Privacy Policy
The short version: your source code never leaves your device, telemetry is metadata only, and memory we store is ciphertext we cannot read. The numbered sections below are the full statement.
Last updated 2026-07-01
1.Our core promise
Zero-trace by construction. Your source code never leaves your device. This is architectural, not a toggle.
2.What we collect
Account identity (email, name), device metadata, and operational telemetry that is metadata only - counts, durations, model names, token totals. Never prompt or source content.
3.Memory & encryption
Memory syncs as ciphertext (end-to-end encrypted). We store the ciphertext; we cannot read your facts. Dashboards render metadata only.
4.Subprocessors
Cloudflare (edge compute & R2), Supabase (identity, ciphertext, dashboards - RLS-isolated), Vercel (Hub hosting), Stripe (billing). Each touches only what its function requires.
5.Your rights
Access, export (.surfilpkg), correction and deletion. Deletion is honored on the tamper-evident audit chain. Contact dpo@surfil.com.
6.Retention
Operational metadata is retained for billing and audit; ciphertext memory is retained until you delete it or close your account, after which it is purged.
This is illustrative structure and posture, not final reviewed legal wording.