Metadata, not messages.
Surf meters inference without retaining the content you send.

Scope
This notice covers the Surf website, dashboard, API, authentication, billing, and operational telemetry. It describes the data needed to provide and secure those surfaces.
What we store
We retain account identity, organization membership, API-key identifiers, billing records, and request metadata such as request ID, public model alias, token counts, latency, status, and cost.
What stays out of the ledger
Surf does not store prompts, images, tool arguments, or model completions in its usage ledger. Inference logging is disabled at the routing layer. Content still passes through the compute path to produce a response.
Processors
Cloudflare provides edge compute, database, inference, routing, and abuse protection. Polar processes checkout and billing. OAuth providers process sign-in data under their own privacy terms.
Retention and security
Operational metadata is retained only as needed for billing, security, support, and legal obligations. API keys are shown once and stored as hashes; customers remain responsible for keeping revealed keys secret.
Your choices
You may revoke API keys at any time and request access, correction, or deletion of eligible account data. Some billing or security records may be retained where the law requires it.