Back

Privacy Policy

Last updated: 2026-08-13

This policy explains what personal information SurfPath - AI Surf Coach (the “Service”) collects, where it is stored, who processes it, and what you can do about it. It applies to every user, and sits alongside our Terms of Service (Australia) and CGU (France).

1. Who is responsible for your data

The data controller is Pierre-Alexis Thoumieu, trading as Thoumieu Consulting, established in France, a sole trader (entreprise individuelle), SIRET 952 576 981 00023, registered address 38 rue Rosenwald, 75015 Paris, France. Contact for any privacy question or request: contact@surfpath.ai.

Because the operator is established in the EU, the EU General Data Protection Regulation (GDPR) applies to all processing described here. For users resident in Australia, the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) apply in addition. Where the two differ, we apply whichever gives you the stronger protection.

2. What we collect

You give us directly

Generated about you

Measured in your browser

Every page of the Service loads Umami, a privacy-preserving analytics script, so we can see how many people visit and which pages they read. It records the page viewed, the site that referred you, your browser, operating system, device type and country — no more. It sets no cookies, stores no identifier on your device, and does not follow you across other websites, so it cannot tell that two visits came from the same person, and it never learns which account you are signed in as. Because it stores nothing on your device and identifies nobody, no consent banner is required for it and there is nothing for you to switch off.

Anti-abuse checks in your browser

When a page talks to our servers it first loads Google reCAPTCHA Enterprise, which checks that the request comes from a real browser using the app and not from an automated script. It runs in the background — there is nothing for you to click. To make that judgement it reads technical signals: your IP address, your browser and device characteristics, and how the page is being interacted with. It also stores a cookie on Google's own domainfor the same purpose. We receive only the verdict — a short-lived token saying "this really is the app" — and never the signals behind it, and Google is never told which account you are signed in as. It is used for security alone: not for advertising, not for audience measurement, and not to build any profile of you. Because protecting the Service against abuse is strictly necessary to run it, this one needs no consent banner (see section 3 — legitimate interest); if you block it, signing in and requesting an analysis may be refused.

Beyond that we use no tracking cookies and no advertising identifiers, and we do not sell or rent personal information to anyone.

3. Why we process it, and on what legal basis

We do not use your videos, photos, journal entries or reports to train our own models, and we do not use them for any purpose unrelated to coaching you.

4. Artificial intelligence: which model, and what happens to your video

Your coaching analysis is produced by Google Gemini, accessed through Google Vertex AI. When you request an analysis, the video (or photo) and the accompanying prompt are sent to that model, which returns the written assessment you then see in the app.

Google Vertex AI operates under enterprise data terms: content you submit is not used to train or improve Google's foundation models, is not reviewed by humans for model improvement, and is not retained by Google beyond what is needed to return the response and meet abuse-detection requirements. Google acts as our processor for this, not as an independent controller.

The AI output can be wrong. It is generated automatically, but it does not produce any legal or similarly significant effect about you within the meaning of GDPR art. 22 — it is recreational coaching feedback that you are free to ignore. No decision about your access to the Service, your pricing, or anything else is taken automatically on the basis of your analyses.

5. Where your data is stored, and which services process it

The Service runs on Google Cloud Platform. Most of your data sits in Australia (australia-southeast1) — including for French users, which is a transfer outside the EEA (see section 7).

Each of these is a processor acting on our instructions under a data processing agreement. We do not disclose your personal information to anyone else except where the law requires it.

6. How long we keep it — and what deletion really means

Your account data, videos, analyses and journal entries are kept for as long as your account is in use, and for at most two years after you last use it. If nobody signs in to an account for two years, we erase it in full — the same deletion described below, run automatically. Signing in resets that clock, so an account you keep using is never swept. You control this directly:

Backups are the honest exception. Our database is backed up on a schedule, and those backups cannot be edited to remove one person's records. Data you delete therefore survives in backups for up to 14 weeks, after which the backups expire and it is gone. During that window the backups are only ever used to recover from a failure of the Service as a whole — never to restore an individual account. Server logs mentioning your account identifier expire after 30 days. Transaction records required for accounting are kept for the period the law requires, independently of your account.

7. International transfers

If you are in the EU/EEA, your data is transferred to Australia and the United States. Neither Australia nor the United States benefits from a general EU adequacy decision covering these transfers, so they rely on Standard Contractual Clauses adopted by the European Commission, entered into with Google Cloud and Stripe, together with the technical measures those providers maintain (encryption in transit and at rest, access controls). Quality-monitoring data stays in the EU and is not a third-country transfer. Audience measurement (Umami) may be handled on servers in the EU or the United States, but the data it holds identifies nobody, so nothing about you personally is transferred through it.

If you are in Australia, APP 8 applies: by using the Service you are informed that your personal information is disclosed to overseas recipients — principally in the United States (Google Identity Platform, Vertex AI, reCAPTCHA Enterprise, Stripe) and in the EU, where the operator is established and quality monitoring (Langfuse) is hosted. We take reasonable steps to ensure those recipients handle it consistently with the APPs, but you should be aware that overseas recipients may be subject to foreign lawful-access requirements.

8. Your rights

Under the GDPR you have the right to:

Under the Australian Privacy Principles you have the right to access your personal information (APP 12) and to ask us to correct it (APP 13). If you are not satisfied with how we handle a request or a complaint, you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au).

Most of these you can exercise yourself in the app, without asking us and without waiting:

For anything the app doesn't cover — restriction, objection, or a complaint — write to contact@surfpath.ai. We will respond within one month (GDPR) or 30 days (APP 12), and we do not charge for a request.

9. Other people in your videos

If someone else appears in a video or photo you upload, you are responsible for having their consent before uploading — this is a condition of using the Service. Their image is processed exactly like yours and deleted with the file. If someone who appears in your content contacts us to have it removed, write to [contact email] and we will act on it.

10. Children

The Service is not intended for anyone under 16, and you must confirm you are at least 16 to create an account. We do not knowingly collect personal information from children under 16; if we learn that we have, we delete it.

11. Security

Data is encrypted in transit and at rest by our infrastructure providers. Storage buckets block all public access, and every read and write goes through our backend, which checks that the record belongs to you; the database's own rules deny anything that would reach it from a browser directly. Access to production data is limited to the operator. No system is perfectly secure; if a breach affects your personal data and is likely to put you at risk, we will notify you and the competent authority as the GDPR and the Notifiable Data Breaches scheme require.

12. Changes to this policy

We may update this policy as the Service changes. Material changes will be notified to you, and the “last updated” date above always reflects the current version.

13. Contact

Any privacy question, request or complaint: contact@surfpath.ai. We have not appointed a Data Protection Officer, as we are not required to.