Data protection
What Surfil holds, how it is protected, and your rights over it. The short version: source never leaves your device, so most sensitive data is never in scope in the first place.
Last updated 2026-07-11
1.What we hold
Account identity, signed metadata built from event names, hashes, counts and timestamps, and end-to-end-encrypted memory. We do not hold source code, prompts or file contents.
2.The zero-trace boundary
The plane that sees your code runs on your device and never talks to the internet about it. Telemetry and dashboards are assembled from metadata only - this is architectural, not a setting you toggle.
3.Encryption
Memory syncs and is stored as ciphertext under end-to-end encryption; the store cannot read it. Device and edge communicate over mTLS with signed batches.
4.Retention
Metadata is retained for the dashboards and audit trail you rely on; you can export and delete your data at any time. Deletion is honoured on request, not buried in a settings maze.
5.International transfers
Processing runs on the managed edge and the subprocessors listed in the Trust Center. Because the payload is metadata and ciphertext, transfer exposure is minimal by design.
6.Your rights
Access, export, correction and deletion. Memory exports as a portable signed package, and a clean uninstall restores every device config byte-for-byte - your data leaves with you.
This is illustrative structure and posture, not final reviewed legal wording.