Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document states that while general customer data is retained for the duration of the customer relationship, Feedback Data and User Interaction Data are retained for an unspecified period determined solely by Cognition.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a carve-out for two categories of data (Feedback Data and User Interaction Data) from the general customer relationship-duration retention standard, with no defined maximum retention period. The retention duration for these categories is governed entirely by Cognition's internal determination.
The updated terms establish a default policy permitting Windsurf to use customer data for model training purposes to improve services. Previously, the company required explicit opt-in before any training use. Under the revised policy, data training occurs automatically for free and paid users unless they affirmatively opt out through the Data Controls settings page. Once disabled, the terms state your data will not be used for training and Zero Data Retention will be enabled with model providers. Enterprise customers operate under a different standard, requiring express prior written consent before any training use occurs.
View change record →The updated document establishes explicit commitments about how Windsurf protects data and manages security. The terms state that all data transmission is encrypted in transit and at rest, that access to production systems is restricted to a small number of employees or contractors based on business roles, and that production systems are monitored via logging, error handling, and monitoring dashboards. The document discloses that Windsurf obtained SOC 2 Type II certification as of March 2024 and that all employees and contractors are required to use multi-factor authentication and receive annual security training. These disclosures describe organizational practices rather than establishing new user-facing rights or obligations.
View change record →Under this clause, Feedback Data and User Interaction Data submitted through Devin may be retained beyond the customer relationship for an indefinite period at Cognition's discretion. The agreement does not define the categories of information constituting Feedback Data or User Interaction Data.
Cross-platform context
See how other platforms handle Feedback and User Interaction Data Retention and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Cognition only retains data processed through Devin for the duration of the relationship with a given Customer, unless otherwise specified by the Customers. Any Feedback Data and User Interaction Data are retained as long as needed and as determined by Cognition.Excerpt from Windsurf's Security & Data Handling
(1) REGULATORY LANDSCAPE: This provision engages GDPR data minimization and storage limitation principles, which require that personal data be retained no longer than necessary for the specified purpose. CCPA/CPRA also addresses data retention practices. The absence of a defined retention period and the delegation of duration determination to Cognition may require evaluation under applicable data protection frameworks. (2) GOVERNANCE EXPOSURE: Medium. The undefined retention period for Feedback and User Interaction Data creates a gap in data lifecycle governance that may complicate deletion requests, data subject access requests, and audit obligations under GDPR and CCPA. (3) JURISDICTION FLAGS: EU/EEA deployments face heightened exposure due to GDPR's storage limitation principle. California-based organizations should assess whether this retention practice satisfies CPRA's proportionality standards. Organizations in regulated industries (financial services, healthcare) may face additional sector-specific retention limitations. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should request clarification from Cognition on what data is classified as Feedback Data and User Interaction Data, and what internal policies govern the 'as needed' determination. Data Processing Agreements should address specific retention schedules for these categories. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should conduct a data mapping exercise to identify what data generated through Devin use falls into the Feedback Data and User Interaction Data categories. Organizations should assess whether existing data subject deletion procedures account for the possibility that these categories may be retained after the customer relationship ends.
This provision creates a carve-out for two categories of data (Feedback Data and User Interaction Data) from the general customer relationship-duration retention standard, with no defined maximum retention period. The retention duration for these categories is governed entirely by Cognition's internal determination.
Under this clause, Feedback Data and User Interaction Data submitted through Devin may be retained beyond the customer relationship for an indefinite period at Cognition's discretion. The agreement does not define the categories of information constituting Feedback Data or User Interaction Data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.