Back to Surecut
Surecut

Privacy Policy

Last updated: July 15, 2026

What Surecut Does

Surecut is a browser extension that adds an AI workspace beside the current page. You can chat with page context, generate or edit images, run browser agent tasks, and save repeated workflows as scripts.

Data We Collect

  • Account and authentication data: When you sign in, we receive your email address, name, profile image, account identifier, access level, and a Surecut session credential. We use this data to authenticate you, keep your account secure, manage device access, and provide account features.
  • Prompts, page content, and task instructions: When you request a page-aware feature, Surecut may process the current page URL, title, selected or relevant text, images, form content you choose to include, prompts, and browser-agent instructions needed to complete that request.
  • Workspace content: Conversations, scripts, drafts, saved workflows, settings, preferences, and related metadata are stored locally and may be synced to your account when cloud sync is enabled.
  • Images, files, and voice input: Images and files you upload, generated outputs, and audio or transcripts used with voice features may be processed to provide the feature you request.
  • Usage, diagnostics, and support data: Feature events, usage amounts, device details, error information, run status, feedback messages, and support communications help us operate the service, enforce limits, prevent abuse, and resolve problems.
  • Billing data: We receive transaction status, plan, billing email, and subscription identifiers from our payment provider. Surecut does not receive or store your full payment-card number.

Before We Collect Data

Surecut shows an in-product data use disclosure before sign-in and account-based features. Users must accept this disclosure before Surecut starts account sign-in, cloud sync, or account-linked support workflows.

For page-aware AI features, image features, voice features, and browser agent actions, Surecut processes the selected page context, prompt, image, audio, or task data only when you request that feature.

Data We Do NOT Collect

  • Your full browsing history or continuous activity across tabs
  • Page content from tabs where you do not ask Surecut to work
  • Passwords or website cookies from pages you visit
  • Full payment-card numbers handled directly by our payment provider

How We Process and Use Data

  • Authenticate your account, maintain your Surecut session, and manage access across authorized devices
  • Send only the inputs needed for the AI, image, voice, browser-agent, or script feature you request
  • Save and synchronize supported workspace content when cloud sync is enabled
  • Measure usage, apply plan limits, diagnose failures, secure the service, and prevent fraud or abuse
  • Process payments, maintain subscription access, respond to feedback, and provide customer support

Data is sent over encrypted HTTPS connections. Surecut does not use user data for third-party advertising, creditworthiness, or purposes unrelated to the feature or service the user requested.

Where Data Is Stored

Settings, session information, scripts, drafts, conversations, and supported assets may be stored locally in Chrome extension storage or browser storage on your device. When cloud sync is enabled, supported workspace content and assets are stored in Surecut's account-linked Cloudflare-hosted databases and object storage so they can be available across your signed-in devices.

Inputs sent to an AI, image, voice, identity, hosting, or payment provider are also processed on that provider's systems only as needed to deliver the selected feature or service, subject to the provider's applicable terms and privacy policy.

How Long We Keep Data

  • Local data: Kept on your device until you delete it in Surecut, clear the extension's data, or uninstall the extension.
  • Account and synced workspace data: Kept while your account remains active or until you delete the content, disable and clear cloud-synced content, or delete your account.
  • Usage, diagnostics, and feedback: Kept only as long as reasonably necessary to operate, secure, troubleshoot, and support the service, and deleted with your account unless retention is required for legal or security reasons.
  • Billing records: Account-linked checkout data is removed when your account is deleted. Limited transaction and subscription records may be retained in de-identified form, and payment-provider records may be retained as required for tax, accounting, fraud prevention, dispute resolution, or other legal obligations.

When you delete your Surecut account, Surecut deletes account details, active sessions, synced workspace content, uploaded assets, usage records, diagnostics, and feedback associated with that account from active Surecut systems. Data already sent to a third-party provider is governed by that provider's retention and deletion practices.

How and When We Share Data

Surecut shares data only with service providers needed to deliver a feature you request, operate the service, process payments, protect users, or comply with law. The data shared is limited to what that provider needs for its role:

  • Identity: Google receives and returns authentication data when you choose Google sign-in.
  • AI and media processing: Selected prompts, page context, images, files, or voice inputs may be sent to Anthropic, OpenAI, xAI, DeepSeek, or OpenRouter, depending on the feature and provider you select.
  • Hosting and storage: Cloudflare processes account, synced content, assets, and operational traffic for hosting, storage, security, and edge delivery.
  • Payments: Creem processes checkout and payment information and sends Surecut the transaction and subscription status needed to provide paid access.

We may also disclose the minimum necessary data when required by law, to investigate fraud or security threats, to protect users or the service, or as part of a business transfer subject to appropriate confidentiality and data-protection obligations. Surecut does not sell or rent personal data and does not share it with data brokers or advertisers.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Your Controls and Choices

  • Choose whether to provide page context, files, images, voice input, prompts, feedback, or browser-agent instructions
  • Turn cloud sync off in Surecut settings for local-only use of supported workspace features
  • Withdraw data-use consent; account-linked collection and cloud sync will stop until consent is accepted again
  • Delete individual conversations, scripts, drafts, and assets from the product
  • Delete your Surecut account from account settings to remove account-linked data from active Surecut systems
  • Contact us to request access, correction, deletion, or answers about your personal data

Permissions

  • activeTab: To read or act on the current tab when you request it
  • scripting: To run approved scripts and agent actions on web pages
  • storage: To save login state, scripts, drafts, and settings
  • sidePanel: To display the Surecut workspace
  • tabs: To manage workspace overlays and connect Surecut to the tab you are using

Security

Surecut uses encrypted transmission, authenticated account access, device and session controls, usage limits, script checks, and confirmation steps for sensitive browser actions. No system can guarantee absolute security, so you should still review generated content, scripts, and agent actions before relying on them.

Contact

For questions about this privacy policy, contact us at [email protected].