Surfil
// Trust center

Data Processing Addendum

How Surfil processes data on your behalf, in plain-language sections. The zero-trace architecture keeps the processed data narrow: metadata and ciphertext, never your source.

Last updated 2026-07-11

1.Roles

You are the controller of your account and memory data; Surfil is the processor. Because source never leaves the device, most of what would normally be processed simply never reaches us.

2.Scope of processing

Surfil processes account identity, signed metadata (event names, hashes, counts, timestamps) and end-to-end-encrypted memory. It does not process source code, prompts or file contents - those stay on the device.

3.Security measures

mTLS between device and edge, Ed25519-signed batches, idempotency keys, RLS tenant isolation, ciphertext-at-rest for memory, and least-privilege RBAC on operator surfaces. Details are on the security page.

4.Subprocessors

Surfil uses the subprocessors listed on the subprocessors page and gives notice before material changes. Each is bound to equivalent protection obligations.

5.Breach notification

In the event of a personal-data breach affecting your data, Surfil notifies you without undue delay and shares what is known, what is affected, and the remediation in progress.

6.Return and deletion

On termination, Surfil returns or deletes your data on request. Memory exports as a portable, signed .surfilpkg; a clean uninstall restores every device config byte-for-byte.

This is illustrative structure and posture, not final reviewed legal wording.

More in the Trust Center