โ† Back to Surfd

Privacy

Public beta ยท Updated 3 October 2026

Surfd is an independent browser surfing game. You can play without an account. Signing in is optional and enables public records.

Information used

Google or X supplies account information to Supabase Auth when you sign in, such as your provider identifier, email address, name and avatar. Surfd uses your account ID to associate your profile and records. It does not request permission to post to your social account.

Online records contain your chosen username, account ID, map and movement version, completion time, checkpoint splits, date, and recorded movement commands. Usernames, account IDs, verified records and available verified replays are public. Your email address and login credentials are not included in leaderboard responses.

Your browser saves controls, preferences, local personal bests, login session and pending submission information in local storage. You can clear these using your browser's site-data controls. There are no advertising or analytics SDKs in the game.

If you finish an eligible run as a guest, the browser also keeps one completed command replay and its temporary claim ticket in IndexedDB so you can sign in and save that run. The replay is uploaded only after you choose to save it or sign in to save it. An unclaimed replay is valid for 24 hours from the run ticket's issue time. Once linked to an account, its local copy can remain for up to seven days to recover an interrupted upload or verification. Expired copies are removed the next time the game accesses them; you can also dismiss the copy or clear site data. An already-uploaded run may still finish verification after its local copy is dismissed.

Hosting and security

Vercel hosts the website and processes record submissions. Supabase provides authentication, the database and replay storage. These providers may process IP addresses, request details and operational/security logs as part of running their services. See Vercel's privacy policy and Supabase's privacy policy.

Retention and deletion

Personal-best replay files remain available with their records. Other verified replay files are eligible for removal after seven days; numeric record history remains. Abandoned/rejected uploads are removed by scheduled maintenance after upload credentials expire. Deletion may be delayed while a service is unavailable.

To remove your Surfd account and records, open Account โ†’ Delete account in the game. This removes the active profile, records and replay files and revokes login sessions. Temporary upload reservations remain until their credentials expire. Provider logs and backups follow the hosting providers' retention processes. Clearing local site data separately removes preferences and local records from your device.

When a guest run is claimed, a temporary record of its claim ID and account ID prevents the same ticket being reused by another account. This record survives account deletion until the original 24-hour ticket expires and is then eligible for cleanup.

Contact

For privacy questions or deletion assistance, contact the project maintainer through the project maintainer on GitHub. Do not post passwords, login tokens or other private account details in public issues.

Beta terms