Surge ⚡ · Legal

Surge Privacy Policy

Effective date: 23 August 2026  ·  Last updated: 23 August 2026  ·  Version 1.0

This policy covers Surge, the AI ad-generation product operated by ClipSpeedAI. It explains, feature by feature, what data Surge collects, where that data physically lives, how long we keep it, who else touches it, and how to get it back or get rid of it. It is written to be read, not to be survived.

The short version
Contents
  1. Who we are
  2. What this policy covers
  3. Terms used here
  4. What Surge collects, feature by feature
  5. AI, model training, and what Surge learns from you
  6. Third-party trending content & removal requests
  7. Publishing, and what Surge still does not do
  8. How we use your information
  9. Who we share it with
  10. No sale, no sharing, no ad profiling
  11. How long we keep things
  12. Deleting your data
  13. Security
  14. Your privacy rights
  15. International transfers
  16. Children
  17. Cookies & local storage
  18. Changes to this policy
  19. Contact

1. Who we are

ClipSpeedAI ("ClipSpeedAI", "we", "us", "our") is the controller of the personal information described in this policy. ClipSpeedAI was founded by Kyle White and is operated from Florida, United States. Surge is one of our products; ClipSpeedAI's video-clipping product is another.

ControllerClipSpeedAI · founded by Kyle White · operated from Florida, USA
ProductSurge ⚡ — clipspeed.ai/surge.html
General supportsupport@clipspeed.ai
Privacy & data rightsprivacy@clipspeed.ai
Security disclosuresupport@clipspeed.ai with "Security disclosure" in the subject

2. What this policy covers

This policy applies to the Surge product: the marketing page at /surge.html, the Surge application, Surge demo links, the Surge API, and Surge emails.

ClipSpeedAI's video-clipping product is governed by a separate policy: clipspeed.ai/privacy.html. That policy covers the part of ClipSpeedAI that connects to your YouTube, TikTok, Instagram, X and LinkedIn accounts and holds the resulting access tokens. Surge uses those connections to publish, but does not create or store them — so token handling, and how to revoke a connection, live in that policy and are cross-referenced here rather than restated. See Section 7.

If you use both products with one account, both policies apply to their respective features. Where this policy and the ClipSpeedAI policy differ about a Surge feature, this policy governs.

This policy sits alongside our Terms of Service, which govern your use of Surge. Defined terms have the same meaning in both documents.

3. Terms used here

TermMeaning
SurgeThe AI ad-generation product described in this policy.
Brand ProfileThe structured description of your business that Surge derives from scanning the website URL you paste — what you sell, who you sell to, your tone, your positioning, your competitors.
AdA generated creative — a meme ad, slideshow, creator-style post or wall-of-text card — produced by Surge for you.
SwipeYour keep-or-kill judgement on a single Ad: right means you would post it, left means you would not.
LibraryThe store of media files you upload to Surge, plus the Ads you have generated.
AI StudioThe Surge surface where you type a prompt and receive a generated image.
AI CharacterA persistent synthetic person you create in Surge and reuse across Ads. Also referred to in the product as an "AI influencer".
Trending FeedThe corpus of publicly posted third-party social content Surge analyses to understand what formats are working. See Section 6.
CalendarThe Surge schedule of Ads you have queued to go out, each with a platform, a date and a time.
Connected AccountA social account you have linked to ClipSpeedAI. Surge publishes through these; it does not create them. See Section 7.
Demo LinkA signed, time-limited link that lets a prospective customer try Surge without creating an account.
CreditsThe internal unit consumed by generation actions in AI Studio and AI Characters.

4. What Surge collects, feature by feature

Most privacy policies open with a page-long list of everything a company could conceivably collect. That style is legally safe and practically useless — it tells you nothing about what actually happens when you press a button. So this section is organised by feature. If a feature is not listed, it does not collect anything beyond the server logs in 4.13.

4.1 Your account

A Surge account is a ClipSpeedAI account. When you sign up — by email, or with "Sign in with Google" — we receive and store your email address and, if your provider supplies it, your name. We never receive or store your password for Google or any other identity provider.

Signing in with Google is an authentication step. It does not connect a YouTube channel to Surge, and it grants Surge no access to your Google data beyond your basic profile.

