serfin
See it workHow it worksSign inGet invited

Privacy

What Serfin collects now.

This notice covers Serfin’s public site, waitlist, invitations, sign-in, offer acceptance, Checkout, and the minimum case, payment, and refund records. Financial intake is separate and does not begin on the offer or payment-status pages.

Effective August 21, 2026

What Serfin collects now

When you request access, Serfin collects your email address and whether you chose the waitlist or invitation path. If you verify your email, Serfin also keeps the account, verification, session, waitlist, and invitation records needed to give you the right access.

Serfin keeps limited technical records needed to operate and secure the service, such as timestamps, an opaque request identifier, and neutral delivery or authentication outcomes. Those records are designed not to contain your email, sign-in link, authentication payload, or MFA material.

When an invited participant accepts the offer and starts Checkout, Serfin keeps the account ownership, invitation entry path, accepted offer version and fingerprint, acceptance time, fixed amount and currency, case history, payment and refund states, related timestamps, and opaque references needed to prevent duplicate processing. Serfin does not store card details, Checkout URLs, raw payment-provider responses or webhook bodies, or identity in payment-provider metadata.

How it is used

Serfin uses this information to verify that an email belongs to you, manage the waitlist and invitations, create and protect your session, deliver service messages, maintain the paid case and its history, prevent duplicate payments or refunds, process a requested refund, prevent misuse, and understand whether the access flow works.

Serfin does not sell personal information or use it to train automated systems. Joining the waitlist does not authorize access to financial accounts or the movement of money.

Who helps provide the service

Better Auth manages identity verification, secure sign-in links, and sessions. Resend delivers those Better Auth-generated emails and does not decide who is verified or invited. The application database keeps the authoritative access, invitation, case, payment-state, and refund-state records.

Stripe hosts Checkout and processes card information. Serfin receives signed payment and refund status events, but does not ask for or store card details in its application ledger. A return to Serfin after Checkout is informational; only a correctly signed event can establish payment or refund completion.

When analytics is enabled for a deployment, Serfin uses Amplitude analytics and Session Replay to collect allowlisted site-use events and make privacy-masked recordings of interactions across the site—such as clicks, scrolling, page navigation, device or browser information, and feature use. Serfin configures Amplitude remotely to mask page text and form entries and block email, sign-in, MFA, recovery-code, participant offer and case, and founder-administration areas. The application uses light masking if that remote configuration is unavailable. Serfin uses opaque identifiers. Masking reduces risk but cannot eliminate every implementation or configuration mistake.

On the beta site, Serfin also uses Vercel Web Analytics for aggregate page-view statistics on only the public landing, privacy, and terms pages. Serfin sends no custom events, form entries, query strings, or access, authentication, and founder page views through this integration. Vercel Web Analytics may process the page path, referrer, approximate location, browser, operating system, and device type. Vercel states that this service uses no cookies and resets its anonymous visitor hash after 24 hours.

How long information is kept

Serfin keeps acquisition, identity, waitlist, invitation, authentication, security-log, offer acceptance, case, payment-state, refund-state, processed-event, and masked analytics records while they remain useful. There is no automatic deletion schedule. Sign-in links, sessions, recovery codes, and recent-MFA checks still expire or become invalid according to their security rules.

When Session Replay is active, recordings use the longest retention included in the selected standard Amplitude plan. Serfin will not use paid retention add-ons, bookmarks, or exports to preserve recordings longer without making a separate decision.

Your choices

You can choose not to submit an email. Email support@serfin.app to ask a privacy question or request that Serfin review the information associated with your email. Do not email card details, passwords or other credentials, one-time codes, or financial account information. Before a founder-approved action is published for a paid case, you may also use that address to ask to stop and receive the full $50 refund described in the accepted offer. Broader deletion rules for later financial features will be decided before those features are used.

© 2026 Serfin

PrivacyTerms

Your money, working for you.