Privacy Policy
Last updated: September 2026
This summary says what Surf collects, what it is used for, who else sees it, and what you can do about it. The full Privacy Policy referenced in Section 11 is the one that governs.
1. Information We Collect
Account information: your email address, username, display name, date of birth, and the profile details you choose to add. If you complete the optional identity verification, the name, date of birth, country and region you type in, and a one-way value derived from them that stops one person verifying two accounts. We never ask for or store an identity document.
Content you create: posts, shorts, stories, threads, polls, comments, messages, and the media you upload.
How you use Surf: likes, follows, views, searches, watch time, which posts were shown to you and where they ranked, plus device, log and approximate location derived from your IP address at our host's edge. In the shorts editor, which of the AI's edits you keep, change or remove on the shorts you publish, and which cut of a one-tap edit you ship. Precise location is collected only if you turn on a feature that asks for it and grant the permission.
How each visit went: when it began, whether a notification, another site or you opened it, the page it landed on, whether Surf ran as an installed app, and how far down the feed you went. Also the steps you take through signup, the composer and the notification and install prompts, whether you opened or swiped away a notification on your device, how you reached a profile you visited or an account you followed, and where you first came to Surf from (a campaign tag, the site that sent you, an invite or a shared post, never the full address you came from).
When you share a post, which way you shared it and how many times the link was opened. The link carries a code that ties those opens to your share and to anyone who joins through it; it never identifies who opened it. When someone who is not signed in opens a post, we count the view and the site they came from, and nothing about them.
Each consent you give or withdraw, with the version of the notice you answered, so we can show it and ask again when a notice changes.
Subscription and payout information: plan, amount, renewal dates and transaction identifiers. Card details go straight to Stripe and never reach our servers. If you take payouts, Stripe collects your identity and tax details directly.
Safety records: each moderation decision about you or your content, with its reasons, who or what decided it, and any appeal, which you can read in Account status; a copy of a profile picture or profile text taken down, kept privately where only you and our staff can see it; the history of your account's trust level and the signals it was read on; and the actions a rate limit refused.
Reports: what you reported and why. Someone who reports without an account may leave an email address to hear the outcome, and we keep a one-way value derived from the connection the report came from, so one person cannot flood the form.
2. How We Use It
To run Surf: deliver your content, sync your devices, process subscriptions and payouts, and keep your account secure.
To rank your feed and suggest things to you, using your own activity and the controls you set. Every one of those controls is yours to change, and you can switch to a plain reverse-chronological feed at any time. When you turn off learning from what you do, the feed stops building a profile of your interests from your activity and deletes the one it had built. For an account under 18, or one with no date of birth, that learning starts off: the feed ranks by the topics picked and the accounts followed until the account turns learning on.
To shape the editor's AI to how you edit, from the edits you kept and the cuts you chose. You can erase that in settings under Your data, and it is collected only from an account whose date of birth shows an adult.
To see whether Surf works: how many people visit and come back, where signup and the composer lose people, and whether a record we rely on has stopped arriving. Those figures are read in aggregate by our team.
If you use Creator Studio, to measure your own account for you: how your posts reached people, how long they were watched, and how a post you made from a Studio suggestion did against your usual post, so its later suggestions learn what works for you.
To keep Surf safe, to answer you, and to meet our legal obligations. We make money from subscriptions and from a fee on creator earnings. We do not run ads, we do not sell your personal information, and we do not share it for cross-context behavioral advertising.
We do not train AI models on your content, and our agreements with the model providers we use forbid them from doing so.
3. End-to-End Encrypted Messages
One-to-one conversations, and group conversations up to 256 people, are end-to-end encrypted on your device. There is no switch to turn it off and no plaintext fallback. We hold ciphertext, so we cannot read the contents, and nothing on our servers reads them on its own. Groups larger than 256 are not encrypted, and the app shows no lock on them.
