Legal

Privacy Policy

Your privacy matters. Here's how Resurf handles your data.

Your Data Stays on Your Devices

Resurf is a local-first application. All your captures, notes, images, and personal data are stored on your own devices: your Mac, iPhone, or iPad. We do not have access to your content, and it is never uploaded to our servers.

iCloud Sync (Optional)

You can sync your captures between your devices through iCloud. Synced data is stored in your personal iCloud account (a private CloudKit database) and handled by Apple under Apple's privacy terms. We cannot read, access, or share anything you sync. You can turn sync off at any time in Settings → Sync and keep everything local-only.

AI Features (Optional)

AI features are off by default and work with your own OpenAI API key. The app asks for your permission before anything is sent: turning AI on shows exactly what will be shared and with whom, and lets you decline. Until you agree, nothing leaves your device.

When enabled, the content needed for the feature you use (a capture's text, text recognized in your images, or a voice recording for transcription) is sent directly from your device to OpenAI under your own account. Image files themselves are never uploaded: text is recognized on your device first, and only that text is sent. It never passes through our servers. OpenAI processes this data under its API data protections and privacy policy, which provide that API data is not used to train OpenAI's models by default.

Your API key is stored in your device's Keychain. On iPhone, you can also choose on-device transcription, which processes voice notes entirely on your device and sends nothing anywhere.

Analytics (Optional)

To help us improve Resurf, the Mac and iPhone/iPad apps collect anonymous product analytics via PostHog. This is optional and can be turned off at any time in Settings on either platform.

Analytics are anonymous by design. We do not create user profiles, we never link events to your name, email, or license, and screen recording and session replay are switched off. Automatic event capture is disabled too, so the app only ever sends the specific events listed below.

When enabled, we collect:

  • An anonymous device identifier, not tied to any account
  • App version, operating system, and device type
  • A fixed, short list of usage events: app opened, onboarding step viewed and completed, capture created, capture failed to save, search performed, search result opened, free limit reached, license activated, and analytics turned off
  • Minimal, non-personal properties on those events only: the type and source of a capture, an error category, and whether a search returned any results

We never send the content of a capture, a note body, a title, a URL, a file name, or the text you typed into search — the number of results is recorded, never the query.

Crash Reporting (Mac App Only)

The Mac app uses Sentry to collect crash reports and error data. This helps us identify and fix bugs to improve app stability. The iOS app includes no third-party crash reporting. Crash reports include:

  • Error messages and stack traces
  • App version and environment
  • Device type and OS version
  • Session replay on errors (UI interactions only, no personal data)

Crash reports never include your captures, notes, images, or any personal content.

What We Never Collect

  • Your captures, notes, or any content
  • Screenshots or images
  • Personal information, browsing history, or pages you haven't explicitly captured
  • Keystrokes or clipboard data

Chrome Extension

The Resurf Chrome extension lets you capture web content directly to your local Resurf library via right-click. When you choose to capture something, the extension reads:

  • The URL and title of the current tab
  • Selected text, link URLs, or media URLs (image, video, audio), only what you explicitly right-clicked on

This data is passed directly to the Resurf app on your Mac via a local protocol. It is never sent to our servers, never stored by the extension, and never shared with any third party. The extension only acts on explicit user gestures. It does not run in the background, monitor your browsing, or access pages you haven't interacted with.

License Validation

If you purchase a license, your license key is validated with our server to activate the app. No personal data is shared during this process.

Disabling Analytics

You can disable analytics at any time. On Mac, go to Settings → General → Analytics. On iPhone and iPad, open Settings and turn off Share anonymous usage analytics. Analytics are enabled by default to help us improve the app. If you prefer not to share any usage data, we recommend turning it off on first launch.

International Users & GDPR

Resurf is operated from Canada. If you are accessing the app from the European Union or another region with data protection laws, the following applies:

  • Your personal content is never collected. It stays on your device. GDPR obligations around personal data access, portability, and deletion do not apply to content we never see.
  • The only data we hold is an anonymous device identifier used for analytics (if enabled) and your email address if you signed up for download or purchased a license.
  • Captures synced via iCloud live in your personal iCloud account and are processed by Apple, not by us. We have no access to them.
  • You may request deletion of your email or any associated data at any time by contacting support@resurf.so.
  • If you prefer analytics not be collected, turn it off in Settings before first use — on Mac under General → Analytics, and on iPhone or iPad under Share anonymous usage analytics.

Contact

If you have any questions about our privacy practices, please contact us at support@resurf.so

Last updated: July 2026