1. Introduction
At Surfaced ("we," "us," or "our"), we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at surfacedsocial.com and our mobile applications (collectively, the "Service").
Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
Account Information:
- Email address
- Username
- Password (stored in encrypted form)
- Display name
- Profile picture (optional)
- Bio (optional)
- Location (optional)
- Website URL (optional)
Content You Create:
- Posts (text, images, links)
- Stories (images, videos)
- Comments and replies
- Likes and bookmarks
- Interests and preferences
Communications:
- Messages you send to our support team
- Feedback and survey responses
- Reports of content or users
2.2 Information Collected Automatically
Usage Information:
- Pages and content you view
- Posts you interact with
- Search queries
- Time spent on the Service
- Features you use
- Frequency and duration of activities
Device Information:
- Device type, model, and operating system
- Browser type and version
- IP address
- Device identifiers (such as advertising ID)
- Mobile network information
- Time zone and language settings
Location Information:
- Approximate location based on IP address
- Precise location (only if you grant permission)
Cookies and Similar Technologies:
We use cookies, web beacons, and similar technologies to:
- Remember your preferences
- Authenticate your account
- Analyze usage patterns
- Deliver personalized content
- Measure advertising effectiveness
You can control cookies through your browser settings, but disabling cookies may limit functionality.
2.3 Information from Third Parties
Social Login:
If you sign up using Google or Apple, we receive:
- Name
- Email address
- Profile picture
- Any other information you authorize
Analytics Providers:
We use third-party analytics services (such as Mixpanel or PostHog) that collect usage data to help us improve the Service.
3. How We Use Your Information
3.1 Provide and Improve the Service
- Create and manage your account
- Display your profile and content to other users
- Personalize your feed based on your interests
- Recommend content and users to follow
- Enable social features (following, commenting, liking)
- Process and store your bookmarks
- Send notifications about activity on your account
- Respond to your support requests
- Detect and prevent fraud, abuse, and security issues
3.2 Communicate with You
- Send transactional emails (account verification, password reset)
- Send you daily digests and weekly roundups (if enabled)
- Notify you of changes to our Terms or Privacy Policy
- Send administrative messages and updates
- Respond to your inquiries
3.3 Research and Analytics
- Analyze usage patterns and trends
- Measure the effectiveness of features
- Conduct surveys and research
- Improve our algorithms and recommendations
- Understand user demographics and behavior
3.4 Legal and Safety
- Comply with legal obligations
- Enforce our Terms & Conditions
- Protect our rights and property
- Investigate and prevent illegal activity
- Respond to law enforcement requests
4. How We Share Your Information
4.1 Public Information
The following information is publicly visible to all users:
- Username and display name
- Profile picture and bio
- Posts, comments, and stories
- Content you like or share (visible to your followers)
- Users you follow and who follow you
- Location and website (if you choose to share)
Your bookmarks and saved items are private unless you choose to share them.
4.2 With Service Providers
We share information with third-party service providers who help us operate the Service:
| Service Type |
Provider Examples |
| Cloud Hosting |
AWS, Railway, Vercel |
| Authentication |
Supabase, Clerk |
| Email Delivery |
Resend, SendGrid |
| Analytics |
Mixpanel, PostHog |
| Content Moderation |
Hive AI |
| Error Tracking |
Sentry |
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
4.3 For Legal Reasons
We may disclose your information if required by law or if we believe in good faith that disclosure is necessary to:
- Comply with legal obligations (subpoenas, court orders)
- Protect our rights, property, or safety
- Investigate fraud or security issues
- Prevent harm to users or the public
- Respond to government requests
4.4 Business Transfers
If Surfaced is involved in a merger, acquisition, or sale of assets, your information may be transferred to the new owner. We will notify you before your information is transferred and becomes subject to a different privacy policy.
5. Your Privacy Rights and Choices
Access & Update
You can access and update your information through your account settings: profile info, email, interests, and preferences.
Delete Account
You can delete your account anytime. Your profile and content will be removed within 24 hours. Some data retained for 30 days for recovery.
Download Data
Request a copy of your data by contacting privacy@surfacedsocial.com. We'll provide it in JSON format within 30 days.
Privacy Settings
Make your account private, control who can comment, control who can tag you, turn off activity status.
Notifications
Disable push notifications, unsubscribe from emails, control which notifications you receive.
Marketing
Opt out of promotional emails by clicking "unsubscribe" or updating preferences. Transactional emails cannot be disabled.
5.1 Regional Rights
For EU/UK Users (GDPR):
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
For California Users (CCPA):
- Right to know what personal information is collected
- Right to know whether your information is sold or disclosed
- Right to opt out of the sale of personal information
- Right to deletion
- Right to non-discrimination for exercising your rights
Note: We do not sell personal information.
To exercise these rights, contact privacy@surfacedsocial.com.
6. Data Security
We implement reasonable security measures to protect your information:
Technical Safeguards:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt)
- Regular security audits
- Access controls and authentication
Organizational Safeguards:
- Limited employee access to personal data
- Employee training on data protection
- Incident response procedures
- Regular security reviews
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Your Responsibility:
- Use a strong, unique password
- Enable two-factor authentication (when available)
- Keep your login credentials confidential
- Log out on shared devices
- Report suspicious activity immediately
7. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy.
| Data Type |
Retention Period |
| Account Information |
While account is active + 30 days after deletion |
| Content (Posts/Comments) |
May be cached or archived even after deletion |
| Stories |
Automatically deleted after 24 hours |
| Usage Data |
Up to 2 years for analytics purposes |
| Legal Compliance |
As required by law or to resolve disputes |
| Anonymized Data |
Indefinitely for research and analytics |
8. Children's Privacy
Surfaced is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are between 13 and 18 years old, you may only use the Service with parental consent.
If we become aware that we have collected information from a child under 13, we will take steps to delete that information promptly.
Parents who believe their child has provided information to us should contact privacy@surfacedsocial.com.
9. International Data Transfers
Your information may be transferred to and processed in countries where our service providers operate, including:
- United States (cloud hosting)
- European Union (content delivery)
- Other countries where our infrastructure is located
These countries may have different data protection laws than your country. By using the Service, you consent to the transfer of your information to these countries.
We take steps to ensure your information receives adequate protection, including:
- Using standard contractual clauses
- Working with service providers that comply with GDPR and other privacy frameworks
- Implementing appropriate technical and organizational measures
10. Third-Party Links and Services
The Service may contain links to third-party websites, apps, and services that are not operated by us. This Privacy Policy does not apply to those third parties.
Third-Party Services We Use:
- Google (authentication, analytics)
- Apple (authentication)
- Content sources (news publishers)
- Social media platforms (when you share content)
We recommend reviewing the privacy policies of any third-party services you access. We are not responsible for their privacy practices.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Effective Date" at the top of this policy
- Post the new policy on our website
- Notify you via email or in-app notification for material changes
- Give you an opportunity to review before the changes take effect
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Your Consent
By using Surfaced, you consent to:
- The collection and use of information as described in this Privacy Policy
- The transfer of your information to countries outside your own
- The use of cookies and similar technologies
You can withdraw consent at any time by deleting your account or adjusting your settings.