Privacy Policy
Last updated: 3 October 2026
SurfLogic ("we", "us") operates SimpleAgents — AI agents that work on your behalf, together with the client apps you install to connect your own devices to those agents: the SimpleAgents Browser Control Chrome/Edge extension, and the Excel and Autodesk Inventor add-ins. SurfLogic is a business name registered in Australia (ABN 45 492 997 202). This policy explains what we collect, why, and what we never do with it.
1. What we collect
Your account
- Your email address and display name — the account you sign in with (we sign you in by email; we never store a password for you).
- Your agents' configuration: names, instructions, enabled features and connections.
Your conversations
- The messages you send to your agents and the replies they give, so your chat history is there when you come back.
- Approvals you grant or decline for sensitive actions.
The page you attach (browser extension)
- When — and only when — you click Attach this tab, the extension reads that one tab: its URL and title, a text/accessibility snapshot of the page, and the content of the fields the agent needs to read or fill.
- That content is sent to your own agent so it can carry out the task you asked for. It is not sent to any other user, and it is not used to build an advertising profile.
- The extension never reads any tab you have not attached, never runs in the background on other pages, and never captures screenshots in the current version.
- Passwords are never auto-filled. The extension refuses to type into password fields at the page level; your agent asks you to enter those yourself.
The documents you attach (Excel and Inventor add-ins)
- Only the workbook or model data involved in the actions you ask the agent to perform on the item currently open in your add-in.
Action records
- An audit record of each action an agent performs through a client app: the action type, its parameters (for example the text asked for in a field), the result, and timestamps. This is what lets you and us see what an agent did, investigate problems, and detect abuse.
Technical data
- Device and session identifiers for the apps you connect. Connection tokens are stored hashed.
- Server logs (IP address, request time, errors) needed to run and secure the service.
2. How we use it
- To run your agents and carry out the tasks you ask for, in the tab or document you attach.
- To keep chat history and action records so you can review what happened.
- To operate, secure, debug and support the service, and to prevent abuse.
- To contact you about your account and service changes.
3. What we never do
- We do not sell your data or share it with data brokers.
- We do not use your data for advertising, and the apps contain no advertising or analytics SDKs.
- We do not use your data to determine creditworthiness or for lending purposes.
- We do not use your data for any purpose unrelated to what the service does for you, and we do not let our staff read your page content or conversations except where you ask us to for support, or where the law requires it.
- We do not read browser tabs you have not attached, and we do not auto-fill passwords.
4. Who we share it with
We use a small number of named service providers ("subprocessors") that process data only on our instructions:
- Nous Research — runs the AI model that does your agent's reasoning when the agent uses a connected Nous subscription. The conversation, the relevant page or document content, and your task instructions are sent to it so it can decide what to do next.
- Your agent's other model providers — if you configure an agent to use a different provider (for example OpenRouter, OpenAI or Anthropic, with your own key), the same content is sent to that provider instead, under your agreement with them.
- DigitalOcean — hosts the service and stores your data (database, profiles and logs) on our behalf.
- Mailjet — delivers sign-in emails and service notifications.
- Cloudflare (Turnstile) — bot protection on our sign-in form. It sees the request that carries your sign-in attempt, not your content.
We may also disclose data if the law requires it, or to protect the rights and safety of our users. We do not use any advertising or analytics providers, and we do not sell data to anyone.
5. Storage and retention
- While your account is active — your agents, conversations, page/document snapshots and action records are stored so the service can work and so you can review what your agents did.
- Sign-in links and codes — single-use, expire after 15 minutes, and the record is deleted within an hour.
- Connection tokens — stored only as a hash, rotated hourly, and revoked the moment you disable a connection.
- Server logs — kept for a short, size-bounded period for security and debugging, not indefinitely.
- When you ask us to delete your account — we remove your agents, conversations and action records from the live service. Anything still held in backups ages out within 30 days.
6. Your choices and rights
- Control what is connected. Client-app control is opt-in per agent and off by default, and you can detach a tab or disconnect an app at any time.
- Access and correction. Ask us for a copy of your data, or to correct it.
- Deletion. Ask us to delete your account and data.
- If you are in the EU/UK or Australia you have rights under the GDPR/UK GDPR or the Australian Privacy Principles, including the right to complain to your supervisory authority or the OAIC.
To exercise any of these, email support@surflogic.com.au.
7. Security
Traffic to the service and to connected apps uses HTTPS/WSS. Client-app connections use short-lived, device-scoped tokens that rotate and are stored hashed, and each connection is scoped to a single agent. Actions are recorded so unusual activity can be detected.
8. Changes to this policy
If we change this policy we will update the date at the top, and tell you in the app or by email if the change is significant.
9. Contact
SurfLogic (ABN 45 492 997 202) — support@surflogic.com.au