Surfil
// legal / privacy

Privacy Policy

The short version: your source code never leaves your device, telemetry is metadata only, and memory we store is ciphertext we cannot read. The numbered sections below are the full statement.

Last updated 2026-07-01

1.Our core promise

Zero-trace by construction. Your source code never leaves your device. This is architectural, not a toggle.

2.What we collect

Account identity (email, name), device metadata, and operational telemetry that is metadata only - counts, durations, model names, token totals. Never prompt or source content.

3.Memory & encryption

Memory syncs as ciphertext (end-to-end encrypted). We store the ciphertext; we cannot read your facts. Dashboards render metadata only.

4.Subprocessors

Cloudflare (edge compute & R2), Supabase (identity, ciphertext, dashboards - RLS-isolated), Vercel (Hub hosting), Stripe (billing). Each touches only what its function requires.

5.Your rights

Access, export (.surfilpkg), correction and deletion. Deletion is honored on the tamper-evident audit chain. Contact dpo@surfil.com.

6.Retention

Operational metadata is retained for billing and audit; ciphertext memory is retained until you delete it or close your account, after which it is purged.

This is illustrative structure and posture, not final reviewed legal wording.