Windsurf · Windsurf Privacy Policy · View original document ↗

AI Model Training Using Prompts and Outputs

High severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Windsurf recorded 5 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Windsurf Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Windsurf states it may use the text you type into the tool as prompts, along with the AI-generated responses, to train and improve its AI models.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision states that content users enter into Windsurf, which may include proprietary code, sensitive queries, or personal information, can be retained and used to train the company's AI systems beyond the immediate session.

Consumer impact (what this means for users)

The policy authorizes collection and use of Prompts and Outputs Information for AI training purposes; users who enter sensitive, confidential, or proprietary content into Windsurf should be aware that this content may be retained and used for model development under the terms of this policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@windsurf.com to request deletion of your personal data, including Prompts and Outputs Information, and specify the data you want deleted.

How other platforms handle this

Strava Medium

We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal info...

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

See all platforms with this clause type →

Monitoring

Windsurf has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
To train, develop, and improve the artificial intelligence, machine learning, and models that we use to support our Services. We may use your Log and Usage Information and Prompts and Outputs Information for this purpose.

— Excerpt from Windsurf's Windsurf Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Articles 5, 6, and 13 for EEA and UK users, requiring a valid legal basis and transparent disclosure of processing purposes. The policy cites legitimate interests as a legal basis for product development and analytics; the use of personal data in AI training under legitimate interests may require a documented Legitimate Interests Assessment and may face scrutiny from data protection authorities including the UK ICO and EU supervisory authorities. For U.S. users, the FTC Act and applicable state comprehensive privacy laws (CCPA, CPRA, and similar statutes) may govern whether this use is consistent with disclosed purposes and whether adequate notice has been provided. GOVERNANCE EXPOSURE: High. The use of user-submitted Prompts and Outputs for AI training creates material compliance exposure because the policy does not disclose a specific opt-out mechanism for this use in the main policy body. Enterprise customers whose employees use Windsurf may be unaware that business-sensitive or proprietary code entered as prompts is subject to this use. Regulatory guidance from the UK ICO and EU data protection authorities on AI training data has increasingly focused on purpose limitation, data minimization, and consent requirements. JURISDICTION FLAGS: EEA and UK users face heightened exposure given GDPR purpose limitation and data minimization requirements. California residents may have rights under CPRA to limit the use of sensitive personal information, depending on whether prompt content qualifies. Enterprise customers in regulated industries such as healthcare, finance, or legal services may face additional restrictions on data submitted to AI tools under sector-specific regulations. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether a Data Processing Agreement is available that addresses the AI training use of Prompts and Outputs, and whether that use can be contractually restricted or disabled. The policy acknowledges that Windsurf may act as a data processor on behalf of enterprise customers, but the main policy does not contain a carve-out excluding enterprise-processed data from AI training uses, which may create a conflict between the processor role and the stated AI training purpose. COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether the legitimate interests basis for AI training is adequately documented and whether a Legitimate Interests Assessment has been conducted. Data mapping updates should reflect Prompts and Outputs as a category subject to AI training use. Organizations with confidentiality obligations should assess whether use of Windsurf is consistent with those obligations given this provision.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive trade practices related to privacy disclosures, including whether AI training uses are adequately disclosed to consumers.
    File a complaint →
  • State AG
    State attorneys general in California and other states with comprehensive privacy laws may have enforcement authority over AI training data uses and purpose limitation obligations.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Windsurf Privacy Policy
Entity
Windsurf
Document last updated
May 5, 2026
Tracking information
First tracked
April 30, 2026
Last verified
May 12, 2026
Record ID
CA-P-004016
Document ID
CA-D-00486
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
ca691298a1c366388f0a1f48ecc65849f0a7d07d6de5b840c646e62cf6239715
Analysis generated
April 30, 2026 05:21 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Privacy Policy
Record ID: CA-P-004016
Captured: 2026-04-30 05:21:09 UTC
SHA-256: ca691298a1c36638…
URL: https://conductatlas.com/platform/windsurf/windsurf-privacy-policy/ai-model-training-using-prompts-and-outputs/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Windsurf's AI Model Training Using Prompts and Outputs clause do?

This provision states that content users enter into Windsurf, which may include proprietary code, sensitive queries, or personal information, can be retained and used to train the company's AI systems beyond the immediate session.

How does this clause affect you?

The policy authorizes collection and use of Prompts and Outputs Information for AI training purposes; users who enter sensitive, confidential, or proprietary content into Windsurf should be aware that this content may be retained and used for model development under the terms of this policy.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.