Privacy Policy
Last updated July 2026
The short version
We make money from subscriptions, not advertising. We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.
We collect the data needed to run Surf: your account details, the content and interactions you create, and limited technical and device information.
Some AI features run in your browser and some run on servers we rent. We say which is which rather than implying it all stays on your device.
You can access, correct, download, or delete your data, and you can object to or limit certain processing. Because we do not sell or share personal information, there is no advertising opt-out to exercise.
This summary is for convenience only; the full policy below governs.
1. Introduction and Scope
This Privacy Policy (“Policy”) explains how Surf Platforms Inc., a corporation organized under the laws of the State of Delaware with its principal place of business in San Jose, California (“Surf,” “Company,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects information in connection with the Surf and Surf Social applications, websites, application programming interfaces, and related services (collectively, the “Platform”).
This Policy is incorporated by reference into our Terms of Service and End User License Agreement. Capitalized terms not defined here have the meanings given in those documents. By accessing or using the Platform, you acknowledge that you have read and understood this Policy.
The Platform is operated from the United States and is currently offered to users in the United States. We do not target the Platform at, or monitor the behaviour of, individuals in the European Economic Area, the United Kingdom, or Switzerland. If you are a California resident, or a resident of another U.S. state with a comprehensive privacy law, the region-specific sections below supplement this Policy and control in the event of any conflict.
2. Information We Collect
Information you provide to us. This includes the information you submit when you create an account (such as your name or display name, username, email address, and date of birth or age confirmation), the content you create, post, upload, or send (“User Content”), your profile information and settings, the messages and communications you exchange on the Platform, and the information you provide when you contact support, respond to surveys, or report a problem.
Subscription and payment information. If you purchase a paid subscription, our third-party payment processors collect and process your payment details. We do not store full payment card numbers. We retain limited billing records (such as transaction identifiers, plan, amount, and renewal dates) as required to operate subscriptions and to meet tax, accounting, and legal obligations.
Information we collect automatically. When you use the Platform, we and our service providers may collect limited technical information, including device and app identifiers, device type and operating system, app version, language and regional settings, IP address, approximate (city- or region-level) location derived from IP address, crash and diagnostic logs, and information about how you interact with features, including which posts were shown to you and where they ranked. We use this information to operate, secure, debug, and improve the Platform.
Precise location. Some optional features, such as the map, ask your browser or device for precise location. If you grant that permission, we store your most recent coordinates on your account so the feature works when you return. Precise location is never collected unless you grant the permission, it is never used for advertising, and when your position is shown to other people it is offset by roughly 500 meters and limited to the audience you choose. You can revoke the permission in your browser or device settings at any time, and you can ask us to delete the stored coordinates.
Information collected by your browser directly. Two things happen in your browser rather than on our servers, and both disclose your IP address to a third party we do not control: during signup, a geolocation lookup is made to ipapi.co to preselect your country and language; and where a feature runs a model on your device, the model files themselves are downloaded from public content-delivery networks operated by Hugging Face, jsDelivr, and Google. Those providers receive the request and your IP address in the ordinary course of serving the file. They do not receive your content.
Information from other sources. If you choose to sign in through, or connect, a third-party service, we may receive limited information from that service consistent with your settings there. We may also receive information from service providers that help us prevent fraud and abuse.
We do not require, and we ask you not to submit, special categories of sensitive personal information except where you voluntarily include it in User Content. We do not use sensitive personal information to infer characteristics about you for advertising.
3. How We Use Information
We use the information described above to: (a) provide, maintain, and operate the Platform and your account; (b) process subscriptions, billing, and renewals; (c) personalize your experience and operate the feed and discovery features according to the controls you set; (d) communicate with you about your account, transactions, security, and changes to our terms or policies; (e) provide customer support and respond to your requests; (f) maintain the safety, security, and integrity of the Platform, including detecting, investigating, and preventing fraud, abuse, spam, and violations of our terms; (g) develop, test, and improve features and the overall service; (h) comply with legal obligations and enforce our agreements; and (i) for other purposes disclosed to you at the time of collection or to which you consent.
Legal bases (EEA/UK). Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of our contract with you (to provide the Platform and your account); our legitimate interests (to secure and improve the Platform, prevent abuse, and operate our business), balanced against your rights; compliance with legal obligations; and your consent where required (for example, for certain optional features or communications), which you may withdraw at any time.
Training and model improvement. We do not train artificial-intelligence models on your content, and our agreements with the model providers named in Section 4 prohibit them from training on it either. For end-to-end encrypted conversations we hold only ciphertext, so training on them would not be possible in any case.
6. Where AI Features Run, and Biometrics
Some features run models locally on your device and some run them on servers, and the difference matters. Local: detecting the position of a face to frame or apply an effect, separating a subject from its background, an advisory screen of an image for unsafe content before upload, and computing similarity between media on your device. For those, the media itself does not leave your device for that step, although the model file is downloaded from a third-party network as described in Section 2. Server-side: summarizing, translating, transcribing, answering questions, generating or improving text, describing images, and the authoritative moderation scan of uploaded media. Those send the relevant content to a model provider named in Section 4. We describe which features are which in the product, and we do not claim that Surf’s AI runs entirely on your device.
