legal
Privacy policy
Surferse is a web browser made by UniAuth Inc. Signing in, your account and sync are provided by UniAuth. This policy lists what the browser sends to us, what still reaches Google, and what it never sends. “We” and “us” mean UniAuth Inc.
What the browser sends to us
- Sign-in and token refreshuniauth.id/api/oauth/*
- When you sign in to UniAuth, and when the browser refreshes its sign-in token. This uses OAuth with PKCE.
- Account profile
- After you sign in: your email address, display name and avatar URL.
- Synced data
- Bookmarks, open tabs, history, saved addresses and settings, encrypted on your device before they are sent. Data is shared between your devices only after you provide a sync key: a sync passphrase, or on desktop your UniAuth Vault master password. Signing in alone is never enough. The key never leaves the device, so our servers store ciphertext that we cannot read. Until you provide a key, each browser profile uses its own random key: your data is still uploaded as ciphertext, but no other device, and not us, can read it.
- Device identifier
- A random identifier for each installation, so that the device can be listed and revoked. It is not derived from your hardware.
- Update check (macOS)surferse.app/api/update/surferse/latest.json
- At every startup, whether or not you are signed in, the macOS app fetches a signed update manifest to tell you when a new version is available. It only notifies you; it never installs an update on its own. The request carries no cookies, but our server sees your IP address and user agent.
- Safe Browsing lookupssurferse.app
- The checks that warn you about dangerous sites are proxied through surferse.app rather than sent to Google directly. A lookup sends a 32-bit hash prefix, not the address of the page you are visiting.
- Crash reportsoff by default
- Sent only if you opt in. A crash report contains the stack trace and device information, not your browsing.
What still reaches Google
Surferse sends no telemetry to Google by default. Some features still connect to Google, depending on your platform and the Google services mode:
- Balanced modethe default
- On macOS and iOS, component updates are downloaded from update.googleapis.com. On macOS, DRM-protected media and web push notifications also connect to Google.
- Chrome Web Store (macOS)a Google service
- Installing extensions and checking for their updates uses the Chrome Web Store: chrome.google.com/webstore, chromewebstore.google.com, chromewebstore.googleapis.com and clients2.google.com. Surferse for iOS has no extensions.
- Block all mode
- Stops every Google background connection, on macOS and iOS. On macOS, DRM-protected media, web push notifications, certificate-list updates and extension updates stop working.
- Password leak check
- Off by default, and inert in the current build.
What is never sent
- Your sync passphrase, or the key derived from it.
- The addresses of the pages you visit. Your history and open tabs leave the device only as encrypted sync data.
- Usage metrics. No metrics endpoint is compiled into the browser.
- Field-trial (“variations”) seed requests, which Chrome uses to switch experiments on and off remotely.
Defaults
- Search
- A privacy-preserving search engine chosen for your region: DuckDuckGo, Brave Search, Startpage, Qwant, Mojeek or Ecosia. Never Google.
- Google services
- Balanced.
- Translate
- Off.
- Password leak check
- Off.
- Crash reporting
- Off.
- Sync
- Shares nothing between devices until you provide a sync key: a sync passphrase, or on desktop your UniAuth Vault master password. Signing in alone is never enough.
What we cannot do
Because we do not hold your key, we cannot read your synced data, export it in readable form, or recover it if you forget your passphrase. For the same reason, we cannot give a readable copy of it to anyone else.
Your choices
- Crash reporting stays off unless you turn it on.
- Set Google services to Block all to stop every Google background connection. On macOS, that also stops DRM-protected media, web push, certificate-list updates and extension updates.
- You can revoke any of your devices.
- For questions or requests about your data, including deletion, write to privacy@uniauth.id.
This website
surferse.com sets no cookies, runs no analytics, and loads every file from surferse.com itself. If you switch between the light and dark themes, that choice is saved in your browser’s local storage and is not sent to us.
Requests to the site pass through Cloudflare. Our web server keeps standard access logs (IP address, requested page, time, referring page and browser user agent) for up to 180 days.
Contact
UniAuth Inc.131 Continental Dr, Ste 305
Newark, DE 19713
United States
privacy@uniauth.id