Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that audio input collected through voice features is processed to generate transcriptions or commands, and that the underlying audio is deleted after transcription unless the applicable terms state otherwise.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a default deletion practice for raw audio data following transcription, while preserving the right to retain audio where stated in applicable terms. The transcription output is retained as user content and subject to the broader data practices described in the policy.
Interpretive note: The 'unless otherwise stated' qualifier creates a dependency on service-tier-specific terms that may modify the default audio deletion practice, and those terms are not reproduced in this document.
Under this clause, audio recordings from voice features are processed for transcription and then deleted by default, though this default may be modified by the applicable service terms. The transcription text is retained as user content and subject to all other data practices described in the policy, including potential model training use.
Cross-platform context
See how other platforms handle Voice Input Processing and Deletion and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Voice input: If you use voice features, we process the audio to generate transcriptions or commands. Audio is deleted after transcription unless otherwise stated.Excerpt from Windsurf's Privacy Policy
1. REGULATORY LANDSCAPE: Voice data collection implicates state biometric privacy laws in jurisdictions such as Illinois under BIPA, which applies to voiceprints and biometric identifiers. GDPR may treat voice recordings as personal data requiring a documented legal basis for processing. The FTC has addressed audio data collection practices under its consumer protection authority. State wiretapping and recording consent laws may also apply depending on the method of collection. 2. GOVERNANCE EXPOSURE: Medium. The policy's 'unless otherwise stated' qualifier on audio deletion creates a dependency on service-tier-specific terms that may modify the default deletion practice. The scope of retained transcription data and its eligibility for model training use under the training provision creates a compounding data practice. 3. JURISDICTION FLAGS: Illinois BIPA creates heightened exposure for voice data collected from Illinois residents, as voiceprints may qualify as biometric identifiers requiring written consent and a retention policy. California CCPA frameworks require disclosure of audio data collection as a sensitive data category. EU deployments may require specific legal basis documentation for voice processing. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers deploying voice features should assess whether Illinois BIPA or other biometric privacy laws create written consent, retention schedule, or destruction policy obligations. Vendor agreements with Cognition AI should address the scope of audio retention and the conditions under which the 'unless otherwise stated' exception applies. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether voice data collection requires state-specific consent notices in Illinois and other biometric privacy jurisdictions. Data mapping should account for the audio-to-transcription pipeline and the retention status of both audio and transcription data. Service tier terms should be reviewed to identify any exceptions to the default audio deletion practice.
This provision establishes a default deletion practice for raw audio data following transcription, while preserving the right to retain audio where stated in applicable terms. The transcription output is retained as user content and subject to the broader data practices described in the policy.
Under this clause, audio recordings from voice features are processed for transcription and then deleted by default, though this default may be modified by the applicable service terms. The transcription text is retained as user content and subject to all other data practices described in the policy, including potential model training use.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.