We do not guarantee the accuracy, reliability, or completeness of any automated or AI-assisted output, including content classification, search results, ranking, recommendations, or captions. You should not rely on such output as professional advice.
Biometric information. Our camera and media features detect that a face is present in order to frame or apply effects to media; it is not designed to recognize or identify who you are, and we do not create, store, or use a biometric template, faceprint, or voiceprint to identify you. If any feature ever collects or uses biometric identifiers or biometric information as defined by applicable law (such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, or the Washington biometric privacy law), we will first provide a specific notice, obtain any consent required by law, and publish a retention and destruction schedule for that data before the feature is made available to you.
7. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Platform, and thereafter only as necessary to comply with our legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements.
When you delete your account, we delete or de-identify your personal information within thirty (30) days, except for: (a) information we are required to retain by law (for example, certain billing and tax records); (b) limited information necessary to prevent fraud, abuse, or ban evasion, or to protect safety; (c) content that you shared with others who retain their own copies; and (d) residual copies in routine backups, which are overwritten on a rolling basis.
Specific retention windows we operate today: engagement signals, 90 days; search history, 90 days; records of which posts were shown to you and where they ranked, 30 days; short-term feed de-duplication records, 7 days; the longer record of posts you have already seen, 365 days; read notifications, 90 days, and unread notifications, 365 days; records of AI usage, aggregated and pruned at 90 days; cached results of automated media scanning, 90 days. Account deletion is scheduled 30 days out and can be cancelled by signing back in during that window, after which the purge is irreversible.
Where we are legally required to preserve specific information (for example, in response to a valid legal process or to comply with the TAKE IT DOWN Act or child-safety reporting laws), we retain that information for the period required.
8. Your Choices
Account information. You can review and update most of your account information directly in your settings. You can adjust your feed and personalization controls at any time.
Communications. You can opt out of non-essential email by following the unsubscribe instructions in those messages or adjusting your notification settings. We may still send you transactional and service messages (for example, security alerts and billing notices).
Access and portability. You can download a machine-readable copy of your profile, posts and replies, bookmarks, and follow lists directly from your settings. That download is a convenience feature and is not the whole of what we hold: for a complete copy, including categories not covered by the in-app download, submit a request as described in Section 13 and we will provide it within the time the law allows.
Deletion. You can delete your account at any time through your account settings, subject to the retention exceptions described above.
Opt-out preference signals. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no such processing for an opt-out preference signal such as Global Privacy Control to stop. If we ever introduce processing that a signal of that kind would apply to, we will honor the signal and say so here before doing so.
9. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this Policy. In the preceding twelve (12) months, we have collected the categories of personal information described in Section 2 (identifiers; customer records; commercial information such as subscription history; internet or other electronic network activity; approximate geolocation; and the contents of communications and User Content you create). We collect this information for the business and commercial purposes described in Section 3, from the sources described in Section 2, and disclose it to the categories of recipients described in Section 4.
Sensitive personal information. If you turn on a feature that uses precise location, we collect and store precise geolocation, which is sensitive personal information under California law. We use it only to provide the feature you asked for and for security, never to infer characteristics about you and never for advertising, so no right to limit its use and disclosure applies. We do not collect account log-in credentials in combination with a security code, government identifiers, health, biometric, racial or ethnic origin, religious belief, union membership, sex life, or sexual orientation data, except to the extent you voluntarily include such information in content you post.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). We have not done so in the preceding twelve (12) months, including with respect to consumers we know to be under sixteen (16) years of age. We retain each category of personal information for the periods stated in Section 7, or for as long as reasonably necessary for the purpose it was collected for, whichever is shorter.
Subject to certain exceptions, California residents have the right to: (a) know and access the specific pieces and categories of personal information we have collected; (b) delete personal information we have collected; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information (which we do not do); and (e) limit the use and disclosure of sensitive personal information (we do not use sensitive personal information for purposes that require an opt-out). We will not discriminate or retaliate against you for exercising any of these rights.
You may submit a request as described in Section 13 (“How to Exercise Your Rights”). You may use an authorized agent to submit a request on your behalf, subject to verification. We will verify your request using the information associated with your account.
10. EEA and UK Privacy Rights (GDPR)
The Platform is not currently offered to users in the European Economic Area, the United Kingdom, or Switzerland, and we have not appointed an Article 27 representative or a Data Protection Officer. This section describes the rights we would honor, and will honor, if and when we make the Platform available there. Surf Platforms Inc. would be the controller of your personal data for the purposes described in this Policy.
Automated processing. Your feed is ordered by an automated ranking system. It scores candidate posts using the weights you set yourself, your engagement history, and a multiplier tied to the author’s subscription tier. It decides only what order content appears in; it produces no legal effect and nothing similarly significant, it never determines eligibility for a service, and you can switch it off entirely and read a strictly reverse-chronological feed instead.
Subject to the conditions in applicable law, you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict or object to processing (including processing based on legitimate interests); data portability; and withdraw consent at any time where processing is based on consent, without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority.