4.2 The website you paste, and your Brand Profile

The core Surge action is pasting your website URL. When you do, our server fetches your site from our own infrastructure — not from your browser — and reads it:

That text is analysed into a Brand Profile: your business summary, offer, audience, tone, keywords, calls to action, angles, identified gaps (social proof, urgency, founder story, and so on), positioning, voice do's and don'ts, segments and competitors. If you edit any of it, your edits are stored alongside the derived values.

Where it is stored: a single row keyed to your user ID in our Supabase Postgres database (US region), in the table blitz_brand_profiles — columns user_id, url, profile (JSON), updated_at.

What leaves our systems: the extracted page text is sent to one AI provider — Anthropic or OpenAI, whichever is configured — to perform the analysis. It is sent for inference only. See Section 5.

Only fetch the URL of a site you are entitled to have analysed. Our fetcher identifies itself as ClipSpeedAI-Surge/1.0, obeys a request timeout, and is restricted so it cannot be pointed at private or internal network addresses.

4.3 Your swipes

Every keep-or-kill judgement you make is recorded as one row in the table blitz_swipes. The row holds:

We do not store your IP address or your browser user-agent on this path. That table is readable only by our server; it is not exposed to any client, including yours.

What we do with swipes is described in Section 5.3. In short: your swipes change which ads Surge shows you next — that is the point of swiping — and no model is trained on them.

4.4 Media you upload to the Library

You can upload JPEG, PNG, WebP images and MP4 video to your Library, between 1 KB and 40 MB per file, up to 200 files. We verify the real file type from the file's own bytes rather than trusting its name or the type your browser declares.

Where it is stored: Cloudflare R2 object storage, under a key of the form blitz/media/<your user id>/<random>.<ext>, served from cdn.clipspeed.ai. The index entry — the file's name (which defaults to your original filename), type, size, storage key and URL — is stored in your Brand Profile row.

Please read this before uploading anything sensitive. Files in the Library and in AI Studio are stored at long, randomly generated, unguessable URLs, and they are not individually access-controlled. They are not listed anywhere, not indexed, and not discoverable by browsing — but anyone who has the exact URL can open the file without signing in. Treat a Surge file URL like a password. Do not upload material you would be unwilling to have viewed by someone holding that link.

4.5 AI Studio prompts and generated images

When you generate an image in AI Studio we store, in your Brand Profile row: the prompt you typed, the full assembled prompt our template produced from it, the template and model used, the aspect ratio, quality, dimensions, file size, generation time, and the resulting image's storage key and URL. The image itself goes to Cloudflare R2 under assets/<your user id>/surge_studio/.

Your typed prompt is retained verbatim. If you would not want a prompt kept, do not type it. AI Studio does not accept reference-image input, and Surge has no video generation.

The most recent 60 generations are kept in your generation history; older entries fall off the list automatically.

4.6 AI Characters — likeness and biometric-adjacent data

This is the most sensitive thing Surge does, so it gets its own explicit treatment.

What an AI Character actually is

An AI Character is a base image plus a short written description. We store: a name you choose, the descriptors you enter (gender, age, ethnicity, free-text details), the assembled prompt, the model used, the credits spent, the character's base image URL and storage key, timestamps, and — where relevant — the time you confirmed you hold the rights to the image.

What we do NOT create or store

We say this plainly because "AI avatar" products frequently do the opposite, and because biometric identifiers are separately regulated in several US states. Under those statutes, Surge does not collect biometric information.

If you upload a photograph of a real person

Surge lets you upload a portrait as a character's base image. If you do:

You may hold up to 50 characters. Deleting a character removes it from your account and removes its image from our object storage.

4.7 Publishing a scheduled ad

Surge has a Calendar. Until 23 August 2026 that Calendar was only a plan, and Surge published nothing. It now publishes. When an item you scheduled comes due, Surge sends the finished ad out to the platform you chose.

Whose credentials are used

This is the part to be precise about, because it determines who holds what.

When you schedule a post, Surge sends it to a platform using a social account you have already connected to ClipSpeedAI. Surge itself does not ask you for, run a login flow for, or separately store social platform credentials — those are held and revocable through your ClipSpeedAI connections.

Concretely: there is no Surge-specific credential store and no Surge OAuth screen. Access tokens live in ClipSpeedAI's shared connection layer, encrypted at rest, and are described in the ClipSpeedAI privacy policy. Surge reads that list at the moment of publishing to find which account to post through. If no account is connected for that platform, the post does not go out and the Calendar says so.

