Summary: Surf has no account, no first-party analytics and no advertising, and MW Supply Limited runs no servers that receive your data. Your cookies and anything you type into websites stay on your device and never sync. A sign-in you ask Surf to remember is kept in your device's keychain; you can switch on iCloud Keychain sync for those, which hands them to Apple to carry to your other devices under your own Apple Account, where we cannot see them either. It is off unless you turn it on. With Surf Pro, your bookmarks, history, reading list and open tabs are kept in step across your devices through your own iCloud account, which we cannot see; on the free plan they stay on your device. Private tabs keep no history and use an in-memory session that is cleared when you close them. Your file library stays on your device, or in your own iCloud account if you leave iCloud sync on. Nothing is tracked, so Surf never asks for App Tracking Transparency permission.
Surf has no account system, no login to us, and no first-party analytics, and MW Supply Limited operates no servers that receive your data. Your browsing data is stored locally in the app's own storage on your device. It is never uploaded to us. The one exception is described in section 4: with a Surf Pro subscription and iCloud sync left on, some of it is also kept in your own iCloud account so it is the same on your other devices — still not on any server of ours. There is no advertising and no third-party analytics, so no data about you is processed off your device by us or on our behalf. If you switch on the optional Claude integration on a Mac, page content leaves your device to an assistant you have chosen — not to us, and not on our behalf; this is described in full in section 7.
Surf is built on Apple's WebKit. The pages you visit, your tabs, bookmarks, history, Top Sites, cookies, cache, and anything you type — including usernames and passwords you enter to log in to a website — are handled by WebKit and stored only in the app's own storage on your device. This is used solely to load the pages you ask for and to remember your bookmarks, history, and Top Sites for you. It is never sent to MW Supply Limited, and we cannot see your browsing or your logins. Cookies, cached pages and anything you type into a website are never synced anywhere, on any plan. The one exception is a sign-in you explicitly ask Surf to remember, and only if you switch its sync on — see below. You can clear it at any time in the app's Settings using Clear Data, which wipes your history, cookies, and cache.
Saved sign-ins. Surf can offer to remember a username and password you type into a website, so you do not have to type it again. It always asks first, one site at a time, and you can answer “never for this site”. What you agree to save is stored in your device's keychain, available only while the device is unlocked. By default it stays on the device you saved it on. In Settings you can switch on Sync with iCloud Keychain, which marks your saved sign-ins for Apple's iCloud Keychain — the same store Safari uses for its passwords — so they reach your other devices under your own Apple Account. Whether they actually travel is up to your Apple Account settings; Surf cannot see whether iCloud Keychain is switched on, and does not claim to. Either way they are never sent to MW Supply Limited: we run no server that could receive them, and we have no way to read them. Surf only offers this on secure (https) sites, and only fills a password back into the same site it was saved for. It never saves or fills anything in a private tab, and never in a tab a Claude session is working with (see section 7). Everything saved is listed in Settings, where you can look at one behind Face ID, Touch ID or your device passcode, remove it, or remove all of them. From Surf 1.12 for Mac and 1.9 for iPhone and iPad you can also copy a saved username or password, and add or edit an entry by hand. Copying a password is the one action here that can put it outside Surf. On iPhone and iPad, Surf marks the copy as local to that device and asks the system to discard it after a minute. macOS offers no equivalent: a password copied on a Mac goes to the ordinary system clipboard, which macOS shares with your other Apple devices through Universal Clipboard if you have Handoff switched on. Treat a copy on a Mac as leaving the machine. Surf marks the clipboard entry so that clipboard managers which honour that marking keep it out of their history, but that is a convention rather than a guarantee, and nothing about it sends anything to us. Removing one deletes it here — and, if you have that sync switched on, from your other devices as they catch up. We hold no copy to delete.
Staying signed in. Websites keep you signed in with cookies, and some of those are “session” cookies a browser would normally discard when you quit. Surf can hold on to those so that quitting the app does not sign you out of everything, as Safari and Chrome also do. They are kept in your device's keychain marked this device only: unlike a saved sign-in, a session cookie is never synced, never backed up and never sent to us, and no setting changes that. Private tabs are never included. You can turn this off in Settings, and Clear Browsing Data erases it.
Private tabs. When you open a private tab, Surf keeps no history of it and holds its cookies and site data only in memory — nothing from a private tab is written to your device's long-term storage. Links you follow from a private tab stay private, and when you close your private tabs that in-memory session is cleared. Private tabs are never included in the iCloud sync described in section 4. Private browsing keeps this activity off your device; it does not make you anonymous to the websites you visit, your network, or your internet provider.
