Last updated: July 27, 2026

Privacy Policy

This Privacy Policy explains how Surfwork collects, uses, shares, and retains information when you use its AI-assisted professional networking, contact research, outreach, and email-tracking features.

Information we collect

Depending on how you use Surfwork, we collect:

  • Account information, such as your name, email address, profile image, account identifier, and authentication session information.
  • Profile information you provide, such as education, work experience, skills, interests, goals, LinkedIn URL, personal website, and target companies or locations.
  • Search and contact information, including search queries, saved results, professional profile details, contact details, notes, and information returned by search and enrichment providers.
  • Outreach content, including templates, generated drafts, recipients, subjects, message bodies, send status, and reply-tracking metadata.
  • Connected Google account information, as described in the Google OAuth and Gmail section below.
  • Subscription and transaction information,such as your Stripe customer and subscription identifiers, plan, status, and billing period. Payment card details are submitted directly to Stripe rather than stored in Surfwork's application database.
  • Technical and usage information processed in connection with requests, authentication, security, rate limiting, and service operation.

How we use information

We use information to:

  • create and secure accounts and provide the Surfwork service;
  • run people searches and save contacts and search history;
  • suggest work email formats and generate or personalize outreach drafts;
  • send user-directed email and track whether a reply is received;
  • operate subscriptions, usage limits, support, security, and troubleshooting; and
  • maintain and improve the reliability and functionality of the service.

Google OAuth and Gmail data

Surfwork uses Google OAuth in two contexts. First, you may use Google to create or access your Surfwork account. For that sign-in flow, Surfwork and its authentication provider receive the account information Google makes available for authentication, such as your name, email address, profile image, and Google account identifier.

Second, after signing in, you may separately connect Gmail. The Gmail authorization currently requests permission to send email, read Gmail messages and history, and modify Gmail data. Surfwork's currently implemented Gmail features use that access to:

  • identify the connected Gmail address and store OAuth access and refresh tokens;
  • send messages that you direct Surfwork to send;
  • retrieve message and thread identifiers and limited message metadata after sending;
  • register inbox-change notifications and review Gmail history, headers, and message snippets to identify replies to messages sent through Surfwork; and
  • store send and reply-tracking records, including recipient and sender addresses, subjects, message bodies sent through Surfwork, reply sender, reply subject, reply snippet, and related message or thread identifiers.

The current product does not use Gmail access to delete messages or change mailbox labels. Surfwork does not sell information received from Google APIs or use it for advertising.

Service providers and sharing

Surfwork shares information with service providers only as needed to provide the functions described in this policy. Current integrations include:

  • Supabase for authentication and application database services;
  • Google for Google sign-in and optional Gmail features;
  • Exa for people search, public professional information, and email format research;
  • Microsoft Azure OpenAI for search summaries, outreach generation, template generation, and email-format analysis;
  • Stripe for checkout, subscription management, and billing; and
  • hosting, infrastructure, and security providers that process application requests and operational data.

The information sent to a provider depends on the feature you choose. For example, search queries go to the search provider, relevant profile or draft content may be included in an AI-generation request, and billing details go to Stripe.

Retention, deletion, and your choices

Surfwork currently stores account and feature data while your account is active and does not apply one fixed automatic retention period to every category of data. You can delete your account from Settings. The account-deletion process is designed to remove your authentication account and associated Surfwork records, including profile, contacts, templates, search history, Gmail connection tokens, send records, and subscription metadata.

You can also revoke Surfwork's Google access from your Google Account permissions. Revocation stops future access through those credentials but does not itself delete information already stored by Surfwork; use account deletion or contact us for that. Limited information may remain temporarily in provider backups, security logs, or records a provider retains under its own obligations.

Security

Surfwork uses authenticated sessions, database access controls, server-side provider credentials, and rate limiting on selected endpoints to help protect information. No storage or transmission method is completely secure, and Surfwork cannot guarantee absolute security.

Changes to this policy

We may update this policy as Surfwork's features and data practices change. We will post the revised policy here and update the “Last updated” date.

Contact

For privacy questions or requests, email jp@surfwork.io.