The short version

Data on Your Device

Surfer stores browser data such as history, bookmarks, tabs, website data, containers, downloads, settings, and site icons. On the Mac, this also includes local offline backup snapshots for recovery purposes. This data may be included in your Apple device backups. Your operating system may retain diagnostic logs, but Surfer does not automatically upload logs or diagnostics.

Private tabs use non-persistent website storage and do not add pages to history. Data you explicitly save, download, or share can still remain.

Optional Sync

If you choose to sign in with Apple, Surfer uses Supabase to sync your bookmarks, history, containers, routing rules, site settings, incoming link behavior, and element hiding rules. Your account includes an identifier and may include the name and email address provided by Apple.

URLs, titles, domains, container names, and element hiding rules are encrypted on your device before upload. Account and record identifiers, settings, visit counts, timestamps, and other metadata needed to operate sync remain readable. Supabase tables use Row Level Security to restrict each account to its own records.

Supabase provides authentication and cloud infrastructure under its Data Processing Addendum and Privacy Policy. Sign in with Apple and push notifications are covered by the Apple Privacy Policy.

Send Tab to Device

The Send Tab to Device feature stores an installation identifier, encrypted device name, time of last device activity, and encrypted tab URL and title in Supabase. On iPhone and iPad, Apple also receives the push token, message identifier, and sender device label needed to deliver a notification; the URL and title are not included in the push. Sent tabs are kept for seven days or until delivery, and may remain stored until later maintenance or account deletion. Send Tab to Device is only available when sync is enabled.

External Services

Surfer sends searches and, during normal browsing, address bar suggestion requests to DuckDuckGo. Live suggestions are disabled in private browsing. See the DuckDuckGo Privacy Policy.

Content blocking is on by default and can be turned off in Settings. While it is on, Surfer downloads filter lists from EasyList/Adblock Plus and GitHub. These requests do not include your browsing history or current page.

Retention and Deletion

Local data remains until you remove it through Surfer or erase the app’s data from your device; downloads, exports, Keychain records, and backups may remain separately. Cloud data remains while your account exists. Deleted sync items may leave a record so the deletion reaches your other devices. Signing out does not delete local or cloud data.

You can delete your account from Settings > Sync > Account Settings > Delete Account. Surfer deletes the authentication account and its active cloud data, signs out, and stops cloud activity on the device. Browser data stored locally remains so you can continue browsing without an account; you can remove it separately through Surfer or by erasing the app’s data from your device.

Surfer does not retain the Apple credential needed to revoke Sign in with Apple automatically. After deletion, the app offers Apple’s instructions for manually revoking Surfer under Sign-In & Security in your Apple Account settings. Cloud data may remain temporarily in Supabase disaster recovery backups until those backups expire through the service’s normal lifecycle; it is no longer available through Surfer.

Contact

Privacy questions and requests: privacy@surfer.rocks