Back to sign in

privacy notice

Privacy Notice

Updated 30 May 2026

This notice explains how Surgifai, Inc. (“Surgifai,” “we,” “us”) handles personal data in the Surgifai customer application at app.surgifai.com. It does not cover the Surgifai marketing site or any data Surgifai processes on a customer's behalf under a separate data-processing agreement; that processing is governed by the Data Processing Agreement and the customer's order or business terms.

Surgifai is operated from the United States and is intended for use by businesses and professionals in the United States. The data controller is Surgifai, Inc., reachable at privacy@surgifai.com.

Scope of this notice

This notice covers personal data Surgifai collects and controls about the people who use our application. Where a customer organization submits data to the service and Surgifai processes that data on the organization's behalf, the organization is the controller and Surgifai acts as its service provider under the Data Processing Agreement.

Information we collect

Information you provide

Information collected automatically

Sensitive personal information

We do not collect personal information for the purpose of inferring characteristics, and we do not collect categories of sensitive personal information as defined under California law for any purpose beyond what is necessary to provide and secure the service. The IP address processed by our bot-protection and rate-limiting systems is used solely for security and abuse-prevention and is stored only in hashed form against abuse records. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit its use.

How we use this information

We do not use your Atlas queries or your content to train foundation models. The large-language-model service that powers the Atlas chat processes your query to produce a response and is not used to train models on your inputs.

Service providers we use

The Surgifai customer application runs on Cloudflare, which provides compute, database storage, transactional email delivery, bot protection, and the large-language-model service that powers the Atlas chat. Cloudflare processes data on Surgifai's behalf as a service provider; see the Cloudflare Privacy Policy.

Email delivery. Sign-in and verification email is sent from connect@surgifai.com; operational and no-reply email is sent from noreply@surgifai.com.

Atlas chat. When you submit a chat message, the text of the message and any results retrieved in response are processed by a large language model hosted by Cloudflare so that an answer can be generated. Your email address, account identifier, and firm identifier are not sent to the model.

Atlas backend. Surgifai operates its own backend on Cloudflare to fulfill Atlas queries. When you submit a query through the chat or through an authorized third-party client, the query text is sent to that backend. Authenticated requests carry a short-lived signed token identifying your firm, your user account, and your role within the firm. We do not attach your email address to Atlas queries.

How we share your data

We do not sell your personal data, and we do not share it with third parties for cross-context behavioral advertising. We share limited data only in the following cases:

Cookies and similar technologies

Surgifai uses only strictly-necessary cookies — no advertising, analytics, or cross-site tracking. The customer application sets a single session cookie to keep you signed in. The cookie is issued with the HttpOnly, Secure, and SameSite=Lax attributes and expires after 7 days; continued use of the service extends the session.

Data retention

Security

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your privacy rights

Surgifai serves users in the United States. Depending on your state of residence, you may have the right to:

To exercise any of these rights, contact us at privacy@surgifai.com. We will verify your request using the email address associated with your account and respond within 45 days, with one permitted extension where reasonably necessary. You may use an authorized agent to submit a request on your behalf, subject to verification.

California residents.The California Consumer Privacy Act, as amended, provides the rights described above. We do not sell or share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. In the preceding twelve months, we have collected the categories of personal information described in “Information we collect” and disclosed personal information only to the service providers and in the circumstances described in “How we share your data.”

Children's privacy

Surgifai is a business service intended for use by adults in professional contexts. We do not knowingly collect personal data from anyone under 16. If we learn we have done so, we will delete it.

Changes to this notice

We may update this notice as the service evolves. Material changes will be reflected by the “updated” date above. For substantive changes affecting how we use your data, we may also notify you by email.

Contact

Privacy questions and rights requests: privacy@surgifai.com.

© 2026 Surgifai, Inc. · Start with the question, not the portal.