Skip to content
Surf Auth
How it works Protect Developers Pricing Sign in
EN PT
Sign in Start free

Terms of Service

These terms explain what Surf Auth provides, what you are responsible for when you use it, how payments work and what happens if something goes wrong.

Last updated October 05, 2026

Draft under review

This text is not final. Before it takes effect, Surf Auth will publish the operator’s legal name and address and confirm the governing law.

On this page
  1. 1. About these terms
  2. 2. Your account
  3. 3. Your scripts and your end users
  4. 4. Acceptable use
  5. 5. API keys and webhooks
  6. 6. Plans, payments and refunds
  7. 7. Availability and changes
  8. 8. Intellectual property
  9. 9. Suspension and termination
  10. 10. Disclaimers and limitation of liability
  11. 11. Governing law and disputes
  12. 12. Contact

1. About these terms

These Terms of Service are an agreement between you and Surf Auth (“we”, “us”), which runs the service at surfauth.me. They cover the website, the dashboard, the API and everything else we provide under the Surf Auth name, including Surf Protect.

Surf Auth is a service for developers of Roblox and Luau scripts. It issues license keys for your scripts, binds keys to devices, authenticates your loader before every download and lets you revoke access mid-session. It also offers API keys and a Developer API, webhooks, analytics and Surf Protect, which turns your Lua or Luau source into a protected build.

To be confirmed: the legal name and address of the operator of Surf Auth will be published here before this page takes effect.

By creating an account or using the service, you accept these terms. Our Privacy Policy explains how we handle personal data. If you do not agree, do not use the service.

We may update these terms. The date at the top of this page shows the current version. When a change is significant, we will announce it on the site before it takes effect. If you keep using the service after that, the new terms apply; if you do not accept them, stop using the service and cancel any subscription.

2. Your account

You must be old enough to form a binding contract where you live. If you use the service for an organization, you confirm that you are authorized to accept these terms on its behalf.

Give accurate information when you register. An account belongs to one person: do not share it or let others sign in with it. Your servers and tools should use API keys, not your password.

Keep your password secret. You are responsible for what happens under your account. If you think someone else has access to it, write to support@surfauth.me right away.

3. Your scripts and your end users

You decide what your scripts do, who receives a license key and how your loader behaves. You are responsible for your scripts, for your loader, for supporting the people who run your scripts (your end users) and for the information you store in the service, such as license names, notes and metadata.

Use the service lawfully and follow the rules of the platforms where your scripts are published or run, including the Roblox Terms of Use where they apply. Roblox is a trademark of Roblox Corporation; Surf Auth is not affiliated with or endorsed by Roblox.

When your end users run your script, your loader sends us data about their devices and connections, as described in our Privacy Policy. You must tell your end users how their data is handled and have a legal basis for it.

4. Acceptable use

Do not use the service, or help anyone else use it, to:

  • distribute malware, or scripts that steal accounts, passwords, cookies or other credentials;
  • harass, threaten or defraud anyone;
  • distribute content you do not have the right to use, such as other people’s scripts;
  • attack, overload or probe the service, or access data or accounts that are not yours;
  • reverse engineer the service, the protection engine or the API, except where the law expressly allows it;
  • abuse the API or the endpoints your loader uses, or get around rate limits, scopes or other technical limits;
  • get around plan limits or payments, for example by opening extra accounts to get more free usage;
  • resell or sublicense access to the service, or to your account, without our written permission.

If we believe you are breaking these rules, we may remove content, disable keys or webhooks, or suspend your account, as described in Suspension and termination.

5. API keys and webhooks

API keys and webhook signing secrets are shown only once. Keep them secret and on your servers: never put them in a script you distribute or in a public repository. You are responsible for every request made with your keys.

Give each key only the scopes it needs, and revoke or rotate any key you no longer trust. We may revoke a key or disable a webhook that appears to be compromised, is being abused or puts the service at risk; when we can, we will tell you.

Webhooks send event data about your projects to the URLs you configure. You are responsible for those endpoints, for checking the signature of each delivery and for how you use the data you receive.

6. Plans, payments and refunds

Surf Auth has a Free plan and two paid subscriptions, Pro and Studio, billed monthly or yearly. Surf Protect tokens are sold separately. Prices are in US dollars and listed on the pricing page; your bank may add currency conversion fees or taxes on international purchases.

