Skip to content
Surf Auth
How it works Protect Developers Pricing Sign in
EN PT
Sign in Start free

Privacy Policy

This policy explains what personal data Surf Auth handles, why, who receives it and how long we keep it. It applies to the developers who use Surf Auth and to the people who run their scripts.

Last updated October 05, 2026

Draft under review

This text is not final. Before it takes effect, Surf Auth will publish the operator’s legal name and address and confirm the governing law.

On this page
  1. 1. Who is responsible
  2. 2. Data about developers
  3. 3. Data about end users
  4. 4. How we use data, and legal bases
  5. 5. Sharing and international transfers
  6. 6. How long we keep data
  7. 7. Security
  8. 8. Your rights
  9. 9. Children
  10. 10. Cookies and browser storage
  11. 11. Changes to this policy
  12. 12. Contact

1. Who is responsible

Surf Auth, which runs the service at surfauth.me, is responsible for the personal data described here: we are its controller and decide how and why it is used. The exception is data about developers’ end users, which we process mainly on the developers’ behalf, as explained in Data about end users.

We handle data about two groups of people: developers, who hold accounts (“you” in most of this policy), and end users, the people who run a developer’s script through that developer’s loader. This policy covers the website, the dashboard, the API and the endpoints that loaders call. It does not cover developers’ own scripts, sites or servers, or the pages of payment providers, which have their own policies. Read it together with our Terms of Service.

For any privacy question or request, write to support@surfauth.me. This address is our channel for data protection requests.

To be confirmed: the legal name and address of the operator of Surf Auth will be published here before this page takes effect.

2. Data about developers

When you create an account and use the service, we collect:

  • Account: your email address, an optional display name, your password as an Argon2id hash (never the password itself), your role and account status, and when you last signed in.
  • Sign-ins and activity: the IP address and browser user agent of each sign-in, and security (audit) logs of the actions taken on your account and resources, with the IP address they came from.
  • Your resources: projects, products, versions, builds, licenses, API keys and webhooks, with the names, descriptions and settings you give them, including webhook URLs and the names, notes and metadata of licenses. License keys and API keys are stored only as hashes.
  • Billing: billing email and country, plan and subscription status, the payment provider’s customer, subscription and payment identifiers, amounts and refunds, and your token balance and history. Card details are entered with the provider and never reach us.
  • Surf Protect and builds: the size of each source you submit, the options you choose, and the size and checksum of the result. Your source code is never stored.
  • Usage and logs: daily usage counters per project and product, and server logs with the method, URL and IP address of each request.
  • Messages: whatever you write to us when you contact support.

3. Data about end users

End users are the people who run a developer’s script through a loader that uses Surf Auth. We do not ask them for a name, an email address or Roblox account details. When a loader activates a license, authenticates or downloads a build, we store:

  • Device: a SHA-256 hash of the device identifier the loader sends, a short display id such as DEV-3fa94c1b7e02, an optional name given by the developer, and when the device was first and last seen.
  • License binding: which license is activated on which device, and since when.
  • Loader sessions: the most recent IP address and user agent of each session.
  • Logs: security records of each loader sign-in attempt and download, and server logs of each request, with the IP address.

The loader chooses the device identifier, and we keep only its hash. Some identifiers can be recovered from their hash, so we still treat it as personal data. The developer of the script can see the device display ids and names, the activation history and each session’s last IP address and user agent, and may receive related events through webhooks. Anything the developer writes in a license’s name, notes or metadata is their responsibility.

For this data, the developer is the controller: they choose to use Surf Auth and decide what their loader sends and who gets a license. We process it on their behalf, as their processor (“operador” under the LGPD), and also to keep the service secure. Developers must tell their end users how their data is handled. If you are an end user, contact the developer of the script first; you can also write to us, but we may not be able to identify you from the little data we hold.

4. How we use data, and legal bases

We use personal data only for the purposes below. Under Brazil’s General Data Protection Law (LGPD, Lei 13.709/2018) and, for people in the European Union or the United Kingdom, the GDPR, each purpose has a legal basis:

  • Providing the service: accounts, sign-in, licenses, device binding, loader authentication, builds, Surf Protect, webhooks, analytics and support. Basis: performance of our contract with you.
  • Security and fraud prevention: sign-in records, audit and server logs, rate limits and detecting abuse of accounts, keys and loaders. Basis: our legitimate interest in keeping the service, our customers and their end users safe.
  • Billing: processing payments through providers, applying plans and tokens, and keeping financial records. Basis: performance of our contract and compliance with legal obligations, such as tax and accounting rules.
  • Legal matters: answering lawful requests from authorities and establishing, exercising or defending legal claims. Basis: compliance with legal obligations and the regular exercise of rights.