Some things inside an encrypted conversation are not encrypted, and we would rather list them. Your messages, a poll's question and options, a voice note and its transcript, an attachment and its filename, a shared location card and a shared contact are sealed. Our servers do see that the conversation exists and who is in it, when each message was sent, delivered and read, reactions and who added them, a poll's running tally and who voted for what, the moves in a game and their order, and, if you start a live location share, the exact coordinates it reports while it runs.
Translating a message, transcribing a voice note and searching your chats run on your device, over the copy it has decrypted, so the readable text is never sent to us.
The one exception is a summary you ask for. When you tap Summarize with AI in a chat and agree, your device sends that chat's recent decrypted messages to our servers once, only to write the summary, and our servers pass them to the model provider, Microsoft. We do not store or log them, and neither we nor Microsoft train AI on them; Microsoft may keep them for up to 30 days solely to detect abuse. Nothing is sent unless you ask for that summary.
4. On-Device AI, and What Runs on Servers
On your device: finding a face to frame a shot or apply a lens, separating a subject from its background, screening an image before you upload it, sorting text into topics, translating a decrypted message, transcribing a voice note before it is encrypted, and the liveness measurement in identity verification. The content does not leave your device for those steps, although the model file is downloaded from Hugging Face, jsDelivr or Google, which see your IP address the way any site you visit does.
On servers: summarizing, translating a public post, answering questions, generating or improving text, describing an image, transcribing uploaded audio, turning a spoken search into words, reading text aloud, building the embeddings behind search from a post's words and pictures, comparing a picture you search by, or attach to a post, with the pictures already posted, the moderation scan that decides whether uploaded media may be shown, and a policy reading of the words people publish, which is how we find threats, hate, harassment, scams and grooming, and how we notice that someone might be in crisis and offer them help. Those send the relevant content to a provider named in the full Privacy Policy.
When a picture you attach carries Content Credentials or a generator's own tag, the original file is read on our servers for that statement before the copy we store drops it, and only the statement is kept, with that upload alone, until the upload is deleted.
The policy reading covers posts and replies, the text in their images and the speech in their audio, story text, profile names, usernames and bios, the names and descriptions of spaces, communities and public groups, live chat messages, the title and description of a page you link to, and a question you put to @ask. A live chat message it finds breaking the rules is taken down at once. Anything else it finds goes to a person, and the words it was about are kept with that review so the decision can be checked and undone.
Face detection is not face recognition. It finds that a face is present; it does not work out whose. Identity verification does measure face geometry, on your device, and no image or video of you is ever transmitted or stored. The full policy sets out the biometric notice, the retention schedule and the destruction schedule that govern it.
5. Who Else Sees It
Other people, according to the settings you choose. Anything you post publicly is public, and anyone you share with can keep their own copy.
While profile views are on in your settings, a Sapphire member can see that you visited their profile, and if you are one you can see who visited yours. Turning profile views off hides both, and stops recording your visits.
Service providers under contract, who may use it only to work for us: Vercel, Supabase, Cloudflare, Microsoft, Stripe and Resend.
Parts of the product load from a company we do not act through, which sees your IP address in order to deliver them: map tiles, the GIF picker, music previews, model files, the sign-in captcha, an embedded video player, and web push. The full policy lists each one and what it receives.
We do not sell your personal information. We disclose it when valid legal process requires it, or to protect people from harm, and we scrutinize every request we get.
6. Supervised Accounts
An account under 18 can be supervised by up to two guardians, and only if both sides agree. It is never a condition of having an account.
While supervision is active, a guardian can see screen time, published posts and stories, who the account follows and who follows it, how many likes and comments it gives, and safety alerts, and can set limits. A guardian never sees what the account searches for or likes, or the contents of an encrypted message. Messages and searches are checked on the device against safety patterns; where a match is serious, a guardian sees a category and a severity, never the words.
Supervision and every under-18 protection end automatically at 18.
7. How Long We Keep It
Your content stays until you delete it or your account. Deleting your account is scheduled 30 days out, and during that window you can withdraw the request from settings. Signing back in does not withdraw it, on purpose. After the window it cannot be undone.
