Legal
Data Handling
Last updated: January 2026
This page describes, at a technical level, what Surfaced AI stores, where it lives, and who processes it on our behalf. It complements our Privacy Policy with implementation detail.
What we store
- The URL you submit for a saved audit, along with its score, detected issues, and raw signal data (H1 text, schema presence, link counts, etc.)
- Your account email and Supabase-hashed password
- Your Stripe customer and subscription IDs, and subscription status
- Timestamps for account creation and audit runs
What we don't store
- The full HTML or content of pages you audit — only the specific signals described above
- Payment card numbers or bank details, which are handled entirely by Stripe
- Passwords in plain text — these are hashed by Supabase Auth and never visible to us
Where data lives
Account and audit records are stored in a Supabase-hosted Postgres database with row-level security policies, so each account can only read its own rows. Access to raw data is restricted to service-role keys held server-side and never exposed to the browser.
Subprocessors
Supabase
Authentication & database
Account email, hashed password, audit records
Stripe
Payment processing
Billing details, subscription status — card data never touches our servers
Resend
Transactional email
Email address, message content (welcome, audit-complete, receipts)
PostHog
Product analytics
Anonymized usage events, page views
Retention & deletion
Data is retained while your account is active. Deleting your account removes your profile and audit history from our primary database; billing records are retained as required by Stripe and applicable tax law.
Data questions or deletion requests: privacy@surfaced.so.