Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that the services are not intended for children and that the minimum age for access is 18 years old, with a stated practice of not knowingly collecting personal information from children.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a minimum age of 18, which exceeds the COPPA threshold of 13 and the GDPR Article 8 digital consent ages applicable in most EU member states. The policy does not describe a technical age verification mechanism for enforcement of this restriction.
Under these terms, individuals under 18 are not authorized to access the services and should stop accessing them as stated in the policy's key highlights. The policy does not describe a process for handling personal information discovered to have been collected from a minor.
Cross-platform context
See how other platforms handle Children's Data Exclusion and Age Minimum and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"The Services are not intended for children, and we do not knowingly request or collect any personal information from children. As set out in our Terms, users must be at least 18 years old in order to access the Services.Excerpt from Windsurf's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages COPPA for US-based users under 13, though the policy's 18-year minimum extends beyond COPPA's threshold. GDPR Article 8 applies to the processing of children's data in the EU, with member-state-specific consent ages ranging from 13 to 16. The UK Age Appropriate Design Code imposes design and data minimization requirements for services likely to be accessed by minors under 18 in the UK, which may be relevant given the stated 18-year minimum. 2. GOVERNANCE EXPOSURE: Low to Medium. The policy states an 18-year minimum age but does not describe a technical or procedural age verification mechanism. Regulators including the FTC and EU supervisory authorities have scrutinized age assurance mechanisms for services asserting minimum age restrictions without verification. 3. JURISDICTION FLAGS: UK deployments may require assessment under the UK Age Appropriate Design Code given the 18-year minimum age claim. EU deployments should confirm that member-state-specific digital consent ages are addressed. California's AADC and similar state-level children's privacy laws may apply depending on the nature of the service and the likelihood of minor access. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers deploying the service in educational or consumer-facing contexts should assess whether the 18-year minimum age and the absence of a described verification mechanism create compliance exposure under applicable children's privacy laws in their jurisdiction. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the absence of a described age verification mechanism is adequate for the stated 18-year minimum under applicable law. A process for identifying and deleting personal information discovered to have been collected from a minor should be documented and operationally implemented.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a minimum age of 18, which exceeds the COPPA threshold of 13 and the GDPR Article 8 digital consent ages applicable in most EU member states. The policy does not describe a technical age verification mechanism for enforcement of this restriction.
Under these terms, individuals under 18 are not authorized to access the services and should stop accessing them as stated in the policy's key highlights. The policy does not describe a process for handling personal information discovered to have been collected from a minor.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.