Last updated: 18 September 2026.
Sight is published by TAPTAKE BİLİŞİM (contact@taptake.net). Questions, requests and complaints: info@usesight.app.
Sight does not record what you browse. There is no history, no list of pages visited, no analytics, no advertising, and no third party receives anything about you except the mail provider that delivers messages you asked for, the app store the app was installed from, and, where the operator serves the block lists through a content network, that network. It is sent no token and no identifier: it sees an address asking for a file, the way any download does.
What leaves your phone is the small amount needed to make a waiting period survive a reinstall, and the email addresses of the people you chose to be told when you ask to turn filtering off.
A device identifier. Android's ANDROID_ID,
specific to this phone and to this app's signing key, or on iOS an identifier
created for this installation and kept in the device's keychain. It is sent so
a waiting period can be held against something that survives the app's data
being cleared. Without it, reinstalling would end a wait, and the wait is the
point.
How long your device thinks a wait has left. A duration in milliseconds. Never a date, never a time of day. The countdown deliberately never reads a clock, so there is no clock reading to send.
Email addresses you enter, if you choose to name anyone. At most three.
A token this device was issued, on each request, so the server can tell your device from someone else's.
Your IP address is visible to the server, as it is to every server you connect to. It is used to limit how often the same address can register a device or save a list of people to tell, and it is not written down. The reverse proxy in front of the server keeps its own access log, which is ordinary for any web server and is described at the end of this page.
Photographs are examined on your phone. The model that examines them is downloaded to the device and runs there. No image and no score for an image is uploaded, and none is written to storage.
The subscription is sold by the app store, not by us. Google Play or the App Store takes the payment, holds the payment details and handles cancellation and refunds. We never see a card number, a billing address or a name.
The app asks the store one question on every launch: does this installation have a subscription. It asks whether or not you have one, because that is how it finds out, so the store knows the app ran even if you never buy anything. What the store does with that is covered by the store's own privacy policy, not by this one.
What the app receives back is one answer: whether this installation has an active subscription. It is kept on the phone and nothing else is read from it. No purchase, no receipt and no subscription state reaches the Sight server, which has no column for it, so the server cannot tell a subscriber from anyone else and neither can we.
The store's own handling of the purchase is governed by the store's privacy policy, which is a document we neither write nor control.
On Android, Sight keeps cookies and site storage like any browser, because no site can be logged into without them. On iOS the web view uses a non-persistent store, so nothing is written to disk at all and a login does not outlive the session.
It does not keep a cache of the images and video it filters. That cache existed and was removed: the media it held was from the sites being filtered, which is precisely the content that may be withheld, and keeping a recoverable copy of a picture the filter refused to show is not filtering. The cost is that scrolling back re-downloads.
The sites and words you add to your own lists are kept on your phone and nowhere else. They are never sent to the server, never included in a notification, and never read by anything but the filter on the device. What a person chose to keep away from themselves is theirs.
No browsing history is kept anywhere, by design and from the first version.
| What | Why | How long |
|---|---|---|
| Device identifier | So a wait survives a reinstall | Until you ask for it to be deleted |
| When a wait ends | The wait itself | Cleared when the wait ends or is cancelled |
| A SHA-256 hash of the device's token | Authentication. The token itself is never stored, so a copy of the database yields no working credentials | Until replaced or deleted |
| Email addresses you entered | Asking the recipient whether they agree, and sending the messages you asked for once they do | Until you remove them, or until the recipient does |
| Whether the recipient agreed, and when | So nothing is sent to somebody who has not, and so somebody who already agreed is not asked again when you list them a second time | Until they remove themselves, or until you ask for your data to be deleted |
| A random secret per address | So the recipient can agree, and can remove themselves, without involving you | Kept with the agreement above, and deleted with it |
| Addresses that have been asked once | So the same address is never invited twice, however many times a list is saved | Kept until they ask for it to be deleted |
| Addresses that removed themselves | So they cannot be listed again by anyone | Kept until they ask for it to be deleted |
| Delivery records: address, event, time, attempts, last error | Retrying a failure, and giving up on one that will never succeed | 12 months, deleted by the server itself |
Nothing here is shared, sold, or used to build a profile.
