Privacy
last updated 27 July 2026
The short version: surfing needs no account and leaves no trail we keep. If you sign in, we hold your email address and the sites you saved. That is the whole list.
Who holds it
Socialbug Apps LLC, a limited liability company registered in Wyoming, United States, with its registered business address at 30 N Gould St, Ste 56488, Sheridan, WY 82801, USA. Questions, requests and complaints: [email protected]. We answer in writing, which is also how a request under any of the laws below is best made and best answered.
If you never sign in
We count page views on our own server: the path, the day, and the host part of the referring site if there is one. Nothing is sent to anyone else — there is no third-party analytics script, embedded font, tracking pixel, or advertising network on any page.
We also count how many people came, rather than only how many pages were served. To do that without a cookie, your address and browser are turned into a one-way mark, mixed with a secret and with today's date. The mark cannot be turned back into you, and because the date is part of it, today's cannot be matched to yesterday's — so we can say how many people visited on a day and never that it was the same person twice. The marks are deleted after two days; the counts they produce contain nothing about anybody.
Alongside that we record two coarse things once per person per day: whether the page was read on a phone, tablet or desktop, and which country the request came from, which Cloudflare works out so that we never have to look at an address ourselves.
A small script served by oddsurf counts active seconds only while an oddsurf page is visible, focused, has been used in the last thirty seconds, and is not showing an embedded destination. It sends a bounded total and session-start signal to our own server. The request uses the same first-party session and anti-forgery protection as the rest of the page, and the network address is visible while the request is handled. Neither is copied into the engagement data: only daily seconds and session counts are retained. We cannot see how long you spend on a destination.
If you tell us a site was worth the tap, or was not, that opinion is kept the same way: the same one-way daily mark, so it counts once a day per site and cannot be traced to you or followed between days. Nothing about it is shown to anybody — it only steers which sites the surf button keeps handing out.
Two cookies exist. One keeps your session if you sign in; one remembers which theme you chose. Neither follows you anywhere, and neither is used for advertising or measurement, which is why this site does not interrupt you with a consent banner.
If you sign in
We ask for an email address and nothing else — no name, no password. We store the address, the date you arrived, the sites you saved, and short-lived sign-in links (only as hashes, so the table is not a set of working keys).
The legal basis is the contract you enter by asking for an account: we cannot keep your saved list without knowing whose it is. For the sign-in email itself, the basis is the same — it is the mechanism you asked for, not marketing.
We do not keep a history of where you surf. The surf button remembers the last few destinations in your own browser so it does not repeat itself; that list never reaches us.
How long
Your account lasts until you delete it. Deleting hides it immediately and erases it for good after 30 days; signing in again inside that window brings it back. Sign-in links expire in 15 minutes. Page-view and active-time counts are totals per day with nothing in them that points at a person, so they are simply kept.
Who else sees anything
These are the only companies involved, and what each one does:
- DigitalOcean — Servers and databases (United States)
- Cloudflare — Network in front of the site (United States)
- Postal (self-hosted) — Sends the sign-in emails (United States)
- DeepSeek — Reads crawled pages to judge them (Singapore)
- Google Web Risk — Checks catalogued sites for malware (United States)
The model that reads crawled pages sees those pages, never anything about you. We do not sell or share personal information, and we never have — including under the meanings California gives those words. There is nothing to opt out of, because there is no such flow to switch off.
What you can do
From your account page you can download everything we hold on you as a file, and delete the account outright. Those cover access, portability and erasure without asking anyone. For correction, objection, or anything else — including under GDPR or the CCPA — write to [email protected] and we will answer within a month. You may also complain to your data protection authority.
We do not send marketing email. If that ever changes it will be a separate, unticked choice on your account page, and it will never be attached to a sign-in email.
Children
oddsurf is not aimed at children under 13, and we do not knowingly hold their data. The catalogue is filtered for safety but points at the open web, which we do not control.
Changes
If this notice changes in a way that matters, the date at the top changes with it and anyone with an account is told by email before it takes effect.