Last updated 25 September 2026
SurgeLab ("we", "us") is an online tool for small businesses and agencies. It checks how AI assistants find and describe a business, helps put that right, and creates brand-consistent content that the business approves before anything is published. Customers sign up and use the tool themselves; agencies use it on behalf of the brands they manage. This policy explains what data we handle and why.
The company responsible for your data (the "data controller" under UK data protection law) is SurgeLab AI Ltd, company number 17297397, registered in England and Wales. Registered office: 81 Fernhead Road, First Floor, London, United Kingdom, W9 3EA.
For any privacy question, or to request deletion of your data, contact support@surgelab.co.
Account data. Email address, display name and authentication identifiers for everyone who logs in, including colleagues you invite.
Brand data. Business details, website content, uploaded photos and logos, product information, and tone-of-voice preferences supplied by you, or by an agency on your behalf, so we can check and generate content for your brand.
Connected platform data. Where you connect a third-party account (such as Google Business Profile or a scheduling tool), we receive the data that connection provides. This is described in more detail below.
Usage data. Records of content generated, scheduled, and published, plus the compute cost of each generation, so we can apply the limits of your plan.
Billing data. Payments are taken by Stripe on its own secure pages. We never see or store your card number. Stripe shares with us your name, email address, the plan you chose and the status of your subscription so we can switch features on and off. Stripe's own privacy policy applies to the payment itself.
Our free checks (for example "Can AI book you?", "Can AI read you?" and "Can AI find your products?") ask for a website address, and to show the full result they ask for an email address and, optionally, a phone number. We use these to show you the result, to send you one email about it, and to follow up about putting it right if you asked us to. We also keep a hashed (scrambled) form of your internet address alongside them, to stop the free check being abused.
We keep checker details for no longer than 12 months from the check, then delete them automatically. If you would like them gone sooner, email support@surgelab.co and we will remove them. If you go on to sign up, the same details become part of your account data instead.
When something goes wrong on a page or on our servers, we send a report to an error tracking service (Sentry, or the compatible GlitchTip) so we can fix it. The report holds the error message, the page or job it happened on, the brand it concerned where known, the browser type, and a short 8-character error id. That id is shown on the error message you see, so quoting it when you email us lets us find exactly what happened. Reports never include your password, card details or the content of your uploads.
With your permission, we use PostHog to understand which pages and features help. PostHog is hosted in the European Union (eu.i.posthog.com), and we only switch it on after you choose "Accept analytics" on the cookie banner. It records the pages you visit, what you click, and general details about your device and browser. It does not run at all if you choose "Essential only", and it honours your browser's Do Not Track setting.
We rely on: performance of a contract (running your account and the service you signed up for); our legitimate interests (keeping the service secure, fixing errors, following up a free check you asked for, and improving the product); consent (optional analytics cookies, which you can withdraw at any time); and legal obligation (keeping billing records for tax purposes).
Where a client connects their Google Business Profile, we request the business.manage scope. We use that access only to:
Limited Use. SurgeLab's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalised artificial intelligence models.
A client can disconnect at any time from within the platform, or by revoking access at myaccount.google.com/permissions. On disconnection we delete the stored access and refresh tokens.
We use third-party processors to run the service. Each receives only the data needed for its function:
Some of these providers are outside the United Kingdom, mainly in the United States. Where personal data goes to them we rely on the safeguards UK law allows: the provider's standard contractual clauses with the UK Addendum or the UK International Data Transfer Agreement, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it. PostHog is hosted in the European Union, which the UK recognises as providing adequate protection.
Content we send to AI providers is sent for the purpose of generating that client's content only. For Priya's Council, a customer's question and their brand's own stored facts are also sent to Google (Gemini) and xAI (Grok) for text generation, the same way they are already sent to Anthropic and OpenAI. We do not sell personal data to anyone.
We keep client brand data and generated content for as long as the client account is active, and delete it on request. Access tokens are stored encrypted at rest and are deleted when a connection is removed. Access to client data within the platform is restricted per project, and administrative data is restricted to SurgeLab staff.
If a free trial ends without a card being added, the account pauses and its data is kept for at least 60 days so you can pick up where you left off. You can ask us to delete it sooner at any time. Billing records are kept for as long as tax law requires, which is normally six years.
Under UK GDPR you have the right to ask for a copy of the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to take it elsewhere in a usable format, and to withdraw consent at any time where consent is what we rely on. Email support@surgelab.co and we will respond within 30 days.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you told us first so we can put it right.
Essential cookies and local storage. These keep you signed in, remember which brand you were last working on, your light or dark theme, and the cookie choice you made. They are needed for the service to work and do not need your permission.
Optional analytics cookies. PostHog sets its own cookies only after you choose "Accept analytics" on the banner. If you choose "Essential only", nothing from PostHog is set or loaded.
We do not run advertising or cross-site tracking cookies.
To change your mind, press Cookie settings below. That clears your choice and the banner asks again on this page. Choosing "Essential only" stops analytics straight away; any PostHog cookies already set expire on their own, or you can remove them in your browser settings.
The service is for business use and is not directed at anyone under 18.
If we make a material change to this policy we will update the effective date above and, where the change affects connected accounts, notify account holders by email.