We Respect You
Not just your privacy -- but your whole self. Your time, your pace, your emotions, your journey. This is our promise, and our privacy policy.
What We Promise
Technology should serve you, not the other way around. These are the commitments we make to every person who uses SURF.
Your Autonomy
You decide when, how, and if you engage. No nudges designed to create guilt. No streaks that punish you for living your life. No manipulation. Ever.
Your Intelligence
We don't dumb things down or talk at you. You're capable of growth. We're here to support it, not direct it. You set the pace. You choose the path.
Your Attention
No attention-grabbing tactics. No infinite scrolls. No dark patterns designed to keep you tapping. Your focus belongs to you, and we refuse to steal it.
Your Emotions
We meet you where you are. Bad day? That's okay. Didn't open the app for a week? Welcome back, no judgement. We adapt to you, never the other way around.
Your Uniqueness
Neural differences aren't deficits. ADHD isn't a limitation. Anxiety isn't a weakness. Your mind works differently, and that is genuinely your strength.
Your Privacy
Your data stays yours. We protect it because respecting you means respecting all of you, including the reflections and goals you trust us with.
Privacy Policy
Effective Date: February 2026
End-to-End Encryption
All data in transit is encrypted with TLS 1.3. Your reflections, goals, and personal growth data are never transmitted in plain text.
Secure Infrastructure
Your data is stored on Supabase's secure, SOC 2 compliant infrastructure with row-level security (RLS) ensuring only you can access your records.
No Data Selling
We will never sell, trade, or share your personal data with advertisers, data brokers, or third parties. Your growth journey is not a product.
Minimal Collection
We only collect what's necessary: your email for authentication, your goals and reflections to power your experience, and payment info processed securely by Stripe.
1. Information We Collect
Account Information: Email address, display name, and optional profile photo when you create an account.
Growth Data: Goals you set, daily reflections you write, and wellness check-ins you complete. This data powers your personalized AI experience.
Payment Information: Processed securely and entirely by Stripe. We never see, store, or have access to your card numbers.
Usage Analytics: Anonymous, aggregated data via Vercel Analytics to help us improve the experience. No personal identifiers are included.
2. How We Use Your Data
Your goals and reflections are used exclusively to generate personalized AI insights, track your progress, and deliver meaningful daily messages. We use your data to serve you, not to build advertising profiles or sell to third parties.
AI analysis is performed in real-time and is specific to your account. Your data is never used to train general AI models or shared across users.
3. Third-Party Services
Supabase: Authentication and secure database hosting with row-level security.
Stripe: Payment processing. They operate under their own privacy policy and PCI DSS compliance.
Vercel: Application hosting and anonymous analytics.
AI Provider: AI-generated insights via the Vercel AI Gateway. Your prompts are not stored or used for model training.
4. Data Retention & Deletion
Your data is retained for as long as your account is active. You may request complete deletion of your account and all associated data at any time by contacting us. Upon deletion, all personal data, goals, reflections, and AI insights are permanently removed within 30 days.
5. Your Rights
You have the right to access, correct, export, or delete your personal data. You can cancel your subscription and stop using SURF at any time, no questions asked. We believe your data is yours, period.
6. Contact
Questions about your privacy or this policy? We want to hear from you.
privacy@surf.appBecause technology should serve you, not the other way around.