โ† Back to Surfd

Privacy

Public beta ยท Updated 9 October 2026

Surfd is an independent browser surfing game. You can play without an account. Signing in is optional and enables public records.

Information used

Google or X supplies account information to Supabase Auth when you sign in, such as your provider identifier, email address, name and avatar. Surfd uses your account ID to associate your profile and records. It does not request permission to post to your social account.

Where email accounts are enabled, Supabase Auth also handles your email address and password. Your public username is separate from your email address. Resend delivers confirmation and password-reset emails and processes the recipient address, email contents and delivery information. We do not enable email open or click tracking. The email-link page does not load visitor analytics.

Online records contain your chosen username, account ID, map and movement version, completion time, checkpoint splits, date, and recorded movement commands. Usernames, account IDs, verified records and available verified replays are public. Your email address and login credentials are not included in leaderboard responses.

Public-name changes are recorded with the previous name, new name, account ID and time. Moderator changes also record the moderator account and reason. This history is available only to moderators for account moderation and is retained while the account exists. Deleting an account removes its name history. Players can change their name once every 60 days; moderators can override this wait.

Your browser saves controls, preferences, local personal bests, login session and pending submission information in local storage. You can clear these using your browser's site-data controls. There are no advertising SDKs in the game.

Signed-in finishes can keep up to six pending command replays in IndexedDB while uploads and verification complete. They are associated with the account that played them and are removed after a terminal result or when the game confirms the attempt has expired. If you stop visiting or do not sign back into that account, copies remain until you clear this site's browser data.

If you finish an eligible run as a guest, the browser also keeps one completed command replay and its temporary claim ticket in IndexedDB so you can sign in and save that run. The replay is uploaded only after you choose to save it or sign in to save it. An unclaimed replay is valid for 24 hours from the run ticket's issue time. Once linked to an account, its local copy can remain for up to seven days to recover an interrupted upload or verification. Expired copies are removed the next time the game accesses them; you can also dismiss the copy or clear site data. An already-uploaded run may still finish verification after its local copy is dismissed.

Visitor analytics

We use Vercel Web Analytics on the live game to measure visits and page views, including referral sources, approximate location, and browser/device information. Vercel uses a temporary visitor hash rather than analytics cookies; it resets daily. These statistics are not linked to your Surfd account. We remove query parameters and URL fragments from the page URL sent to analytics, including login codes and replay identifiers. We do not send your email, username, account ID, or movement commands to analytics. See Vercel Web Analytics privacy information.

Multiplayer and chat

Joining an online server shares your public name, temporary or account identifier, movement, displayed run timer, rank and points with the other players there. Public chat and verified finish announcements are visible to that server. Solo play does not connect to a multiplayer room. Hiding players changes your display; it does not stop other players from seeing you.

Cloudflare runs the multiplayer rooms. The game keeps a short excerpt of each connected player's recent chat so a report can include context. Reports include the reporter's public name, the reported player, a reason and recent-message excerpts. Reports are eligible for deletion after seven days and moderation action logs after 30 days. Room cleanup happens during later room activity, so deletion can be delayed while a room is unused. Connection attachments disappear when the connection closes. Accepted-result delivery receipts are retained for up to seven days in the records database; room copies are eligible for cleanup after one day.

A secret-salted hash of the connection's IP address is used for guest connection limits and temporary bans. The room does not store the raw IP address in player state. Guest identifiers are kept in the browser for reconnecting. Mute preferences are local to your browser. Moderators can mute, disconnect or temporarily ban a player.

Hosting and security

Vercel hosts the website and processes record submissions. Supabase provides authentication, the database and replay storage. Cloudflare relays multiplayer connections and stores room and moderation state. These providers may process IP addresses, request details and operational/security logs as part of running their services. See Vercel's privacy policy, Supabase's privacy policy and Cloudflare's privacy policy.

Where enabled, Cloudflare Turnstile checks account requests for automated abuse using browser and connection signals. Resend processes account email delivery; see Resend's privacy policy.

Retention and deletion

Personal-best replay files remain available with their records. Other verified replay files are eligible for removal after seven days; numeric record history remains. Abandoned/rejected uploads are removed by scheduled maintenance after upload credentials expire. Deletion may be delayed while a service is unavailable.

To remove your Surfd account and records, open Account โ†’ Delete account in the game. This removes the active profile, records and replay files and revokes login sessions. Temporary upload reservations remain until their credentials expire. Provider logs and backups follow the hosting providers' retention processes. Clearing local site data separately removes preferences and local records from your device.

When a guest run is claimed, a temporary record of its claim ID and account ID prevents the same ticket being reused by another account. This record survives account deletion until the original 24-hour ticket expires and is then eligible for cleanup.

Account deletion does not retract chat or announcements already delivered to another player's browser. Room moderation records follow the short retention periods above.

Contact

For privacy questions or deletion assistance, contact the project maintainer through the project maintainer on GitHub. Do not post passwords, login tokens or other private account details in public issues.

Beta terms