How to revoke it

Because the connection is ClipSpeedAI's, you revoke it there, and revoking it stops Surge publishing immediately:

You can also stop all Surge publishing account-wide at our end; ask support@clipspeed.ai and we will disable it.

What is transmitted, and to whom

What we store about a publish

On the Calendar item itself: the status (planned, posting, posted or failed), the number of attempts, the time it was claimed and posted, the platform's post identifier, and — if it failed — the reason, written where you will see it. A post is claimed before the network call so that two overlapping sweeps can never double-post to your audience, and a failure is retried at most three times.

Separately, at the moment a post goes out, we freeze a record of what was posted — the ad's identifier, the creative attributes behind it, the platform and the time. This is our own record of our own generator's output; it contains no audience data.

4.8 Delivery results and post metrics

Surge collects performance figures for the ads it published for you, and it is important to be exact about how narrow that is.

What we retrieve: for each ad Surge itself posted, we periodically ask our publishing transport for that post's view, like and comment counts and its public post URL, and we store those values together with the time we learned them. Nothing is retrieved for a post that Surge did not publish.

The numbers come from the platform, never from us, and we always store when we fetched them, so a zero can be read as either "genuinely zero" or "not synced yet" rather than presented as a confident measurement. These figures are stored in your own account record and are shown only to you.

4.9 Credits and billing

Payments are processed by Stripe. Card entry happens entirely on Stripe-hosted pages — Stripe Checkout and the Stripe Billing Portal. ClipSpeedAI never receives your card number, expiry, CVC or bank credentials, and we do not even store the last four digits.

What we store on our side is subscription state, in your Brand Profile row: plan, status, trial end date, current period end, your Stripe customer ID, your Stripe subscription ID, trial-consumed and past-due timestamps, whether you have cancelled at period end, and event timestamps.

What we send to Stripe: your email address, a description of the subscription, and your account's internal identifier so a payment can be matched to an account. We handle four Stripe webhook events — subscription created, updated, deleted, and checkout session completed — and persist only the identifiers, plan, status and timestamps above.

Credits are tracked as a ledger in your Brand Profile row: timestamp, signed amount, reason (for example ai_studio_generate), an optional reference string, an idempotency key and the resulting balance. The last 200 entries are retained. No IP address, device or location is recorded per spend. Note that the reference field is caller-supplied free text, so if you use the Surge API, do not place anything sensitive in it.

4.10 Email

Surge sends email through Resend. It sends two messages: a welcome email when you finish onboarding, and a receipt when a paid trial starts. Both contain your first name, your website's domain, and your plan details.

Delivery events — delivered, opened, clicked, bounced, complained — are recorded against a send log so we can tell whether our email actually arrives. Yes, that means our emails contain open and click tracking. Every message carries a working unsubscribe link and one-click unsubscribe headers; unsubscribing is recorded on your profile and suppresses future non-essential mail. A hard bounce or spam complaint also suppresses you automatically.

Non-essential email is suppressed between 22:00 and 08:00 US Eastern time. Billing receipts are not.

4.11 API keys

If you create a Surge API key, we store only a SHA-256 hash of it, plus a display hint showing the first and last few characters, a name you choose, creation time, last-used time, a request counter and a revocation timestamp. The key itself is shown to you exactly once and is unrecoverable afterwards, including by us. No IP address, user-agent or per-request log is retained against a key. Surge API keys are stored separately from ClipSpeedAI's own API keys and share nothing with them.

4.12 Demo Links (using Surge without an account)

A Demo Link lets a prospective customer try Surge with no signup. When you use one:

4.13 Server logs

Our hosting provider records standard application logs: request paths, status codes, timing, error traces, and operational lines about swipe and email events. Where a client IP address appears in ClipSpeedAI logging, it is stored as a salted SHA-256 hash rather than in the clear. Logs are retained for up to 30 days.

We also send ourselves operational alerts about subscription changes over Telegram. Those alerts contain internal identifiers — your account UUID and Stripe subscription and price IDs — and no name, email address or content.

4.14 What Surge does not collect

5. AI, model training, and what Surge learns from you

This is the question people ask first about any AI product, so it gets a direct answer rather than a defensive one. There are two separate questions hiding inside it — do you train models on my data, and does the product learn from what I do — and most policies collapse them into one sentence. They have different answers here, so they get separate sections.

