CA-C-002146
Windsurf — Windsurf Security & Data Handling
Entity
Date detected
May 16, 2026
Effective date
May 16, 2026
Severity
Low
Direction
Neutral
Affected users
all users users not on zero-data retention mode
Taxonomy
Vendor disclosure shift
Changes
+2 sentences added
Share 𝕏 Share in Share 🔒 PDF
Watch Windsurf Get alerts when this policy changes.
Watch — Free

Event Summary

Windsurf updated its Security & Data Handling policy on May 16, 2026 to disclose two practices involving data exposure. The policy now states that Windsurf uses Raindrop, a third-party service, to view usage analytics and aggregate statistics, and that users not using Zero-data retention mode may have their logs exposed for debugging purposes. Previously, this disclosure was not present in the policy.

LOW

Consumer Impact

The updated policy now explicitly states that Windsurf uses Raindrop to view usage analytics and aggregate statistics, and that debug logs may be exposed for users not on zero-data retention mode. Previously these practices were not disclosed in the policy. The policy establishes that Zero-data retention mode provides more restricted log access, while standard users operate under different log exposure terms. You can switch to Zero-data retention mode to limit debug log exposure.

Governance Analysis

The updated policy establishes explicit disclosure of third-party analytics tool usage and debug log exposure practices, which affects transparency regarding how user data is processed and accessed. Users operating without Zero-data retention mode should understand that their logs may be exposed for debugging purposes under the revised terms.

Available Actions

Review whether Zero-data retention mode is available and whether enabling it meets your data retention preferences.

If No Action Is Taken

Users not on zero-data retention mode will operate under the terms stated in the updated policy, which permits debug log exposure as described.

The disclosed practices will apply as written to all users who do not take steps to change their retention settings.

Key Clauses Affected

Raindrop analytics disclosure

Explicitly states that Raindrop is used for dashboards to view usage analytics and aggregate statistics.

Debug log exposure for non-zero-data-retention users

States that logs may be exposed for debugging purposes from users not using Zero-data retention mode.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Windsurf — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
889b76dd82a3b5b7ce09daf0ddaefc5a9a9d80f43db3e482201261e36da32c91
May 11, 2026 10:31 UTC
✓ Verified
Current Version
235c9ffbc1b2d16d6ae04f328a8bd634c97c83343d629ccfbabbbc4865adc2d3
May 16, 2026 00:48 UTC
✓ Verified
Change Detected
May 16, 2026 00:48 UTC
Analysis Methodology
✓ Verified
Source Document
https://windsurf.com/security
Citation Record
Entity: Windsurf
Document: Windsurf Security & Data Handling
Record ID: CA-C-002146
Captured: 2026-05-16 00:48:02 UTC
URL: https://conductatlas.com/change/2026-05-16-windsurf-windsurf-security-data-handling-2146/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Windsurf added explicit disclosure of third-party analytics tool usage (Raindrop) and debug log exposure practices. This represents a clarification of data handling practices rather than a substantive operational change. The disclosure may engage GDPR Articles 13-14 (transparency obligations) and CCPA disclosure requirements, depending on jurisdiction. Review whether existing privacy notices and vendor documentation accurately reflect these practices and whether user consent or notification protocols need update.

Regulatory Exposure

GDPR (Articles 13-14, transparency and lawful basis), CCPA (disclosure of data practices), state privacy laws (Virginia VCDPA, Colorado CPA, Utah UCPA), PIPEDA (where applicable)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002146.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Windsurf Security & Data Handling
Entity
Windsurf
Captured
May 16, 2026
Source URL
https://windsurf.com/security
Related Analysis
AI Governance · May 18, 2026
Three AI Governance Restructuring Patterns ConductAtlas Detected in May 2026

How Meta, TikTok, and Supabase restructured governance language across documents, jurisdictions, and consent frameworks through incremental…

AI Governance · May 12, 2026
AI Training Data Provisions Across Major Platforms: A Provision-Level Comparison

How 10 AI platforms describe the use of user data for model training, improvement, and development, based on archived governance provisions.

Track Windsurf policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.