Surf offers an optional on-device content blocker that removes many ads and known trackers from the web pages you load. This runs entirely on your device using rule lists bundled with the app; it does not report the sites you visit to us or to anyone else. Surf itself shows no advertising — see section 6.
Surf includes a file manager. Files you save or import are stored in the app's own library on your device, and their names, folders, tags, and playback positions are kept in the app's own storage. MW Supply Limited never receives any of it — we operate no servers and there is nothing for us to receive it with.
iCloud sync is on by default so your library is the same on your iPhone, iPad, and Mac. When it is on, your files are stored in your own iCloud account, under Apple's terms and your Apple Account settings — not on any server of ours, and we cannot see them. You can turn it off at any time in the app's Settings, which moves your library back onto the device; turning it on moves it into iCloud. On a Mac the library also appears in Finder under iCloud Drive.
Browser data sync (Surf Pro). With an active Surf Pro subscription, and only while iCloud sync is left on, Surf also keeps your bookmarks and bookmark folders, browsing history, reading list (including the article text saved for offline reading), per-site preferences, and the list of tabs open on each device in your own iCloud account, so they are the same on your iPhone, iPad and Mac. The tab list is the last one each device published rather than a live view: on a Mac set to open on a new tab, closing the window does not withdraw the tabs it had, so another device may go on listing them until that Mac opens something again. This is stored under Apple's terms and your Apple Account settings; it is not sent to any server of ours and we cannot see it. Turning iCloud sync off in Settings stops it and moves that data back to the device. If a subscription lapses, nothing is deleted — the device simply stops sending changes. Private tabs, cookies, cached pages and anything you type into a website are never included. Saved sign-ins do not travel this way either; if they sync at all it is through Apple's iCloud Keychain, described in section 2.
The Private area. Files you move into the Private area are hidden behind Face ID, Touch ID, or your device passcode, and they are moved out of the part of the container that other apps and the Files app can browse. To be precise about what this is: it is access gating plus your device's own file protection — Surf does not apply its own additional encryption, and the files still sync if iCloud sync is on. It is not a substitute for a dedicated encrypted vault.
Surf Pro is sold through Apple's In-App Purchase using StoreKit, either as an auto-renewable subscription or as a one-time purchase. Your purchase, payment, and renewals are handled entirely by Apple under your Apple Account; MW Supply Limited never sees your name, your Apple ID, or your card or payment details. Subscriptions can be managed or cancelled any time in your Apple Account settings.
Surf shows no advertising, on any tier. No ads are served to free users or to Surf Pro subscribers, no advertising SDK is started, and no advertising or tracking data is collected, processed, or transmitted — not by MW Supply Limited, and not by any third party.
Because nothing is tracked, Surf does not ask for Apple's App Tracking Transparency permission.
If advertising is ever introduced, this policy will be updated to describe exactly what would be processed before any such feature ships, and the App Store privacy label will be updated with it.
On a Mac, Surf can let Claude — Anthropic's assistant, running in software you have installed and signed in to yourself — read and act on a web page for you. It is part of Surf Pro, it is off until you switch it on, and it does nothing at all before you do. It is not available on iPhone or iPad.
The switch is remembered, from Surf 1.12 for Mac. If you leave it on, it is on again the next time you open Surf, and it stays that way through updates until you turn it off — in Settings › Claude, in … › Add-Ons, or from the Automation › Stop Automation menu, which is always there while it is running. In Surf 1.11 and earlier it was off at every launch and had to be switched on each time. Nothing is remembered until you turn it on yourself; a fresh install, and an install updating from 1.11, both start off.
How it is connected. A small separate program, the Surf Connector, is downloaded and installed by you and runs on your Mac only while your Claude software is running. Surf talks to it over your machine's loopback interface — traffic that never reaches a network. Nothing about Surf is reachable from another machine, and with that program not running there is no connection at all. MW Supply Limited receives nothing from any of this and operates no server involved in it.
What Surf can hand over, while it is switched on. For a page in a tab the session is working with: its address and title, the visible text, a description of the elements on it — links and where they point, buttons, and form fields including anything already typed into an ordinary one (an address, a name, a message you were part-way through) — a picture of the page, and the messages and network requests that page produced while you were on it. It can also scroll the page, go back and forward, open and close its own tabs, and resize the Surf window. Surf hands this to the connector on your Mac only when your assistant asks for it.