1. We do not train AI models on your data. Not your website content, not your Brand Profile, not your uploaded media, not your prompts, not your generated Ads, and not your swipes — none of it becomes training data. We do not fine-tune models, we do not build datasets from customer content, and we do not license or sell your content to any AI provider for their training. There is no enterprise-only opt-out, because there is nothing to opt out of.

2. Surge does learn from your swipes, and that is the point of the product. Your keeps and skips change which ads you are shown next. That is arithmetic over your own decisions, not a model absorbing them — Section 5.3 says exactly how far it goes.

Claim 1 is a statement about training and only about training. It is not a claim that we ignore what you do in the product, and it should not be read as one.

5.1 What our AI providers actually do

Surge calls third-party AI providers to perform inference — one request in, one result out, no state kept on our behalf. We call only standard inference endpoints. We do not call any provider's fine-tuning, training-job, or dataset-upload endpoints.

ProviderUsed forWhat it receives
Anthropic or OpenAI
(whichever is configured)
Reading your website into a Brand Profile; writing ad copy, hooks and captionsThe extracted text of your site and the working prompt. No account identifier, no email address.
Replicate
(running FLUX Schnell)
Generating images in AI Studio and base images for AI CharactersPrompt text only — including any descriptors you typed for a character. No images, no account identifier, no email address. An uploaded photograph is never sent.

These providers' API terms state that data submitted through their APIs is not used to train their models. We rely on those terms, and we would change provider rather than accept a term that permits training on your content. Providers may retain a request briefly for abuse monitoring under their own published policies; we do not have a negotiated zero-retention agreement with them, and we would rather tell you that than imply one.

ClipSpeedAI's separate clipping product uses additional AI providers for transcription and speech. Those are described in the ClipSpeedAI privacy policy and are not used by Surge.

5.2 We do not build models either

ClipSpeedAI does not train, fine-tune or host a model of its own. There is no in-house model that could learn from you.

5.3 We do learn from your swipes — and that is the point

Surge learns from your swipes. That is the product, not a side effect. Every keep and every skip tells Surge which ads you would actually post, and Surge uses that to decide what to show you next. A tool that showed you the same deck no matter how you swiped would be a worse tool. Here is exactly how far it goes, in both directions.

What it does for you — personal to your account

Your swipes from the last 7 days are converted to a small numeric score per card type, weighted so recent swipes count more — the weighting halves every three days — and averaged. The result adjusts the mix of card types in your next deck: how many creator-style posts versus memes versus slideshows. The tilt is bounded and never removes a card type entirely, so a run of skips narrows what you see without cutting off a format for good.

Two limits worth stating explicitly:

What it does for the product — aggregate, and reviewed by a person

Across accounts, we compute yes-rates by format, vertical and emotion arc to learn which kinds of ads business owners will actually post. This is median-lift-by-slice arithmetic with a minimum-sample gate, so a handful of swipes can never overturn a well-evidenced pattern.

Nothing is applied automatically. The output is a report file that a person reads. Where new swipe evidence conflicts with what we already believed and the sample is small, the process is built to hold both and change nothing rather than pick a winner. Any change to how Surge generates ads is a human decision made after reading that report.

Only genuine customer swipes count

Since 24 August 2026, the aggregate learner reads only swipes that have been positively established as customer traffic. Swipes from our own internal and test accounts, swipes from Demo Links, and any swipe whose origin could not be established are all excluded by code — "unknown" never counts as a customer. The classification is written by our server when the swipe is recorded, after any values the browser supplied, so it cannot be spoofed from the client.

What your swipes are never used for

No automated decision is made about you that produces a legal or similarly significant effect. Surge decides which ad to show you next; it decides nothing about your eligibility for anything.

If you would rather Surge did not personalise from your swipes at all, you can object — see Section 14.1 — and we will switch it off for your account. You will still get ads; you will just get an unpersonalised mix.

To know what actually performs, Surge analyses a corpus of 4,404 public TikTok posts, harvested on 29 July 2026. If you are a creator whose post is in that corpus, this section is for you.

6.1 How it was collected

The corpus was assembled by loading public, logged-out TikTok pages — hashtag pages to discover posts, then each post's own public page. No login, no private content, no scraping of anything behind an access control, and no use of a TikTok API for user data.

