Privacy Policy
This policy covers Surfspace — the surf.space web app, the Surfspace apps for iPhone, Android, and Mac, and the Surfspace Terminal — and the cloudsurf.com website, all made by CloudSurf Software LLC. It's written in plain English on purpose.
Effective: August 2, 2026.
Your account
When you create an account we collect your email address and a username. We use them to create your account, sign you in, and keep your account secure. That's all signup asks for — we don't collect more than we need to run your account. You can optionally add a phone number for sign-in codes by text message (see Service providers below).
Your content
The docs, chats, and images you create are stored on the Surfspace backend so they're available across your devices. Your content belongs to you. We store it to run the product for you — nothing else, except as this policy describes. Like any service, our servers also keep ordinary operational records — which features you use and standard server logs — so we can run and debug Surfspace. We don't use third-party analytics, and we don't build advertising profiles.
AI processing
When you chat with Surfy, your Surfspace assistant, your messages are processed in one of three ways, depending on the model handling your request:
- Third-party AI providers. By default, your messages are sent from our servers to third-party large-language-model providers to generate the response. Today those providers include Anthropic (Claude), Google (Gemini), and OpenAI. These calls are made server-side from CloudSurf's backend — the Surfspace apps don't include any third-party AI SDKs. We tell you this before your first Surfy conversation, and using Surfy is always your choice.
- CloudSurf's own models. Some responses may instead be generated by CloudSurf's own models, running either on infrastructure we own and operate or on cloud infrastructure we rent and control. In that case, your content is not sent to any third-party model provider.
- On-device models. You can optionally download models that run entirely on your device — or on another of your own devices you've linked to your account in Settings. Responses are generated on your hardware; no third-party model provider is involved. When two of your devices work together, the request travels between them through our servers, like any other sync. Your chats are still saved to your workspace so they're available across your devices, like any other content.
What's sent when a third-party provider handles your request: the messages you send to Surfy, plus workspace content the conversation uses — a doc, task, or app spec you ask Surfy to work on, or that Surfy opens from your workspace to answer you.
What's not sent: workspace content that no Surfy conversation touches stays on our servers and is never shared with model providers. Voice audio never reaches CloudSurf or the model providers (see Speech below).
Providers process this data to generate your response. Under our commercial terms with them, they may retain API inputs for a limited period for safety and abuse monitoring, after which their terms require deletion — and they may not use your content for anything else.
We never use your content to train models, and our agreements with every model provider prohibit them from training on it.
If we ever offer an optional program to improve Surfy using volunteered content, it will be strictly opt-in, off by default, and clearly labeled — and we'll update this policy first. Unless you choose to join such a program, nothing you create is ever used for training.
Speech
Voice input uses your device's built-in speech recognizer. Your audio never reaches CloudSurf's servers — we only ever see the text, as your message. Depending on your device and language, the recognizer may run on-device or use your operating system vendor's speech service under their privacy policy.
Connected apps (MCP & API)
You can connect outside AI assistants and other MCP-compatible apps to your Surfspace workspace, either by approving an OAuth connection or by minting an API key. Each connection is scoped to one workspace and to the permissions you grant it.
When a connected app calls Surfspace, the content its tools return — your docs, tasks, and search results from that workspace — is sent to that app, where it's handled under that app's own privacy policy, not this one. Nothing is shared until you approve the connection, and you can revoke a connection at any time in Settings → API Keys, which cuts off its access.
Service providers & sharing
We never sell your data, and we don't share it for advertising. Like almost every service, we rely on a small number of providers to run Surfspace, and they process data only to provide their service to us:
- AI model providers — Anthropic, Google, and OpenAI receive the Surfy conversations they're asked to answer, and the content those conversations use, solely to generate responses (see AI processing above).
- Cloud hosting — your content is stored on cloud infrastructure we rent and control. Surfspace runs on servers in the United States, so your content is stored and processed there wherever you live.
- Payments — paid plans are processed by Stripe on the web, or by Apple or Google when you subscribe through the iPhone or Android app. Your payment details go to the payment processor, not to us — we receive only what we need to know your plan is active.
- Web & news search — when you (or Surfy, on your behalf) run a web search, the search query — which can include text from your conversation — is sent to our search provider (Brave) to fetch results. Your workspace content is not otherwise shared with them.
- Push notifications — notifications are delivered through Apple's and Google's push services and can include a short preview of the message that triggered them. We collect your device's push token to deliver them.
- Text messages — if you add a phone number for sign-in codes, those codes are delivered through Twilio, our SMS provider.
- Bot protection — sign-in pages and website forms use Cloudflare Turnstile to tell humans from scripts; it processes standard browser signals to do that.
Beyond that, we disclose data only when the law requires it, when it's needed to protect Surfspace and its users from abuse or serious harm, when you ask us to, or — if CloudSurf is ever acquired or merges — to a successor who takes on this policy's commitments. We'd tell you before your data ever became subject to a different policy.
The cloudsurf.com website
cloudsurf.com is our company website. You can browse it without an account, and it doesn't use analytics, cookies for tracking, or advertising. If you contact us — by email or through the contact or careers forms — we store what you send us, along with standard technical details like your IP address, so we can reply and follow up. Nothing else is done with it. Other CloudSurf products have their own privacy policies.
Data retention
We keep your content for as long as your account exists, so it's there when you come back. When you delete your account — or ask us to — your content is removed from our systems right away, and residual copies in our backups are deleted within 60 days as backups rotate. One exception: content in shared workspaces you own together with other people stays with those people — it belongs to the workspace, not just to you. We don't keep what we no longer need.
Analytics
We don't use third-party analytics or tracking services today. If that ever changes, we'll update this policy first.
Data deletion & contact
You can delete your account and all your content at any time from your account settings in the app, or by emailing team@cloudsurf.com — we'll take care of it either way. Deletion takes effect right away; see Data retention for how backup copies clear and what stays in shared workspaces. You can also ask us for a copy of your data, or to correct it — same address. Whatever your country's privacy law gives you, email us and we'll honor it. The same address works for any privacy question.
Children
Surfspace is for adults — it's not directed at children, and we don't knowingly collect information from children.
Changes to this policy
If we make meaningful changes, we'll update this page and the effective date at the top — and for significant changes, we'll also let you know in the app. The version published at surf.space/privacy is always the current one.