Your IP address is not stored. Three things are rate limited, because each of them can be used to send mail to people: registering a device, saving the list of people to tell, and starting or cancelling a wait. The first two count by IP address. The third counts by the token your device was issued, and falls back to the IP address only for a request that arrives without one. Each counter is held in memory for as long as its own window lasts, a minute for registration and an hour for the other two, and none of them is written to the database or to a log. The server's own log records the status, method and path of a request and nothing that identifies who made it.
The machine in front of the server is a separate matter and an honest policy has to say so: a reverse proxy keeps its own access log, which does contain IP addresses, and how long it keeps them is set by whoever runs it rather than by this application. That is a question for the operator named at the top of this page.
Read this part carefully, because it concerns somebody who is not you.
If you enter someone's email address, we send one invitation asking whether they agree. If they do, we send them a short message when you ask to turn filtering off, another if you change your mind, and another if the app is removed and put back while a wait is running. The message says that someone who asked them to know has done so. It never names a site, a category, or anything you looked at.
They did not sign up for this. You typed their address. So:
They are asked first, once. The only message that reaches a new address is an invitation: it explains that somebody listed them, what they would receive, and how to agree. Nothing else is sent unless they open the link and say yes.
Silence is a refusal. No reminder follows an invitation that goes unanswered, and nothing further is ever sent to that address. In the app you can see who has agreed and who has not, so you know whether anyone would actually be told.
Every message can end it. Each carries a link, including the invitation itself. It opens a page with a single button, and pressing that button removes the address. Opening the link alone changes nothing, deliberately: mail gateways follow every link in a message to scan it, and a link that acted on being opened would have them deciding on the recipient's behalf. Nothing else is asked: no account, no reply, and you are not asked and not told. Their mail client will also show its own unsubscribe button, because the messages carry the standard header for it.
Removal is immediate and final. The address and its secret are deleted, and any message still queued to them is dropped rather than sent. Nothing is ever sent to that address again, by you or by anyone else.
Somebody can still type it into the form afterwards, and it will sit in their list looking exactly like an address that was asked and never answered. That is deliberate. Refusing to store it told the person who typed it that their save had failed, and it turned the reply into an answer to "has this address refused Sight?" for anyone who cared to ask. Listed and silent gives away nothing and delivers nothing.
Ask them first. It is their inbox, and the terms require it.
Sight is for adults setting limits on themselves. You must be 18 or older. It is not a parental control product, not a monitoring product, and it is not directed at children.
Under the KVKK and the GDPR you may ask what is held about your device, ask for it to be corrected, ask for a copy, or ask for it to be deleted. Write to info@usesight.app and we will answer within 30 days.
Deleting your data ends any waiting period recorded on the server.
Uninstalling the app does not delete the server's record. That is deliberate: a record that disappeared when you uninstalled would make uninstalling the way around the product you chose to use. Ask, and it is deleted.
If you believe we have handled your data unlawfully you may complain to the Turkish Personal Data Protection Authority (KVKK) or, in the EU, to your national supervisory authority.
Servers in the United States, at a hosting provider working for the publisher. What is processed there is only what the table above lists, and it travels over TLS.
Material changes are published on usesight.app, and the date at the top of this page says when it last changed.
Written down so that the reasoning survives the person who made it.
The recipients of notifications ask for their own consent. They are third parties whose address was supplied by someone else, so the only message that reaches them before they have agreed to anything is the invitation, and it is sent on legitimate interest: one message, to ask, with a way to agree and a way to refuse in the same email.
Everything after that runs on the recipient's own consent, recorded against their address with the time they gave it. Silence is a refusal and there is no reminder. That closes the question this document previously left open, at the cost the earlier draft predicted: a user can list somebody who never answers, and then nobody is told. The app shows who has agreed, so that cost is visible rather than discovered.
What remains is ordinary. The invitation itself is unsolicited mail to somebody who did not ask for it, justified by being a single message that exists only to ask. It carries the standard unsubscribe header, refusing is one click, and a refusal is permanent and applies to every user, not only the one who listed them.
Retention periods are chosen, not derived. Twelve months for delivery records, so that "was this person ever told" can be answered for a plausible period, and the server deletes them itself.
The application keeps no log of its own. It writes to standard output, which carries counts and row identifiers and no address or device identifier, so there is nothing there to set a period on. What the machine running it does with that output, and what the reverse proxy keeps in its own access log, is the operator's, and is described above.
Eighteen rather than sixteen, because the subject matter is adult content and the product is a self-control tool, not because of any consent threshold.