6.2 What we hold about each post

FieldDetail
IdentityThe post ID, the post URL and the creator's public handle. No real name, no email address, no contact detail.
ContentThe caption, the on-screen text, the hashtag it was found under, language, duration, and — for roughly half the corpus — a text transcript of the speech in the video.
Public metricsPlay, like, comment, share and save counts as displayed publicly, the creator's follower count, and whether the account carries a verification badge.
ImageryFor a subset of posts, a single still cover frame, obtained through TikTok's own public oEmbed endpoint and re-hosted on our storage at cdn.clipspeed.ai/surge/trending/tiktok/. We re-host because TikTok's own image links expire.

We do not download the video. We do not download the audio. One still frame per post is the most we ever copy.

6.3 How it is used and displayed

The corpus is used to identify format patterns — which hooks, arcs and structures perform — which then inform the Ads Surge writes for you. It is a reference set, not source material: a third-party post is never re-published as your ad, and its footage is never used in your ad. Where a trending post is shown in the product, it is shown with the creator's handle and a link to their original post.

The corpus is not used to train any model, by us or by anyone else. It never leaves our systems and is never sold, licensed or shared.

6.4 Removal requests

If your post is in our corpus and you want it out, email privacy@clipspeed.ai with the post URL or your handle. We will remove every record of that post and delete any cached cover frame from our storage within 10 business days, and confirm to you when it is done. You do not need to give a reason, prove ownership beyond a plausible claim to the handle, or send a formal legal notice.

If you prefer a formal route, a copyright notice to the same address is also honoured under our Terms of Service. Deleting or making your post private on TikTok stops us fetching anything further from it, but does not by itself remove what we already hold — please email us.

7. Publishing, and what Surge still does not do

Surge publishes to five platforms — TikTok, Instagram, YouTube, X and LinkedIn — when you schedule an ad to go out. The mechanics are in Section 4.7. This section states the boundaries of that, because "it can post for me" and "it has the keys to my accounts" are very different things and the difference matters.

7.1 Surge publishes, but supplies and stores no social credentials

Surge runs no OAuth flow of its own and has no Surge-specific credential store. It publishes through Connected Accounts you have already linked to ClipSpeedAI. The access tokens sit in ClipSpeedAI's shared connection layer, encrypted at rest, shared with the clipping product, and covered by the ClipSpeedAI privacy policy. Disconnecting there stops Surge posting immediately — see Section 4.7 for the three ways to revoke.

Practically, that means Surge cannot obtain access to an account you have not already connected, and cannot retain access to one you have disconnected.

7.2 Publishing is not measuring

Surge does retrieve view, like and comment counts for the specific ads it posted for you, so the product can tell you what happened to what it sent out. That is the whole extent of it, and Section 4.8 lists what is excluded. Restated as flat negatives:

7.3 Still true, and unchanged

Publishing can be switched off entirely — there is an operational kill switch on our side, and you can ask support@clipspeed.ai to disable it for your account.

8. How we use your information, and on what legal basis

PurposeData involvedGDPR lawful basis
Generating ads for youBrand Profile, uploads, prompts, charactersPerformance of a contract
Running your account and LibraryAccount data, stored Ads and mediaPerformance of a contract
Publishing a scheduled adThe ad file and caption, and the Connected Account you chosePerformance of a contract, at your instruction
Reporting what happened to a published adView, like and comment counts for that postPerformance of a contract
Taking payment and managing subscriptionsEmail, Stripe identifiers, subscription statePerformance of a contract
Sending billing and service emailEmail address, name, planPerformance of a contract
Sending the onboarding welcome emailEmail address, name, website domainLegitimate interests, with unsubscribe available
Personalising your ad mix from your swipesYour own swipes, last 7 daysLegitimate interests — you may object, see 14.1
Improving formats across the productAggregated swipe outcomes, customer traffic onlyLegitimate interests
Preventing abuse, fraud and credit farmingAccount data, usage counters, hashed IPsLegitimate interests
Keeping tax and transaction recordsStripe recordsLegal obligation
Responding to legal processWhatever is lawfully compelledLegal obligation

Where we rely on legitimate interests, we have considered your interests and rights, and you can object at any time by emailing privacy@clipspeed.ai.

9. Who we share it with

We do not share your personal information with anyone except the service providers below, each acting on our instructions under their standard data-processing terms, plus the narrow legal cases that follow. Naming them is deliberate: a policy that says "trusted third-party partners" is telling you nothing.

