Legal

Data Handling

Last updated: January 2026

This page describes, at a technical level, what Surfaced AI stores, where it lives, and who processes it on our behalf. It complements our Privacy Policy with implementation detail.

What we store

  • The URL you submit for a saved audit, along with its score, detected issues, and raw signal data (H1 text, schema presence, link counts, etc.)
  • Your account email and Supabase-hashed password
  • Your Stripe customer and subscription IDs, and subscription status
  • Timestamps for account creation and audit runs

What we don't store

  • The full HTML or content of pages you audit — only the specific signals described above
  • Payment card numbers or bank details, which are handled entirely by Stripe
  • Passwords in plain text — these are hashed by Supabase Auth and never visible to us

Where data lives

Account and audit records are stored in a Supabase-hosted Postgres database with row-level security policies, so each account can only read its own rows. Access to raw data is restricted to service-role keys held server-side and never exposed to the browser.

Subprocessors

Supabase

Authentication & database

Account email, hashed password, audit records

Stripe

Payment processing

Billing details, subscription status — card data never touches our servers

Resend

Transactional email

Email address, message content (welcome, audit-complete, receipts)

PostHog

Product analytics

Anonymized usage events, page views

Retention & deletion

Data is retained while your account is active. Deleting your account removes your profile and audit history from our primary database; billing records are retained as required by Stripe and applicable tax law.

Data questions or deletion requests: privacy@surfaced.so.