Data Processing Addendum
How Surfil processes data on your behalf, in plain-language sections. The zero-trace architecture keeps the processed data narrow: metadata and ciphertext, never your source.
Last updated 2026-07-11
1.Roles
You are the controller of your account and memory data; Surfil is the processor. Because source never leaves the device, most of what would normally be processed simply never reaches us.
2.Scope of processing
Surfil processes account identity, signed metadata (event names, hashes, counts, timestamps) and end-to-end-encrypted memory. It does not process source code, prompts or file contents - those stay on the device.
3.Security measures
mTLS between device and edge, Ed25519-signed batches, idempotency keys, RLS tenant isolation, ciphertext-at-rest for memory, and least-privilege RBAC on operator surfaces. Details are on the security page.
4.Subprocessors
Surfil uses the subprocessors listed on the subprocessors page and gives notice before material changes. Each is bound to equivalent protection obligations.
5.Breach notification
In the event of a personal-data breach affecting your data, Surfil notifies you without undue delay and shares what is known, what is affected, and the remediation in progress.
6.Return and deletion
On termination, Surfil returns or deletes your data on request. Memory exports as a portable, signed .surfilpkg; a clean uninstall restores every device config byte-for-byte.
This is illustrative structure and posture, not final reviewed legal wording.