Surfil
// Trust center

Data protection

What Surfil holds, how it is protected, and your rights over it. The short version: source never leaves your device, so most sensitive data is never in scope in the first place.

Last updated 2026-07-11

1.What we hold

Account identity, signed metadata built from event names, hashes, counts and timestamps, and end-to-end-encrypted memory. We do not hold source code, prompts or file contents.

2.The zero-trace boundary

The plane that sees your code runs on your device and never talks to the internet about it. Telemetry and dashboards are assembled from metadata only - this is architectural, not a setting you toggle.

3.Encryption

Memory syncs and is stored as ciphertext under end-to-end encryption; the store cannot read it. Device and edge communicate over mTLS with signed batches.

4.Retention

Metadata is retained for the dashboards and audit trail you rely on; you can export and delete your data at any time. Deletion is honoured on request, not buried in a settings maze.

5.International transfers

Processing runs on the managed edge and the subprocessors listed in the Trust Center. Because the payload is metadata and ciphertext, transfer exposure is minimal by design.

6.Your rights

Access, export, correction and deletion. Memory exports as a portable signed package, and a clean uninstall restores every device config byte-for-byte - your data leaves with you.

This is illustrative structure and posture, not final reviewed legal wording.

More in the Trust Center