SubprocessorPurposeData it receivesLocation
SupabasePostgres database and authenticationAccount data, Brand Profiles, swipes, credit and subscription recordsUnited States
RailwayApplication hosting and computeAll data in transit through the application; application logsUnited States
Cloudflare (R2 + CDN)Object storage and content deliveryUploaded media, generated images, character images, cached trending cover framesUnited States, delivered from a global edge network
StripePayments and subscription billingEmail address, account identifier, plan; card details entered directly with StripeUnited States
ResendTransactional email deliveryEmail address, name, website domain, message content, delivery and open eventsUnited States
Anthropic or OpenAIText analysis and ad copywritingExtracted website text and prompt text. No account identifier or email addressUnited States
ReplicateImage generationPrompt text only. No images, no account identifier, no email addressUnited States
Post for MePublishing transport for scheduled ads, and retrieving that post's countsThe ad file, its caption, the Connected Account identifier for the platform you chose; returns the delivery outcome and the post's view, like and comment countsUnited States
TelegramInternal operational alertsInternal account UUID and Stripe subscription and price IDs only — no name, email or contentGlobal

Social platforms are not subprocessors. When you schedule an ad, TikTok, Instagram, YouTube, X or LinkedIn receives your ad and caption at your instruction and handles it as an independent controller under its own privacy policy and terms — not on our behalf. We send only to the single platform you chose.

We will also disclose information in three other circumstances: legal process (a valid subpoena, court order or lawful request — we will resist requests that are overbroad and notify you unless legally prohibited); protecting rights and safety (investigating fraud, abuse or a threat to someone); and a business transfer (if ClipSpeedAI is acquired or merged, your information may transfer, and we will notify you by email with enough notice to delete your account first).

When we add or replace a subprocessor that handles personal information, we will update this table and note the change in Section 18.

10. No sale, no sharing, no ad profiling

Because we do not sell or share, there is no opt-out for you to exercise. We still honour Global Privacy Control signals as an opt-out request, and we would rather receive one and have nothing to do than argue about it.

11. How long we keep things

"For as long as reasonably necessary" is not a retention period. Here are ours.

DataRetention
Account record (email, name)While your account is open; deleted within 30 days of account deletion
Brand Profile and your edits to itUntil you overwrite it, or within 30 days of account deletion
Uploaded media in the LibraryUntil you delete the file, or within 30 days of account deletion
Generated Ads and AI Studio imagesUntil you delete them; generation history keeps the most recent 60 entries; otherwise within 30 days of account deletion
AI Characters, including any uploaded base imageUntil you delete the character, or within 30 days of account deletion
Calendar items, including publish status, attempts and failure reasonsUntil you delete the item, or within 30 days of account deletion
Record of what was posted (ad identifier, creative attributes, platform, time)Until account deletion. Contains no audience data
View, like and comment counts for ads Surge publishedUntil you delete the Calendar item, or within 30 days of account deletion
Credit ledgerMost recent 200 entries; deleted with the account
API keys (hashes)Until revoked or the account is deleted; a revoked key's hash is kept 90 days for abuse investigation
Swipes tied to an account24 months from the swipe, then deleted or irreversibly de-identified
Swipes from a Demo Link (no account)24 months from the swipe; the link itself expires in 14 days by default and 60 days at most
Demo scan resultsHeld in memory for about 15 minutes, never written to the database
Email send and delivery logs90 days
Unsubscribe and suppression recordsKept indefinitely — that is the only way to keep honouring your opt-out
Application and server logs30 days
Billing and tax records held by us and by Stripe7 years, as US tax law requires. These hold transaction records, not your content
Third-party trending corpusUntil superseded by a newer harvest, or removed on request within 10 business days (see Section 6.4)

Two honest caveats. First, files are delivered through a CDN with long cache lifetimes, so a copy of a deleted file may briefly remain in an edge cache after the original is removed; it is unreachable from the product and expires on its own. Second, encrypted backups roll on their own schedule, so deleted data can persist in a backup for up to 30 days before the backup itself expires. We do not restore deleted records from backup.

12. Deleting your data

You can delete at four levels, and each is real deletion rather than hiding.