Records of what you do are kept for a fixed time and then deleted, every night, by the same schedule this list is written from:
Kept 30 days, then deleted: which posts you were shown and where they ranked.
Kept 90 days, then deleted: likes, dwell and other engagement signals; when each visit began, how it was opened and how far the feed went; steps through signup, the composer and permission prompts; the day each view was counted; profiles you visited and how you got there; stories you watched; what you searched for; your recent searches; who you sent a post to; and which AI features you used and what they cost.
Kept 180 days, then deleted: how long each video was watched; how close you are to the accounts you engage with, as the feed learned it; the topics the feed learned you like; which edits the editor's AI made that you kept, changed or removed; which cut of an auto-edit you chose, and how its post was watched; and the editing style the editor learned from you.
Kept 365 days, then deleted: which posts you have viewed; posts your feed will not show you again; posts you have seen; posts you shared, where to, and how often each link was opened; accounts you unfollowed; suggestions you dismissed; your daily time in the app; the devices you are signed in on, with their address and approximate location; and your notifications and whether you opened or dismissed them.
Kept 730 days, then deleted: views of a post from outside Surf, by referring site, with nothing about the visitor.
Kept for the life of your account: each consent you gave or withdrew.
An auto-edit is planned from a transcript and face positions that are deleted within the hour. Some things are longer because they have to be: billing records the law makes us keep, a value derived from an email address that has used a free trial, and the history of usernames an account has held.
A media file is removed from our storage when you delete it, and a copy already held in a delivery cache ages out after that.
Safety records follow the account: a moderation decision and a held copy of your profile stay until your account is deleted, trust history is kept 180 days, and refused actions 90 days. An email address left on a report without an account is deleted once the outcome is sent, and the connection value after 30 days.
8. Your Rights
Wherever you live, you can see and change most of your information in settings, download a complete copy of what we hold about you (your profile, your content, and every record listed in section 7, as far back as we keep it), and delete your account, which deletes those records with it.
Depending on where you live, you may also have the right to a complete copy of what we hold, to correct it, to have it deleted, to a portable copy, and to opt out of any sale, sharing or targeted advertising. We do none of those three, so there is nothing for an opt-out preference signal such as Global Privacy Control to stop. If we ever introduce processing one would apply to, we will honor the signal and say so here first.
To make a request, use the data and privacy category of the form at surfplatforms.org/report, which gives you a tracked reference, or write to legal@surfplatforms.com. We verify requests, answer within the time the law allows, and never treat you differently for asking.
9. Security
Encryption in transit on everything, encryption at rest by our infrastructure providers, access control enforced in the database rather than only in the app, least-privilege staff access, and an append-only record of every moderation action. We have not completed a SOC 2, an ISO 27001, or a third-party penetration test, and we claim no certification.
No system is perfectly secure, and security also depends on your device, your network and your password. This describes our practices; it is not a warranty.
If a breach affects your personal information we will investigate, act to contain it, and notify you and the regulators the law requires within the time the law requires. Tell us at once at contact@surfplatforms.com if you think your account is no longer secure. We welcome good-faith security research at the same address.
10. Children
Surf is not for anyone under 13, we do not knowingly collect their information, and an account we learn belongs to someone under 13 is removed along with its data. Accounts we know belong to someone under 18 start closed rather than open, with stricter privacy, contact and content defaults enforced on our servers, some of which cannot be switched off. We show no targeted advertising to anyone.
11. The Full Policy
This is a summary. The Privacy Policy that governs is at surfplatforms.org/privacy-policy, it is incorporated into our Terms of Service by reference, and it carries the detail this page leaves out, including the complete list of third parties, the biometric notice, every retention period, and the region-specific rights that apply to you. Where this summary and the full policy differ, the full policy controls. Our Terms of Service, End User License Agreement and Community Guidelines are at surfplatforms.org/terms, surfplatforms.org/eula and surfplatforms.org/guidelines.
12. Changes
We update this policy as Surf changes. Where a change is material we will tell you in the app or by email before it takes effect, and we will update the date above.