Privacy Policy
Last updated 7 September 2026
Surfbird is a live call coach for iPhone. It listens to the room through the microphone, turns speech into text on the device, and suggests what to say next. This policy describes exactly what leaves your phone, what is stored, and how to get rid of it.
Call audio never leaves your phone. Speech is turned into text on the device using Apple's on-device speech recognition. The audio is never recorded to a file, uploaded, streamed or stored — not by us, and not by anyone else. Only text leaves the device.
Who is responsible
Surfbird is built and operated by an independent developer based in the United States. There is no company behind it and no staff — one person can read what is stored, and does so only to fix something that is broken.
For anything in this policy, including a request to delete your data: support@surfbird.app.
What is collected
Your account
Surfbird uses Sign in with Apple. Apple sends a stable identifier for you, which is hashed before it is stored, and your email address — which may be Apple's private relay address if you chose to hide it. A per-device token is created so signing out on one device does not sign out the others; it is tied to the identifier iOS gives apps from the same developer, and tells us nothing about you or your other apps.
What is said on your calls
The transcript your phone produces is sent to our server so a tip can be written. The transcript, the tips and the recap are stored against your account so you can read the call back later. This text can contain anything either party said, including things about the other person, who has not agreed to this policy — see the people you talk to.
Documents you attach
If you attach a CV or sales material, the file itself never leaves your phone. The text is extracted on the device and sent; a short summary is written from it once, and both the text and that summary are stored against your account until you delete the document. A CV typically contains your name and employment history.
Prep notes and call details
Anything you type before a call, the mode you chose, and when the session started and ended.
Subscription
Apple handles payment. We never see your card, your billing address or your Apple ID. We store which plan you are on, when it expires, the product you bought and Apple's transaction identifier, so the app knows what you are entitled to.
The waitlist
If you sign up on the website, your email address is stored, along with a salted hash of your IP address — used only to stop one person submitting the form thousands of times, and not reversible into an IP address by us.
What is not collected
- No call audio, ever.
- No analytics, no advertising, no third-party trackers. The website loads no scripts other than its own, and sets no cookies.
- No location, no contacts, no photos, no browsing history.
- Nothing is sold or shared for advertising, and nothing is used to train anyone's models.
Why, and on what basis
Everything above exists to make the product work: to write a tip, to write a recap, to show you your own history, and to count sessions against your plan. Under GDPR the basis is performance of the contract you enter when you use Surfbird, except the hashed IP on the waitlist, which is a legitimate interest in not being flooded.
Who else processes it
| Service | What it handles | Where |
|---|---|---|
| Anthropic | The transcript excerpt, your notes and document summaries, to write tips and recaps | United States |
| Supabase | The database holding accounts, calls and documents | Frankfurt, Germany |
| Vercel | Hosting for the website and the API | United States and edge locations |
| Apple | Sign in with Apple, and all payment | Per Apple's own policy |
Anthropic processes API content to provide the service and does not use it to train its models. If you are in the EU or UK, note that data reaches the United States through Anthropic and Vercel; those transfers rely on the standard contractual clauses in their terms.
How long it is kept, and how to delete it
- A call. Kept until you delete it. Deleting it in the app erases the transcript, the recap, the tips and your notes from the server. A row remains recording that a session happened and when, because that is what your plan is counted against — it contains nothing that was said.
- A document. Kept until you delete it. Deleting it removes both the extracted text and the summary entirely.
- Signing out revokes that device's token. It deletes nothing; signing back in brings your history with it.
- Your whole account. There is not yet a button for this in the app. Email support@surfbird.app from the address on the account and everything — account, calls, documents — is deleted within 30 days. This is a gap we intend to close with an in-app control.
- The waitlist. Deleted once the app launches and the announcement has gone out, or sooner if you ask.
Your rights
Depending on where you live, you may have the right to access what is held about you, to correct it, to delete it, to receive a copy, to object to processing, and to complain to your data protection authority. In the EU and UK these come from GDPR; several US states give similar rights. Exercise any of them by emailing support@surfbird.app. There is no charge and no penalty for asking.
The people you talk to
Surfbird transcribes what the other person on your call says. They have not agreed to this policy and may not know the app is running. Whether you may do that is your responsibility, not ours — some countries and US states require every party to consent before a conversation is recorded or transcribed. The Terms set this out, and you should read that section before using Surfbird on a call with anyone else.
Children
Surfbird is not for anyone under 16, and is not directed at children.
Changes
If this policy changes in a way that affects what is collected or who processes it, the date at the top changes and anyone with an account is told by email before it takes effect.