LEGAL / PRIVACY

Metadata, not messages.

Surf meters inference without retaining the content you send.

Abstract contour boundary surrounding an empty protected core
01

Scope

This notice covers the Surf website, dashboard, API, authentication, billing, and operational telemetry. It describes the data needed to provide and secure those surfaces.

02

What we store

We retain account identity, organization membership, API-key identifiers, billing records, and request metadata such as request ID, public model alias, token counts, latency, status, and cost.

03

What stays out of the ledger

Surf does not store prompts, images, tool arguments, or model completions in its usage ledger. Inference logging is disabled at the routing layer. Content still passes through the compute path to produce a response.

04

Processors

Cloudflare provides edge compute, database, inference, routing, and abuse protection. Polar processes checkout and billing. OAuth providers process sign-in data under their own privacy terms.

05

Retention and security

Operational metadata is retained only as needed for billing, security, support, and legal obligations. API keys are shown once and stored as hashes; customers remain responsible for keeping revealed keys secret.

06

Your choices

You may revoke API keys at any time and request access, correction, or deletion of eligible account data. Some billing or security records may be retained where the law requires it.