What happens next is not ours, and we want to be exact about it. Your assistant will send what it receives to its own provider to be processed, under that provider's terms and privacy policy and under your account with them — not ours. Surf can neither see that nor limit it. Read your assistant's own policy before switching this on. It is the reason this feature is off until you ask for it, is Surf Pro only, and can be stopped from the menu bar at any moment.
What Surf refuses, in its own code, whatever it is asked. Private tabs are never exposed — not their content, not their addresses, and not their existence: they are left out even of the count of tabs an assistant is told it cannot see. Password fields are never filled, and Surf also refuses any field it recognises as a payment card, security code or one-time code. What you have typed into one is never read either: it is left out of what an assistant is told, and Surf hides it for the moment a picture of the page is taken, so it is not in that either. Recognition beyond a password field relies on how the site marks it up, so treat it as a strong safeguard rather than a guarantee. A session can only see and act on tabs it opened itself, or a tab you have explicitly handed to it, and it cannot switch itself on, create a private tab, or reach the tabs of another session.
Whose browser it is working in, which we want to be equally exact about. Those limits are about tabs. Behind them, a tab a Claude session opens is an ordinary tab in your ordinary browsing session, using the same cookies as the rest of Surf — there is no separate, signed-out browser hiding behind this feature, and none is claimed. So a site you are signed into is a site the session is signed into: it can reach your account pages there, read what is on them, and act as you. It runs the other way too — a sign-in or a sign-out a session performs, or persuades a site to perform, is one your own browsing keeps afterwards, not one that disappears when the session stops. Private tabs are the exception on both counts, as above: they hold their cookies only in memory, and they are never exposed to a session at all. None of this sends anything to MW Supply Limited — we still receive nothing — but what a signed-in page shows is page content, and page content is what goes to your assistant's provider as described above. It is part of why the feature is off until you switch it on, why it is confined to tabs the session opened or you handed over, and why Automation › Stop Automation stays in the menu bar the whole time it is running.
A limit worth stating plainly. Any program running on your Mac as you can present itself to Surf as an assistant session. No secret would change that — a program running as you could read it. This is why the feature does nothing until you switch it on, why every connected session is listed by name in the app's Add-Ons panel, with a pill in the toolbar and a tinted border on any page being acted on whenever a Surf window is open, and why the refusals above are enforced by Surf rather than requested politely. Those on-screen signals need a window to appear in: Surf keeps running with its window closed so that downloads finish, and a session connected at that moment is not drawing anything anywhere. Automation › Stop Automation stays in the menu bar the whole time, which is why the menu-bar switch rather than the on-screen signal is the one to rely on. It is also why a remembered switch is one you can always revoke from the menu bar, without opening a settings pane to do it. And it is why a web page's own text can attempt to influence an assistant that is reading it; Surf is not immune to that, and no browser is.
The App Store privacy label is unaffected. Surf still collects no data. The connector is not part of the app, we receive nothing from it, and your assistant's provider is not processing anything on our behalf.
Surf is a general-purpose web browser and is not affiliated with, endorsed by, or sponsored by any website you visit. The websites you load have their own privacy practices and terms, which are outside our control. You are responsible for complying with the terms of service of the sites you visit and with applicable law.
Surf does not collect or transmit your browsing history, bookmarks, tabs, Top Sites, or search terms to us; it has no account and asks for no personal information; and it performs no first-party analytics or crash tracking. The app requests no access to your photos, contacts, camera, microphone, or location. No data of any kind is sent to MW Supply Limited. The only things that leave your device are the web requests you make yourself by loading a page; — if you leave iCloud sync on — your own files, and (with Surf Pro) the browser data listed in section 4, syncing to your own iCloud account, which we cannot see; — if you switch on iCloud Keychain sync for saved sign-ins — those sign-ins, going to your own iCloud Keychain and no further; and — if you switch on the Mac Claude integration — the page content described in section 7, going to the assistant you chose and its provider; and — if you copy a saved password on a Mac (Surf 1.12 and later) — that password, going to the system clipboard and, through Universal Clipboard, to your other Apple devices. On iPhone and iPad a copied password is marked local to the device instead. None of it comes to us.
Surf is not directed to children under 13 and is age-rated accordingly in the App Store, because it provides unrestricted access to the web. The app shows no advertising and collects no personal data, consistent with the Children's Online Privacy Protection Act (COPPA) and similar regulations worldwide.
If we change how Surf handles data, we will update this page and the “Last updated” date above. Material changes will also be reflected in the App Store privacy labels for the affected version of the app.
Questions about this privacy policy can be sent to mwsupplylimited@gmail.com.