  • Payments. Third-party providers (Stripe, and PayPal or Komerza where offered) process payments on their own checkout pages or forms, under their own terms. Your card details never reach us. A plan or tokens are applied once the provider confirms the payment.
  • Renewals. Subscriptions renew automatically at the end of each period until canceled. To cancel or change plans, write to support@surfauth.me, or use the payment provider’s tools where they are available. Canceling stops future renewals; your plan stays active until the end of the period you have paid for.
  • Surf Protect tokens. Each Surf Protect run, including a protected build, uses tokens based on the size of the source, as shown on the pricing page; runs that fail are not charged. Tokens included with Pro or Studio are credited each billing period and expire at its end. Tokens have no cash value and cannot be moved to another account.
  • Failed or reversed payments. If a renewal fails, your account may fall back to the Free plan’s limits until the payment goes through. If a payment is refunded or charged back, we may remove the plan time or tokens it paid for; if those tokens were already used, your token balance can go negative and Surf Protect runs pause until it is covered.
  • Refunds. We handle refund requests case by case: write to support@surfauth.me with the details of the purchase. Approved refunds are paid through the provider used for the purchase, under its rules.

Nothing in these terms limits the rights that consumer protection law gives you, including any legal right to withdraw from a purchase.

7. Availability and changes

We work to keep Surf Auth running, but we provide it on a best-effort basis. Unless we have agreed otherwise in writing, there is no guaranteed uptime, and the service may be interrupted for maintenance, by failures of our providers or by events outside our control.

Your loader checks with the service before each download. If the service cannot be reached, your scripts may not load for your end users until it is back. Take this into account in your loader and in how you support your users.

We may add, change or remove features, limits and plans. When a change significantly reduces what a paid plan includes, we will try to tell you in advance.

8. Intellectual property

You keep all rights to your scripts, your source code and anything else you upload. You give Surf Auth a limited, non-exclusive, worldwide, royalty-free license to host, copy, process, protect and deliver that content, only as needed to run the service for you. This license ends when the content is deleted from the service.

You confirm that you own your content or have the rights needed to upload it and to let us process it this way.

The service, its software, the protection engine and the Surf Auth and Surf Protect names and logos belong to us or our licensors. You may use and distribute the protected builds made from your scripts, but this gives you no rights to the protection technology itself. If you send us feedback, we may use it without any obligation to you.

9. Suspension and termination

You can stop using the service at any time. To close your account, write to support@surfauth.me; we will also cancel any active subscription.

We may suspend or close your account, or disable specific keys, licenses, products, builds or webhooks, if you break these terms, if the law requires it, if a payment is reversed or charged back, or if it is needed to protect the service, other customers or end users. When we can, we will tell you why and give you a chance to fix the problem.

When an account is closed, its loaders, license keys and API keys stop working, and we delete or anonymize its data as described in the Privacy Policy, except what the law requires us to keep. Sections that by their nature should survive, such as intellectual property, liability and governing law, continue to apply.

10. Disclaimers and limitation of liability

To the extent the law allows, the service is provided “as is” and “as available”, without warranties of any kind, express or implied, including warranties of merchantability, fitness for a particular purpose and non-infringement.

No protection is unbreakable. License checks, device binding and Surf Protect make unauthorized use and copying harder, but we do not guarantee that no one will get around them or recover your source. We are not responsible for your scripts, for your end users or for decisions made by Roblox or other platforms.

To the extent the law allows, we are not liable for indirect or consequential losses, such as lost profits, revenue, data or goodwill, and our total liability for all claims relating to the service is limited to the amounts you paid us in the 12 months before the event that gave rise to the claim.

Nothing in these terms excludes or limits liability that the law does not allow to be excluded or limited, such as liability for fraud or willful misconduct, or the rights you have as a consumer.

11. Governing law and disputes

These terms are governed by the laws of Brazil (to be confirmed).

If you use the service as a consumer, you keep the protection of the mandatory laws of the place where you live, and you may bring claims in the courts those laws allow.

If you have a problem with the service, please write to support@surfauth.me first. Most issues can be solved quickly, without a formal dispute.

12. Contact

Questions about these terms, your account or a payment? Write to support@surfauth.me. For questions about personal data, see our Privacy Policy.

Privacy Policy →

Surf Auth

Access control for Luau scripts.

How it works Protect Developers Pricing Sign in Start free
Language
EN PT

© 2026 Surf Auth

Terms of Service Privacy Policy