We do not sell personal data, use it for advertising or send marketing email. If we ever need your consent for something, we will ask for it, and you can withdraw it at any time.

5. Sharing and international transfers

We share personal data only with:

  • Payment providers: Stripe, and PayPal or Komerza where offered, receive what they need to process your purchase, such as your billing email, and collect your payment details directly. They handle that data under their own privacy policies.
  • The protection engine: when you run a build or a Surf Protect job, your script source is sent to the engine that protects it. The engine is operated for Surf Auth, which does not keep the source.
  • Hosting: the service and its data run on a virtual private server rented from a hosting provider.
  • Your webhook endpoints: event data about your projects goes to the URLs you configure.
  • Developers: the developer of a script sees the data about its end users described above.
  • Authorities: when the law, or a valid order from a court or authority, requires it.

Our servers and these providers may process data outside Brazil and outside your country. When personal data is transferred internationally, we rely on the mechanisms that the LGPD and, where it applies, the GDPR allow, such as contractual safeguards or the transfer being necessary to provide the service you asked for.

6. How long we keep data

We keep personal data for as long as your account exists and, after that, as long as needed for security, billing and legal obligations. This covers account data, sign-in records, audit logs, licenses, devices and billing records. You can ask us to delete your data at any time (see Your rights). Some data has its own limits:

  • Surf Protect source code is never stored, and protected outputs are deleted 24 hours after each run.
  • Webhook events and their delivery history are kept for about 30 days.
  • Daily usage counters are kept for 400 days.
  • Loader sessions may be removed after they expire.
  • Build artifacts, the files your loader downloads, are kept until they are removed.

When we delete an account, we delete or anonymize its data, except what the law requires us to keep, such as billing records.

7. Security

We protect personal data with technical measures suited to the service, including:

  • passwords hashed with Argon2id, and session tokens, API keys, runtime tokens and license keys stored only as hashes;
  • device identifiers stored only as SHA-256 hashes;
  • webhook signing secrets encrypted with AES-256-GCM;
  • HTTPS for the site, the dashboard and the API;
  • secrets and authorization headers removed from server logs;
  • access controls that keep each developer’s data apart from other accounts.

No system is completely secure. If a security incident may cause you significant risk or harm, we will notify you and the competent authorities as the law requires.

8. Your rights

Under the LGPD and, where it applies, the GDPR, you can ask us to:

  • confirm whether we process your data, and give you access to it;
  • correct data that is incomplete, inaccurate or out of date;
  • delete your data, or anonymize or block data that is unnecessary, excessive or processed unlawfully;
  • give you your data in a portable format;
  • tell you who we share your data with;
  • stop or restrict processing you object to, where the law gives you that right;
  • withdraw any consent you gave.

To exercise these rights, write to support@surfauth.me, from your account’s email address if you have an account. The dashboard does not let you export your data or delete your account yourself, so we handle these requests by email. We may ask you to confirm your identity, and we will answer within the time the law sets.

You can also complain to Brazil’s National Data Protection Authority (ANPD) or, in the EU or UK, to your local data protection authority.

9. Children

The service is not directed to children. To create an account, you must be old enough to form a binding contract where you live; if we learn that an account holder does not meet this requirement, we will close the account.

Scripts that use Surf Auth may be run by people of any age. We do not ask end users for their age or identity, and we collect only the technical data described in Data about end users. Each developer is responsible for following the rules that apply to minors’ data in their scripts, including getting consent where the law requires it.

10. Cookies and browser storage

We do not use cookies to track you, and the site and dashboard use no visitor analytics or advertising tools. They keep only a few items in your browser’s storage:

  • your language choice, on the site and in the dashboard (local storage);
  • your dashboard session token, until you sign out or the session expires (local storage);
  • for a moment, the dashboard address you opened, so a direct link still works after a redirect (session storage).

You can clear these items in your browser settings at any time; clearing the session token signs you out of the dashboard. Payment pages run by Stripe, PayPal or Komerza may use their own cookies under their own policies.

11. Changes to this policy

We may update this policy as the service changes. The date at the top of this page shows the current version. When a change significantly affects how we handle your data, we will announce it on the site before it takes effect.

12. Contact

For questions about this policy or your personal data, write to support@surfauth.me. If you are an end user of a script that uses Surf Auth, you can also contact the developer of that script.

Terms of Service →

Surf Auth

Access control for Luau scripts.

How it works Protect Developers Pricing Sign in Start free
Language
EN PT

© 2026 Surf Auth

Terms of Service Privacy Policy