  1. A single file or generation — from the Library or AI Studio. The record disappears immediately and the underlying file is removed from object storage.
  2. An AI Character — removes the character and its base image, including any photograph you uploaded.
  3. Your Brand Profile — rescanning replaces it. To clear it entirely, email us.
  4. Your whole account — email privacy@clipspeed.ai from your account address, or use account deletion in ClipSpeedAI settings. We purge your files from object storage before removing your account record, so nothing is left stranded, then delete your Brand Profile, Library, generations, characters, Calendar, post metrics, credit ledger and API keys within 30 days, and de-identify or delete your swipe history. Stripe transaction records are retained for the tax period described above and contain no content.

If you cannot delete something through the product, email us and we will do it within 30 days and tell you when it is done.

One thing we cannot delete: an ad that has already been published. Once Surge has posted an ad to TikTok, Instagram, YouTube, X or LinkedIn at your instruction, that post lives on that platform under your account. Deleting it from Surge removes our copy and our records; it does not remove the post. You take it down on the platform itself, and the platform's own retention policy governs what happens after that.

13. Security

We would rather describe controls that exist than list controls that sound impressive. Here is what is actually in place.

What we do not claim

We are not SOC 2 certified, not ISO 27001 certified, and have not commissioned a third-party penetration test. Tenant isolation is enforced in application code rather than by database row-level security. We do not hold negotiated zero-retention agreements with our AI providers. We would rather you know that than infer otherwise from a policy that stays silent.

Breach notification

If personal information is disclosed without authorisation, we will notify affected users by email within 72 hours of confirming the incident, describe what happened and what data was involved, and notify supervisory authorities where the law requires it.

Responsible disclosure

If you have found a vulnerability, email support@clipspeed.ai with "Security disclosure" in the subject line, and it will be routed to the founder. We will acknowledge within 5 business days. We will not pursue legal action against researchers who act in good faith, test only against their own accounts, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before publishing.

No system is perfectly secure, and we will not pretend otherwise. Use a strong, unique password, and tell us immediately if you think your account has been accessed by someone else.

14. Your privacy rights

14.1 Rights we give everyone, wherever you live

We do not gate privacy rights by geography. Every Surge user may:

14.2 How to exercise them

Email privacy@clipspeed.ai from the address on your account, or from any address if you tell us which account you mean. We verify identity by confirming control of the account email; for a sensitive request we may ask one additional question that only the account holder could answer. We do not require an ID document.

StageOur commitment
AcknowledgementWithin 10 business days
Substantive responseWithin 30 days (US state laws generally allow 45; we hold ourselves to 30)
ExtensionOnce, by up to 45 further days for a genuinely complex request, with reasons given in writing before the first deadline
CostFree, unless a request is manifestly unfounded or repetitive
AppealIf we refuse, we will tell you why and how to appeal. Email privacy@clipspeed.ai with "Appeal" in the subject; we respond within 45 days

You may use an authorised agent where the law allows, with written authorisation we can verify.

14.3 California (CCPA / CPRA)

California residents have the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation.

We do not sell or share personal information, so the opt-out right has nothing to act on. We do not collect sensitive personal information as the CPRA defines it — no government identifiers, no precise geolocation, no biometric identifiers, no account credentials for other services, no contents of your private communications — so the right to limit its use likewise has nothing to act on.

Categories collected in the last twelve months, in CCPA's own vocabulary: identifiers (email, name, account and Stripe IDs); commercial information (subscription and credit records); internet activity (usage and swipe records within Surge, and the view, like and comment counts of ads Surge published for you); professional information (your business, from the website you asked us to scan); inferences (your Brand Profile and your ad-format preference); and visual information (media you upload). Each is collected for the business purposes in Section 8, disclosed only to the subprocessors in Section 9 (plus the one social platform you instruct us to post to), and retained per Section 11. We collect no personal information from sources other than you, your website at your instruction, our own service, and the per-post counts a platform returns for an ad we published for you.

14.4 Florida

ClipSpeedAI is operated from Florida. The Florida Digital Bill of Rights applies to controllers above revenue thresholds we do not meet, so we are not currently a covered "controller" under it. We nevertheless extend its substantive rights — access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling — to Florida residents on the same terms as everyone else in Section 14.1. Being small is not a reason to give you fewer rights.

14.5 Virginia, Colorado, Connecticut, Utah and other US states

The same applies to the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with similar statutes: we may fall below their applicability thresholds, and we extend their core rights to you regardless. Colorado and Connecticut residents may appeal a refusal as described above and may contact their state Attorney General if unsatisfied.

