SurgeLab

Privacy Policy

Last updated 25 September 2026

Who we are

SurgeLab ("we", "us") is an online tool for small businesses and agencies. It checks how AI assistants find and describe a business, helps put that right, and creates brand-consistent content that the business approves before anything is published. Customers sign up and use the tool themselves; agencies use it on behalf of the brands they manage. This policy explains what data we handle and why.

The company responsible for your data (the "data controller" under UK data protection law) is SurgeLab AI Ltd, company number 17297397, registered in England and Wales. Registered office: 81 Fernhead Road, First Floor, London, United Kingdom, W9 3EA.

For any privacy question, or to request deletion of your data, contact support@surgelab.co.

What we collect

Account data. Email address, display name and authentication identifiers for everyone who logs in, including colleagues you invite.

Brand data. Business details, website content, uploaded photos and logos, product information, and tone-of-voice preferences supplied by you, or by an agency on your behalf, so we can check and generate content for your brand.

Connected platform data. Where you connect a third-party account (such as Google Business Profile or a scheduling tool), we receive the data that connection provides. This is described in more detail below.

Usage data. Records of content generated, scheduled, and published, plus the compute cost of each generation, so we can apply the limits of your plan.

Billing data. Payments are taken by Stripe on its own secure pages. We never see or store your card number. Stripe shares with us your name, email address, the plan you chose and the status of your subscription so we can switch features on and off. Stripe's own privacy policy applies to the payment itself.

The free checkers

Our free checks (for example "Can AI book you?", "Can AI read you?" and "Can AI find your products?") ask for a website address, and to show the full result they ask for an email address and, optionally, a phone number. We use these to show you the result, to send you one email about it, and to follow up about putting it right if you asked us to. We also keep a hashed (scrambled) form of your internet address alongside them, to stop the free check being abused.

We keep checker details for no longer than 12 months from the check, then delete them automatically. If you would like them gone sooner, email support@surgelab.co and we will remove them. If you go on to sign up, the same details become part of your account data instead.

Error reporting

When something goes wrong on a page or on our servers, we send a report to an error tracking service (Sentry, or the compatible GlitchTip) so we can fix it. The report holds the error message, the page or job it happened on, the brand it concerned where known, the browser type, and a short 8-character error id. That id is shown on the error message you see, so quoting it when you email us lets us find exactly what happened. Reports never include your password, card details or the content of your uploads.

Product analytics

With your permission, we use PostHog to understand which pages and features help. PostHog is hosted in the European Union (eu.i.posthog.com), and we only switch it on after you choose "Accept analytics" on the cookie banner. It records the pages you visit, what you click, and general details about your device and browser. It does not run at all if you choose "Essential only", and it honours your browser's Do Not Track setting.

Why we are allowed to use your data

We rely on: performance of a contract (running your account and the service you signed up for); our legitimate interests (keeping the service secure, fixing errors, following up a free check you asked for, and improving the product); consent (optional analytics cookies, which you can withdraw at any time); and legal obligation (keeping billing records for tax purposes).

How we use Google user data

Where a client connects their Google Business Profile, we request the business.manage scope. We use that access only to:

  • read the business locations the account manages, so the client can pick one;
  • read reviews for that location, so the client can see and reply to them;
  • publish posts to that location when the client approves them.

Limited Use. SurgeLab's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalised artificial intelligence models.

A client can disconnect at any time from within the platform, or by revoking access at myaccount.google.com/permissions. On disconnection we delete the stored access and refresh tokens.

Service providers

We use third-party processors to run the service. Each receives only the data needed for its function:

  • Supabase (database, file storage and sign-in) and Vercel (hosting);
  • Anthropic (Claude), OpenAI, Google (Gemini) and xAI (Grok) for text generation: your brand's stored facts, website text and the questions we ask on your behalf;
  • Perplexity, one of the AI assistants we ask questions on your behalf: the questions, which can name your business, its area and what it sells;
  • FAL.ai (image and video generation), ElevenLabs (voice) and Shotstack (video assembly);
  • Firecrawl (reading your website and the pages we check);
  • DataForSEO (search and review data about your business name and area, and asking your tracked questions in the ChatGPT app);
  • Bright Data (asking your tracked questions in Microsoft Copilot): the questions, which can name your business, its area and what it sells;
  • Metricool (scheduling to social networks) and Google (Business Profile and Places);
  • Stripe (payments) and Resend (the emails we send you);
  • PostHog (analytics, only after consent) and Sentry or GlitchTip (error reports).

Some of these providers are outside the United Kingdom, mainly in the United States. Where personal data goes to them we rely on the safeguards UK law allows: the provider's standard contractual clauses with the UK Addendum or the UK International Data Transfer Agreement, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it. PostHog is hosted in the European Union, which the UK recognises as providing adequate protection.

Content we send to AI providers is sent for the purpose of generating that client's content only. For Priya's Council, a customer's question and their brand's own stored facts are also sent to Google (Gemini) and xAI (Grok) for text generation, the same way they are already sent to Anthropic and OpenAI. We do not sell personal data to anyone.

Retention and security

We keep client brand data and generated content for as long as the client account is active, and delete it on request. Access tokens are stored encrypted at rest and are deleted when a connection is removed. Access to client data within the platform is restricted per project, and administrative data is restricted to SurgeLab staff.

If a free trial ends without a card being added, the account pauses and its data is kept for at least 60 days so you can pick up where you left off. You can ask us to delete it sooner at any time. Billing records are kept for as long as tax law requires, which is normally six years.

Your rights

Under UK GDPR you have the right to ask for a copy of the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to take it elsewhere in a usable format, and to withdraw consent at any time where consent is what we rely on. Email support@surgelab.co and we will respond within 30 days.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you told us first so we can put it right.

Cookies

Essential cookies and local storage. These keep you signed in, remember which brand you were last working on, your light or dark theme, and the cookie choice you made. They are needed for the service to work and do not need your permission.

Optional analytics cookies. PostHog sets its own cookies only after you choose "Accept analytics" on the banner. If you choose "Essential only", nothing from PostHog is set or loaded.

We do not run advertising or cross-site tracking cookies.

To change your mind, press Cookie settings below. That clears your choice and the banner asks again on this page. Choosing "Essential only" stops analytics straight away; any PostHog cookies already set expire on their own, or you can remove them in your browser settings.

Children

The service is for business use and is not directed at anyone under 18.

Changes

If we make a material change to this policy we will update the effective date above and, where the change affects connected accounts, notify account holders by email.