10 Total
2 High severity
7 Medium severity
1 Low severity
Summary

This document establishes Windsurf's data collection and usage practices for users of its AI-powered coding tool, website, and IDE extension provided by Exafunction, Inc. The policy authorizes collection of user-submitted prompts and AI-generated outputs for purposes of training and improving Windsurf's AI models. For users accessing Windsurf through enterprise or work accounts, the policy permits account administrators and employers to access prompts, outputs, and account controls.

Technical / Legal Breakdown

This document is Windsurf's (Exafunction, Inc.) privacy policy, last updated October 21, 2025, governing the collection, use, and disclosure of Personal Information through the windsurf.com website, downloadable extensions, APIs, and associated software and services. The agreement states that Windsurf collects Registration Information, Communications Information, Log and Usage Information, Prompts and Outputs Information, voice command transcriptions, and information from third-party integrations; the terms authorize use of Log and Usage Information and Prompts and Outputs Information to train, develop, and improve AI and machine learning models, and permit disclosure to partners, affiliates, vendors, analytics providers, and enterprise account administrators who may access user Prompts and Outputs. The policy authorizes disclosure of any categories of Personal Information to current or future partners and affiliates for any purpose described in the policy, and enterprise account administrators are stated to have access to individual Prompts and Output Information, which is operationally distinct from policies that restrict employer access to derived or aggregated data only; the document also asserts that Standard Contractual Clauses govern EEA-to-US transfers, though the document does not specify which SCCs or the supervisory authority responsible. The policy engages GDPR and UK GDPR for EEA and UK residents, the California Consumer Privacy Act and California Privacy Rights Act for California residents (with a separate California Resident Privacy Notice referenced), and various other U.S. state comprehensive privacy laws; COPPA-adjacent age restriction provisions apply to users under 18. Compliance considerations include the use of AI training as a stated purpose for processing user Prompts and Outputs without a clear opt-out mechanism disclosed in the main policy text, enterprise data access provisions that may require evaluation under employment law and data processor agreement requirements in the EU and UK, and the absence of a specified retention schedule beyond a general necessity standard.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

2 important changes detected

4 versions captured · Last updated: June 2026

What changed Windsurf reordered the navigation links in their privacy policy footer on June 12, 2026. The 'Privacy Policy' link moved from its original position to appear after the 'Data Processing Addendum' link, and a new 'Report Vulnerability' link was added to the footer navigation. This is a formatting and organizational change with no impact on the substance, scope, or obligations described in the privacy policy itself.
Why this matters This change affects how users navigate to Windsurf's policy documents but does not alter the privacy practices, data handling, or rights described in the privacy policy itself. The Privacy Policy link remains accessible in the footer navigation, now positioned differently and alongside new links including a vulnerability reporting mechanism. No action by users is required.
View full change record →
What changed Windsurf removed the 'Windsurf' navigation link from the header menu in their privacy policy document on June 2, 2026. The updated privacy policy header now omits the redundant Windsurf link that previously appeared after 'Contact Devin'. This is a formatting change with no operational impact on the privacy terms themselves, their scope, or user protections.
Why this matters This change is a formatting update to the privacy policy document header and does not modify any privacy terms, data handling practices, or consumer protections. The substantive privacy policy language remains unchanged. No consumer action is required.
View full change record →

Recent Provision Changes Jun 12, 2026

10 provisions unchanged.

View full change record →
High — 2 provisions
Medium — 7 provisions
Low — 1 provision

Monitoring

Windsurf has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle AI Model Training Using Prompts and Outputs and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 12, 2026 00:50 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000486
Version ID CA-V-003729
SHA-256 63056dae4070a5e2d9a6a1aa6b668560eefeb4027991d3ef3a10cc0ad5d58845
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans