Privacy Policy
Last updated: March 6, 2026
What We Collect
When you sign in with Google, we store your name, email address, and profile photo. We use this solely to identify your account and personalize your experience.
Google User Data
Surface uses Google OAuth 2.0 for authentication. We request only the following scopes:
email— Your email address for account identificationprofile— Your name and profile photo for account personalizationopenid— Authentication verification
This data is used solely to create and maintain your Surface account. We do not access any other Google user data such as contacts, calendar, drive files, or Gmail content.
We do not sell, share, or transfer your Google user data to any third party for any purpose, including advertising, analytics, or data brokering.
Surface's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You may delete your account and all associated Google user data by contacting support. All Google-sourced data will be permanently removed within 30 days of your request.
How We Use Your Data
Your data is used to: authenticate your account, save your preferences (topic filters, depth settings, topic weights), track which items you've read, and manage your subscription. We do not sell, share, or provide your personal data to any third party.
Content Data
Surface monitors publicly available content sources (RSS feeds, YouTube channels, blogs). All content scoring and labeling is performed by AI. Your reading history and preference data is stored per-account and is not visible to other users.
Payments
Payments are processed by Stripe. We store your Stripe customer ID and subscription status. We never see or store your credit card number or payment details — those are handled entirely by Stripe.
Cookies
We use a single HttpOnly session cookie to keep you signed in. We do not use tracking cookies, analytics pixels, or any third-party tracking.
Data Storage
Your data is stored on Cloudflare's infrastructure (D1 database, Workers KV). Session tokens are SHA-256 hashed before storage. Cookie values are HMAC-signed.
Your Rights
You can delete your account and all associated data by emailing support@unsupervised-learning.com. We will remove your account, preferences, reading history, and subscription records within 30 days of your request.
Contact
Questions about this policy? Email support@unsupervised-learning.com.