Sortly

Privacy

Last updated 27 August 2026

What Sortly is

You send Sortly things you have not got time to deal with — a photograph of a letter, a screenshot, a PDF, a note. It works out what each one is, pulls out the useful parts, and either reminds you about it, puts it in your calendar, or files it so you can find it again.

Sortly is run by one person in the United Kingdom. It is invite only.

What it holds

  • What you send it. The image, file, or text itself, and what was read out of it.
  • Your email address, and a passkey credential if you made one. Sortly stores no password.
  • A notification subscription, if you allowed notifications — one per device, and only so a message can reach it.
  • Your calendar connection, if you made one: which Google account it is, which calendar you chose, and a token that can write to it.

Photographs are shrunk before they are sent

A photograph is resized in your browser to 1600 pixels on its longest edge before it is uploaded. The full-resolution original never leaves your device, and Sortly cannot recover it. That is a deliberate trade: it makes sending fast, and it means the copy Sortly holds is smaller than the one your camera took.

Reading is done by Anthropic

Working out what something is requires reading it, and Sortly does not do that itself. What you send is passed to Anthropic to be read. Under Anthropic’s API terms that content is not used to train their models.

If you would rather a particular thing was never read by anything, Sortly is the wrong place to put it.

It is encrypted, and that has a limit worth stating

Documents and calendar tokens are encrypted with AES-256-GCM before they are stored. A key is derived per person, so the database holds no readable letters and the file store holds nothing readable on its own.

This is not zero-knowledge. Every derived key comes from one master key, so whoever runs Sortly can decrypt anything in it. Keys only you hold would prevent that, and would also prevent Sortly reading your letters on your behalf, which is the entire product. The distinction is easy to blur and blurring it here would be a lie.

Your Google data

If you connect a calendar, Sortly asks for two things and uses them for one purpose each:

  • calendar.app.created: to make one calendar, called Sortly, and to manage the events it puts there. This permits nothing else: Sortly cannot see, change, or delete any calendar you already had, or any event you wrote yourself. That is enforced by Google, not by a promise made here.
  • userinfo.email: to show you which account is connected, so “connected” means something you can check.

Sortly does not ask for access to your existing calendars, and could not use it if it had it. Delete the Sortly calendar in Google Calendar and everything Sortly ever wrote goes with it, leaving the rest of your diary untouched.

Sortly’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What is never done with it

Nothing you send is sold, shared with advertisers, or used to build a profile of you. There is no advertising in Sortly and no third-party analytics watching you use it.

How long it is kept

Things you send are kept until you remove them or close your account. Removing an item removes what was read out of it and the original it came from.

Ask for your account to be closed and everything belonging to it is deleted within 30 days, including the stored files. Backups are overwritten on their own schedule and are gone within 30 days of that.

Taking it back

  • Disconnect the calendar in Settings. The stored token is deleted and nothing further is written.
  • Revoke it at Google instead, at myaccount.google.com/permissions. That works whether or not Sortly is cooperating, which is the point of it being there.
  • Ask for a copy, or for it all to go. Write to the address below. Under UK GDPR you may ask what is held, ask for it to be corrected, ask for it to be deleted, and complain to the ICO.

Where it runs

Sortly runs on a server in Germany. Reading is done by Anthropic, which may process it in the United States. Calendar entries go to Google.

Contact

Privacy·Terms