Windsurf · Windsurf Security & Data Handling · View original document ↗

Model Use Independent of User Selection

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Windsurf recorded 4 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Windsurf Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The document discloses that OpenAI, Anthropic, and Google Cloud Vertex models may be used for background processing tasks such as summarization regardless of which model the user has selected for their primary AI interactions. Enterprise administrators can disable specific providers at the organizational level.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that user model selection does not fully constrain which inference providers receive code-derived data, as background tasks may route data to additional providers. Enterprise administrators have controls to disable specific providers, but individual users do not appear to have equivalent granular controls outside of zero-data retention mode.

Change history

modified Jun 2, 2026

Provision was renamed from 'AI Model Use Independent of User Selection' to 'Model Use Independent of User Selection' with identical content.

View full change record →

Consumer impact (what this means for users)

Under these terms, data including code context may be routed to OpenAI, Anthropic, and Google Cloud Vertex for background tasks such as summarization independent of the user's explicit model selection. Enterprise administrators can disable specific model providers for their organization, but individual user controls over this routing are not described beyond zero-data retention mode.

How other platforms handle this

Grubhub Medium

For campus users only, we may provide identifiers to select food service providers that operate restaurants and other food ordering and delivery services on your campus so that they can communicate directly with you and send you personalized communications and marketing. Please see Section 2.1 below...

YouTube Kids Medium

We will share individual user information with companies, organizations or individuals outside of Google if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to: meet any applicable law, regulation, legal process or enforceable govern...

MetaMask Medium

We may share your personal information with our affiliates, meaning entities that control, are controlled by, or are under common control with Consensys. We also share information with service providers who assist in operating our services, subject to confidentiality obligations.

See all platforms with this clause type →

Monitoring

Windsurf has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may leverage OpenAI models independent of user selection for processing other tasks (e.g. for summarization). We may leverage Anthropic models independent of user selection for processing other tasks (e.g. for summarization). We may leverage these models independent of user selection for processing other tasks (e.g. for summarization).

— Excerpt from Windsurf's Windsurf Security & Data Handling

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR purpose limitation principles, as data submitted for one purpose may be processed by additional third-party providers for background tasks. The FTC Act is relevant to the accuracy of disclosures regarding data routing practices. Enforcement authorities include national supervisory authorities under GDPR and the FTC for US consumer protection purposes. 2. GOVERNANCE EXPOSURE: Medium. The disclosure that model routing for background tasks may differ from user-selected model preferences creates a transparency consideration, particularly for organizations that have approved specific AI providers in their vendor management programs but not others. The zero-data retention agreements with OpenAI, Anthropic, and Google Vertex mitigate but do not eliminate the governance consideration. 3. JURISDICTION FLAGS: EU/EEA users may raise purpose limitation concerns under GDPR if data submitted for code assistance is processed by additional providers for summarization tasks without a clear legal basis. Organizations in regulated sectors that have approved specific AI vendors should assess whether this routing is consistent with their approved vendor lists. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should confirm that all providers that may receive code-derived data under this provision (OpenAI, Anthropic, Google Vertex) are included in their vendor assessment and approval processes. The ability for administrators to disable specific providers is a material control that should be documented in vendor management records. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should document which providers are enabled or disabled at the organizational level and ensure this aligns with their AI governance policies. For organizations with specific AI provider approval requirements, administrator-level controls over model provider selection should be reviewed and configured before deployment.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over data practices and disclosure accuracy relevant to consumer understanding of which third parties receive their data.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Windsurf Security & Data Handling
Entity
Windsurf
Document last updated
May 11, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-013136
Document ID
CA-D-00783
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
09f15224ef746c31f64489deed565c66e77ca519b3c55d45f54937824fef52f0
Analysis generated
May 21, 2026 05:27 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Security & Data Handling
Record ID: CA-P-013136
Captured: 2026-05-21 05:27:25 UTC
SHA-256: 09f15224ef746c31…
URL: https://conductatlas.com/platform/windsurf/windsurf-security-data-handling/model-use-independent-of-user-selection/
Accessed: June 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Windsurf's Model Use Independent of User Selection clause do?

This provision establishes that user model selection does not fully constrain which inference providers receive code-derived data, as background tasks may route data to additional providers. Enterprise administrators have controls to disable specific providers, but individual users do not appear to have equivalent granular controls outside of zero-data retention mode.

How does this clause affect you?

Under these terms, data including code context may be routed to OpenAI, Anthropic, and Google Cloud Vertex for background tasks such as summarization independent of the user's explicit model selection. Enterprise administrators can disable specific model providers for their organization, but individual user controls over this routing are not described beyond zero-data retention mode.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.