivers nothing.
Ask them first. It is their inbox, and the terms require it.
Sight is for adults setting limits on themselves. You must be 18 or older. It is not a parental control product, not a monitoring product, and it is not directed at children.
Under the KVKK and the GDPR you may ask what is held about your device, ask for it to be corrected, ask for a copy, or ask for it to be deleted. Write to info@usesight.app and we will answer within 30 days.
Deleting your data ends any waiting period recorded on the server.
Uninstalling the app does not delete the server's record. That is deliberate: a record that disappeared when you uninstalled would make uninstalling the way around the product you chose to use. Ask, and it is deleted.
If you believe we have handled your data unlawfully you may complain to the Turkish Personal Data Protection Authority (KVKK) or, in the EU, to your national supervisory authority.
Servers in the United States, at a hosting provider working for the publisher. What is processed there is only what the table above lists, and it travels over TLS.
Material changes are announced in the app before they take effect.
Written down so that the reasoning survives the person who made it.
The recipients of notifications ask for their own consent. They are third parties whose address was supplied by someone else, so the only message that reaches them before they have agreed to anything is the invitation, and it is sent on legitimate interest: one message, to ask, with a way to agree and a way to refuse in the same email.
Everything after that runs on the recipient's own consent, recorded against their address with the time they gave it. Silence is a refusal and there is no reminder. That closes the question this document previously left open, at the cost the earlier draft predicted: a user can list somebody who never answers, and then nobody is told. The app shows who has agreed, so that cost is visible rather than discovered.
What remains is ordinary. The invitation itself is unsolicited mail to somebody who did not ask for it, justified by being a single message that exists only to ask. It carries the standard unsubscribe header, refusing is one click, and a refusal is permanent and applies to every user, not only the one who listed them.
Retention periods are chosen, not derived. Twelve months for delivery records so that "was this person ever told" can be answered for a plausible period; thirty days for logs, which is long enough to investigate abuse and short enough not to become a record of who used the service.
Eighteen rather than sixteen, because the subject matter is adult content and the product is a self-control tool, not because of any consent threshold.