International transfers. We are based in the United States, and your data will be processed in the United States and in other countries where we or our service providers operate. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.
EU/UK representative and Data Protection Officer. If and when we offer the Platform to users in the EEA or UK, we will appoint and identify any legally required EU/UK representative and Data Protection Officer here, and we will comply with applicable obligations under the GDPR and the EU Digital Services Act. Until then, contact us at legal@surfplatforms.com.
11. Other U.S. State Privacy Rights
Depending on your state of residence (for example, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, and other states with comprehensive privacy laws), you may have the right to confirm whether we process your personal data and to access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in targeted advertising, we do not sell personal data, and we do not carry out profiling of that kind.
Appeals. If we decline to act on your request, we will tell you why. You may appeal that decision within a reasonable period by replying to our response or by writing to legal@surfplatforms.com with the word “appeal” in the subject line. We will respond to an appeal in writing within forty-five (45) days, stating the reasons for our decision. If we deny the appeal, we will provide you with a method to contact your state attorney general to submit a complaint.
12. Children’s Privacy
The Platform is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Where the law of your state sets a higher minimum age, or requires verifiable parental consent below a stated age, we apply that requirement instead. If you are a parent or guardian and believe a child under 13 has provided us with personal information, contact us at legal@surfplatforms.com and we will delete it and terminate the account.
Age is established by the date of birth you enter when you create an account. We do not currently use identity documents or age-estimation technology, so we rely on that declaration and on reports. Where we have actual knowledge that a user is under 13, we delete the account and the associated personal information. Accounts we know to belong to users under 18 receive stricter privacy, contact, and content defaults that are enforced on our servers, and some of those protections cannot be turned off.
13. How to Exercise Your Rights
You can exercise many choices directly in your account settings. To submit a privacy request (access, correction, deletion, portability, or a question), use the “Data or privacy request” category of the form at surfplatforms.org/report, which creates a tracked record and returns a reference number, or write to legal@surfplatforms.com. Both reach the same team.
We will verify your identity before fulfilling a request, generally using information associated with your account, and we will respond within the timeframes required by applicable law. There is no charge to exercise your rights, except that we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive, as permitted by law. If we decline a request, we will explain why, to the extent the law requires.
14. Security and Data Breach Notification
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, and alteration. These include transport encryption on all traffic, row-level access control enforced in the database rather than only in the application, least-privilege access for staff, an append-only audit log of moderation actions, and a strict content-security policy. Data at rest is encrypted by our infrastructure providers under their standard practices. One-to-one direct messages, and group conversations of up to 256 participants, are end-to-end encrypted on your device by default, with no setting to turn off and no plaintext fallback. Their contents are not readable by our servers. Group conversations larger than 256 participants are not end-to-end encrypted, because the group key scheme does not extend past that size; those messages are stored on our servers and the app shows no lock on them. We have not yet completed a SOC 2, ISO 27001, or third-party penetration test, and we do not claim any certification.
No method of transmission or storage is completely secure, and security depends in part on factors outside our control, including your own devices, networks, and credentials and the systems of third parties. Accordingly, while we work hard to protect your information, we cannot and do not guarantee absolute security, and our security measures are described as a description of our practices and not as a warranty or guarantee.
In the event of a data breach affecting your personal information, we will investigate, take steps to mitigate and remediate, and notify affected users and applicable regulators where and within the timeframes required by applicable law (for example, U.S. state breach-notification laws and, where applicable, the 72-hour notification requirement under the GDPR). Notification of a breach is not by itself an acknowledgment of fault or liability.
You play an important role in security. Keep your credentials confidential, use a strong and unique password, enable available security features, and notify us immediately at contact@surfplatforms.com if you believe your account or data is no longer secure. We welcome good-faith security research. If you find a vulnerability, report it to contact@surfplatforms.com with enough detail for us to reproduce it and give us a reasonable opportunity to fix it before disclosing it publicly. So long as you act in good faith, stay within the scope of your own account and test data, do not access, modify, or exfiltrate anyone else’s data, do not degrade the service, and comply with this paragraph, we authorize your testing for the purposes of the Computer Fraud and Abuse Act and comparable state laws, and we will not pursue or support legal action against you for it.
15. Third-Party Services and Links
The Platform may link to or integrate with third-party websites, services, or content that we do not control. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party service you use. We are not responsible for the privacy practices of third parties.
16. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will provide notice through the Platform, by email, or by other means reasonably calculated to reach you, and we will update the “Last updated” date below. Changes are effective when posted unless otherwise stated. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy, except where additional consent is required by law.
17. Contact Us
California Shine the Light. California Civil Code section 1798.83 permits California residents to request information about a business’s disclosure of personal information to third parties for those parties’ own direct marketing purposes. We do not disclose personal information for that purpose. You may confirm this by writing to legal@surfplatforms.com with “Shine the Light” in the subject line.
If you have questions, concerns, or requests regarding this Policy or your personal information, contact us at:
Surf Platforms Inc., Attn: Privacy, legal@surfplatforms.com, San Jose, California, United States.
Looking for our privacy philosophy and product commitments? See the Privacy overview.