Legal
Privacy
Surge has no accounts, no cookies, no analytics and no database.
What Surge's server sees
- The addresses and tickers you request, as part of ordinary HTTP logs and an in-memory per-IP rate limiter. Nothing is written to a database.
- Your IP address, for rate limiting only, kept in memory and evicted within minutes.
What Surge's server never sees
- Your wallet connection. Connecting happens entirely in your browser between the page and your wallet.
- Your private keys or seed phrase. Surge never asks for them and there is no place to enter them.
- Your signature on a login message. Surge has no login.
Third parties
- Robinhood's public API is called from Surge's server, not from your browser, so Robinhood sees Surge's server IP, not yours.
- Robinhood Chain RPC providers are called from Surge's server for cards and from your browser for wallet balances, approvals and transactions. Public RPCs may log the requester's IP.
- Token logos are loaded from Robinhood's CDN when a card or table displays them.
- If WalletConnect is enabled by the operator, WalletConnect's relay sees the connection metadata according to its own policy.
Browser storage
Your wallet library may remember the last connector in local storage so you don't have to reconnect. Surge itself keeps three small preferences in local storage: your light/dark choice, your motion choice and the last few tickers you opened (for the search box). Nothing else, and none of it leaves your browser.