14.6 European Economic Area, United Kingdom and Switzerland

If you are in the EEA, the UK or Switzerland, the GDPR or UK GDPR applies to our processing of your personal data. Our lawful bases are set out in the table in Section 8. In addition to the rights in 14.1 you may:

We are not established in the EEA or UK and have not appointed an Article 27 representative. Direct all data protection enquiries to privacy@clipspeed.ai.

15. International transfers

Surge is operated from the United States, and your information is stored and processed in the United States. If you use Surge from outside the US, your data will be transferred there.

For transfers of personal data from the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses as incorporated into our agreements with the subprocessors in Section 9, together with the UK International Data Transfer Addendum for UK transfers. We keep the data we transfer to the minimum each provider needs — notably, our AI providers receive prompt and website text without any account identifier or email address attached.

One transfer is directed by you rather than by us: when you schedule an ad, it is sent to the social platform you selected, which may process it anywhere it operates, under its own privacy policy. That transfer happens on your instruction and we cannot place safeguards on the platform's own handling of it.

You may request further detail about the safeguards applying to a specific transfer by emailing privacy@clipspeed.ai.

16. Children

Surge is for adults. You must be at least 18 years old to use it, consistent with our Terms of Service. Surge is a business advertising tool; it is not directed to children, we do not knowingly collect personal information from anyone under 18, and we run no service that would be attractive to a child.

If we learn that an account belongs to someone under 18, we will close it and delete the associated data. If you believe a child has given us information, email privacy@clipspeed.ai and we will delete it promptly.

Separately and importantly: never upload an image of a minor to Surge, and never create an AI Character intended to depict one. Our Terms prohibit it and we will terminate accounts that do it.

17. Cookies and local storage

Surge is unusually light here, so this appendix is short and complete rather than hedged.

CategoryWhat Surge usesPurposeLifetime
Strictly necessaryBrowser local storage entry holding your session tokenKeeps you signed in between page loads. Surge does not work without itUntil you sign out or clear browser storage
Strictly necessaryA browser-generated session identifier attached to swipe recordsGroups the swipes of one sitting so drop-off can be measuredThe current session
Strictly necessaryCloudflare security cookiesBot and abuse protection in front of our serversSet by Cloudflare, typically up to 30 days
Strictly necessaryStripe cookies, on Stripe's own checkout pagesFraud prevention during payment. Governed by Stripe's privacy policySet by Stripe
FunctionalLocal storage entries for interface preferencesRemembering your view and filter choicesUntil cleared
AnalyticsNoneSurge loads no product-analytics script, no session replay and no heatmap tool
AdvertisingNoneSurge loads no advertising pixel and no cross-site tracker

Two things to be precise about. Our Surge emails include open and click tracking, described in Section 4.10 — the unsubscribe link removes you from those messages entirely. And ClipSpeedAI's wider marketing website has consent-gated advertising and analytics tools of its own; if you reach Surge through one of those pages, the ClipSpeedAI privacy policy describes them and its consent banner controls them. Nothing loads on those pages before you accept.

Because Surge sets nothing that requires consent, there is no cookie banner on the Surge product itself. Your browser's Do Not Track and Global Privacy Control signals are respected by default, since there is nothing to switch off.

18. Changes to this policy

We will update this policy as Surge changes. When a change materially affects your rights or how we handle your data — a new subprocessor, a new category of data, a shorter retention period, a change to Section 5 — we will:

We will never make a retroactive change to how we treat data you have already given us without asking you first. In particular, if we ever wished to use customer data for model training — we do not intend to — that would require your affirmative, specific opt-in, not a policy update.

19. Contact

Privacy, data rights, removal requestsprivacy@clipspeed.ai
General supportsupport@clipspeed.ai
Security vulnerabilitiessupport@clipspeed.ai — put "Security disclosure" in the subject
PostalClipSpeedAI, Florida, United States — full address supplied on request to privacy@clipspeed.ai

A real person reads these. If something in this policy is unclear, or you think it is wrong about what we actually do, tell us — we would rather correct it than defend it.

This policy is written to comply with the California Consumer Privacy Act as amended by the CPRA, the Florida Digital Bill of Rights, the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah and comparable states, the EU General Data Protection Regulation and the UK GDPR. Where any provision conflicts with a law that applies to you, that law governs and the rest of this policy stands. Related documents: Surge Terms of Service · ClipSpeedAI Privacy Policy · ClipSpeedAI Terms of Service.