Privacy Policy

Last updated: March 28, 2026

TL;DR - Quick Summary

Your data stays private: Files and chats are isolated to your session only

Zero data retention: All AI providers have strict zero data retention policies - your data is never stored, logged, or used for training

Sandboxed processing: All AI agents run in isolated containers with strict security

You control your data: Delete files, sessions, or your entire account anytime

Invite-only access: Only approved emails can use FileSurf (no public registration)

Enterprise security: TLS 1.2+ encryption, HttpOnly cookies, and secure data storage

Your Privacy Matters

At FileSurf, we take your privacy seriously. We've built our platform with security and data protection as core principles. This policy explains how we handle your data and the measures we take to keep it safe.

Information We Collect

Account Information

  • Email address (for invite-only authentication)
  • User ID (automatically generated)
  • Login timestamps

Files and Content

  • Files you upload to your sessions
  • Chat messages and conversations
  • Session metadata

How We Protect Your Data

Sandboxed AI Processing

All AI agents run in isolated, sandboxed containers. This ensures that processing happens in a secure environment with strict access controls, preventing unauthorized access to your data.

Multi-Provider AI Infrastructure

We use a carefully selected mix of AI providers to deliver the best models at affordable prices. Given the fast pace of AI development, our provider selection may change over time to ensure you always have access to the best AI capabilities.

Current providers:

  • AWS Bedrock - Enterprise-grade AI infrastructure
  • Fireworks AI - Fast, efficient model inference
  • Cerebras - High-performance AI computing

Zero Data Retention Guarantee:

  • No data storage: Your prompts and completions are never stored or logged by our AI providers
  • No training data: Your content is never used to train any AI models or distributed to third parties
  • No provider access: Model providers have no access to your prompts, completions, or conversation logs
  • Configured for privacy: We explicitly configure all providers to disable any data retention features
  • Encrypted in transit: All communications use TLS 1.2+ encryption
  • Isolated processing: Each request is processed independently without retaining context between sessions

Learn more about our providers' data protection policies: AWS Bedrock | Fireworks AI | Cerebras

Session Isolation

Each user session is completely isolated. Your files and conversations are only accessible to you and cannot be viewed by other users.

Secure Authentication

We use invite-only authentication. Only pre-approved email addresses can access the platform. Secure, HttpOnly cookies with 365-day expiration protect your session.

Data Retention

AI Processing - Zero Data Retention: Your prompts and AI responses are processed in real-time and are never retained by our AI service providers. We configure all providers to explicitly disable data logging and retention.

Session Data: Your uploaded files are stored in your workspace until you explicitly delete them. Conversation data (chat messages) is kept in short-term storage for retrieval during your session. Conversations older than 1 day are automatically wiped by a scheduled daily cleanup job — there is no long-term retention of conversation history beyond that window.

Account Data: Your email and user ID are retained for the lifetime of your account unless you request deletion.

Your Rights

You have the following rights regarding your data:

  • Access: View what data we have about you
  • Deletion: Delete your sessions, files, and conversations at any time
  • Export: Download your files from any session
  • Account Closure: Request complete account deletion by contacting the administrator

Invite-Only Access

FileSurf operates on an invite-only basis. This means:

  • Only approved email addresses can create accounts
  • No self-registration is available
  • Administrators can activate or deactivate accounts
  • This ensures a controlled, trusted user base

Technical Security Measures

TLS 1.2+ Encryption

All data in transit is encrypted

HttpOnly Cookies

Protected from XSS attacks

Container Isolation

AI agents run in sandboxes

Secure Data Storage

Industry-standard encryption

Third-Party AI Services

When you connect your own AI subscriptions (such as ChatGPT Plus/Pro, Kimi Coding Plan, Z.ai Coding Plan, or Minimax Coding Plan) to FileSurf, your messages and prompts are sent directly to those third-party services for processing.

Important: Messages processed through your connected AI subscriptions are subject to the privacy policies and data handling practices of those third-party providers. FileSurf cannot control what data these services collect, store, or use. Please review the privacy policies of the respective AI providers before connecting your accounts.

Updates to This Policy

We may update this privacy policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. We encourage you to review this policy periodically to stay informed about how we protect your information.

Questions?

If you have any questions about this privacy policy or how we handle your data, please contact the administrator.

Return to FileSurf

Privacy Policy · Terms of Service · Pricing