Privacy.
Surve reads a business's email inbox and replies to it. That means we handle other people's messages, so being vague here would be a poor start. This page says what we read, what we keep, how long we keep it, and who else touches it.
- 1. Two different roles
- 2. When you contact us
- 3. When we run your inbox
- 4. How long we keep things
- 5. Who else touches the data
- 6. AI and model training
- 7. Security
- 8. Your rights
- 9. Where data goes
- 10. Contact
1. Two different roles
Surve handles personal data in two quite different capacities, and the rules differ for each. Conflating them is how privacy policies become useless, so they are separated below.
- As a controller — for the handful of details you give us directly: your waitlist signup, your account, our correspondence with you. We decide what to do with those.
- As a processor — for everything inside the inbox you connect. That mail belongs to you and to the people who wrote to you. We act on your instructions and nothing else. The terms governing that are in the Data Processing Agreement.
2. When you contact us or join the waitlist
| What | Why | Lawful basis |
|---|---|---|
| Email address | To reply and to tell you when we launch | Consent (you typed it in) |
| IP address, browser user-agent | Rate limiting, to stop the form being flooded | Legitimate interests (keeping the service up) |
| Account details, billing contact | Running your subscription and invoicing | Contract |
Waitlist entries are deleted 90 days after signup if you have not become a customer. There is no marketing list beyond this, and every email we send you has a working unsubscribe.
3. When we run your inbox
Once you connect a mailbox, Surve reads the messages that arrive in it in order to classify them, draft replies, and route the ones a person needs to see. For each message it handles, Surve stores:
- the sender's name and address, the subject, and the message ID;
- the message body, and any reply that was drafted or sent;
- a short summary, a category, and whether a human was needed;
- timestamps and an audit record of what was sent and when.
Attachments are not stored. Surve reads only the mailbox you explicitly connect — not your other mailboxes, not your files, not your calendar.
Surve never moves money. It cannot issue a refund, confirm a price, or make a binding commitment; anything touching money, disputes or legal matters gets a holding acknowledgement and is escalated to a person. This is enforced in code and tested, not merely promised.
Every reply Surve sends says that it is AI-assisted, and tells the recipient they can reply to reach a person. That disclosure is on by default and is a requirement of the EU AI Act (Article 50), not a stylistic choice.
4. How long we keep things
| Data | Kept for |
|---|---|
| Handled messages and drafted replies | 45 days after the conversation is resolved, then automatically deleted |
| Audit records of what was sent | 12 months — you need to be able to answer "what did it say to my customer?" |
| Waitlist entries | 90 days, unless you become a customer |
| Billing records | 6 years, because UK tax law requires it |
| Mailbox access tokens | Until you disconnect the inbox or close the account |
The 45-day purge runs nightly and is automatic. If you close your account, everything other than billing records is deleted within 30 days.
5. Who else touches the data
We use a small number of suppliers. Each is bound by a contract no weaker than this policy, and each is listed because pretending otherwise would be dishonest.
| Who | What for | Where |
|---|---|---|
| Anthropic | The AI model that classifies mail and drafts replies | USA |
| Hetzner | The servers Surve runs on | Germany (EU) |
| Supabase | Database | EU (London / Frankfurt) |
| Gmail access, only if you connect a Google mailbox | USA / EU | |
| Stripe | Card payments, if you pay by card | USA / EU |
We will tell you before adding a new sub-processor, so that you have the chance to object. We do not sell data, share it for advertising, or hand it to data brokers.
6. AI and model training
Your mail is not used to train any AI model — not ours, not our suppliers'. Messages are sent to the model to produce one answer and are not retained by us for training.
Surve drafts replies; it does not make decisions with a legal or similarly significant effect on anyone. A person can review anything, and new accounts start in a mode where every reply is held for approval before it is sent.
7. Security
- Everything is encrypted in transit (TLS). Mailbox credentials are stored on access-restricted servers and are being moved to encryption at rest.
- Each customer's data is isolated; one account cannot read another's.
- There is a kill switch that stops all sending immediately.
- Mail arriving from third parties is treated as data, never as instructions — attempts to manipulate the AI through the contents of an email are detected and get a fixed safe reply.
- Access to production is limited to the people who need it.
If a breach affects your data, we will tell you without undue delay and within 72 hours of becoming aware, with what we know and what we are doing about it.
8. Your rights
Under UK and EU data protection law you can ask for a copy of your data, ask us to correct or delete it, object to processing, or ask us to restrict it. Email privacy@surve.app and we will respond within one month.
If the request concerns mail inside a customer's inbox, we are the processor, not the controller — we will point you to the business whose inbox it is, and help them answer you. If you are that business, you can export or delete a person's data from your account at any time.
You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
9. Where data goes
Surve runs on servers in Germany and stores data in the EU. Two suppliers — Anthropic and, where relevant, Stripe — process data in the United States. Those transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
10. Contact
Surve
privacy@surve.app