GDPR Compliant

Privacy Policy

We're committed to protecting your privacy and being transparent about how we handle your data.

Effective date: 21 September 2025

Privacy at a Glance

The key points about how we protect your data.

Your Data is Secure

We use enterprise-grade encryption and never sell your personal information.

You Stay in Control

Export or delete your data anytime. Your quotes and notes belong to you.

Transparent Communication

We only send essential emails and will ask before adding you to marketing lists.

1. Who we are

Resurface ("we", "us", "our") provides an AI-powered service to capture, manage, and resurface quotes from physical books. We are a controller of your personal data when you use our site and app.

2. Personal data we process

We collect and process the following types of data:

  • Account data: name, email, profile image

  • Content data: quotes, notes, tags, book and author metadata, images you upload

  • Usage data: device information, approximate location (from IP), and analytics events

3. How and why we use your data (lawful bases)

We process your data for the following purposes:

  • To provide the service and features you request (contract)

  • To improve performance, safety, and reliability (legitimate interests)

  • To send essential service emails (contract) and optional updates (consent/opt-in)

4. Sharing

We share data with processors who help us run the service (e.g., hosting, analytics, email). We require strict confidentiality and security measures. We do not sell personal data.

5. International transfers

Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

6. Data retention

We retain personal data for as long as your account is active and as required to provide the service. You may request deletion at any time from your account settings.

7. Your rights

Under GDPR, you have the following rights:

  • Access, rectification, erasure, and portability

  • Restriction and objection to processing where applicable

  • Withdraw consent where processing relies on consent

  • Lodge a complaint with your local supervisory authority

8. Security

We use technical and organizational measures to protect your data, including encryption in transit, access controls, and regular reviews of our security practices.

9. Children

Our service is not intended for children under 16. We do not knowingly collect personal data from children under 16.

10. Contact

For privacy requests, contact us at privacy@getresurface.com. We will respond within one month.

11. Changes

We may update this policy to reflect changes to our practices or for legal reasons. We will notify you of material changes via the app or email.

Questions about your privacy?

We're here to help. Contact our privacy team for any questions or requests.