Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that user content, including personal information provided in inputs, file uploads, feedback, and outputs, may be used to train, fine-tune, and improve the AI models powering the services, subject to the terms applicable to the specific service tier.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision asserts a legitimate interests basis for using user-submitted content, including conversational inputs and file uploads, for model training purposes. The practical scope of this use depends on the terms applicable to the user's specific service tier, which may include enterprise or platform-specific agreements that modify or restrict this use.
Interpretive note: The provision states that model training use is conditional on 'the terms that apply to your use of the Services,' creating a dependency on service-tier-specific terms that are not reproduced in this policy.
Under this clause, user-submitted content including inputs, file uploads, and outputs may be processed for AI model training and fine-tuning. Users in the EEA and UK have the right to object to this processing by contacting privacy@cognition.ai, as the legal basis is stated as legitimate interests.
Cross-platform context
See how other platforms handle User Content for AI Model Training and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To customize your experience with our Services and otherwise improve our Services including, depending on the terms that apply to your use of the Services, using User Content to train, fine tune and improve the models that power our Services.Excerpt from Windsurf's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 6(1)(f) regarding legitimate interests as a legal basis for processing, and requires a documented legitimate interests assessment and balancing test for EEA and UK deployments. The UK GDPR imposes parallel requirements. The FTC Act is relevant to the extent that the use of consumer data for model training constitutes a material data practice requiring adequate disclosure. The provision may also engage emerging state AI governance frameworks depending on jurisdiction. 2. GOVERNANCE EXPOSURE: Medium-High. The use of user content for model training under a legitimate interests basis, without explicit consent, may face challenge under GDPR balancing test requirements, particularly where the content includes sensitive personal information or is submitted in professional or enterprise contexts. The policy conditions the scope of this use on the applicable service tier terms, creating a multi-document dependency that compliance teams should map. 3. JURISDICTION FLAGS: EEA and UK users have the statutory right to object to processing under legitimate interests, which could operationally limit model training data sources from those regions. California users may have rights under CCPA frameworks depending on applicability. Enterprise deployments in the EU face heightened exposure under GDPR given the breadth of user content categories involved. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should review the Data Processing Addendum and Platform or Enterprise Terms of Service to determine whether model training use of employee-generated content is excluded, restricted, or modified for their account tier. B2B procurement teams should confirm that the applicable service tier terms align with their organization's data governance obligations. 5. COMPLIANCE CONSIDERATIONS: Organizations should conduct a documented legitimate interests assessment if relying on this policy for EEA or UK data processing. Consent mechanism reviews should assess whether explicit opt-in or opt-out is operationally available for model training use. Data mapping should account for user content categories flowing into model training pipelines.
This provision asserts a legitimate interests basis for using user-submitted content, including conversational inputs and file uploads, for model training purposes. The practical scope of this use depends on the terms applicable to the user's specific service tier, which may include enterprise or platform-specific agreements that modify or restrict this use.
Under this clause, user-submitted content including inputs, file uploads, and outputs may be processed for AI model training and fine-tuning. Users in the EEA and UK have the right to object to this processing by contacting privacy@cognition.ai, as the legal basis is stated as legitimate interests.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.