Windsurf · Windsurf Security & Data Handling · View original document ↗

Subprocessor Code Data Access Disclosure

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Windsurf recorded 4 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Windsurf Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The document provides a comprehensive list of subprocessors, identifying for each whether they see code data and under what conditions. Multiple infrastructure and analytics providers including GCP, Crusoe, Modal, Oracle Cloud, and dashboard tools including Retool, Raindrop, Metabase, and Tableau may access code data for individual users not on zero-data retention mode.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses the full subprocessor chain and the conditions under which each provider may access code-derived data, enabling enterprise compliance teams to conduct third-party risk assessments and verify alignment with their vendor approval requirements. The disclosure that multiple analytics dashboard tools may expose code logs for users not on zero-data retention mode is operationally significant for individual user data governance.

Change history

added Jun 2, 2026

New provision adds plan-dependent disclosure of subprocessors and introduces Google Cloud Platform as a subprocessor with conditional code data storage.

View full change record →

Consumer impact (what this means for users)

Under these terms, individual plan users not in zero-data retention mode may have code snippet logs accessible to multiple internal analytics and dashboard subprocessors including Retool, Raindrop, Metabase, and Tableau for debugging and analytics purposes. Enterprise and Teams plan users operating under zero-data retention defaults are not subject to this subprocessor code data exposure under normal operation.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact security@windsurf.com to inquire about data deletion or to raise data handling questions related to specific subprocessor data flows.

How other platforms handle this

Telegram Medium

By issuing a chargeback or refund request for Premium subscriptions paid for through a third party, you agree to allow Telegram to release necessary data to that third party regarding your account status and Telegram Premium purchases.

YouTube Kids Medium

We will share individual user information with companies, organizations or individuals outside of Google if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to: meet any applicable law, regulation, legal process or enforceable govern...

Midjourney Medium

11 Inferences Conclusions that could be used to create a profile reflecting an individual's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, aptitude. YES. YES

See all platforms with this clause type →

Monitoring

Windsurf has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on your choice of plan (and thus deployment), we may use some or all of the following subcontractors. Google Cloud Platform (GCP) (Stores code data only if Cloud and relevant features are opted-in, sees code data): Usage analytics and logs are primarily hosted on GCP. Crusoe (Sees code data for inference): We manage Crusoe's compute for training some of our custom models, as well as hosting some of our custom models. Modal (Sees code data for inference): We manage Modal's compute for training some of our custom models, as well as hosting some of our custom models.

— Excerpt from Windsurf's Windsurf Security & Data Handling

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 28 requirements for data processing agreements with subprocessors, requiring that each subprocessor listed provide sufficient guarantees of GDPR-compliant data processing. CCPA obligations regarding disclosure of service providers and their data handling practices are also relevant for California users. Enforcement authorities include national supervisory authorities under GDPR and the California Privacy Protection Agency. 2. GOVERNANCE EXPOSURE: Medium. The breadth of the subprocessor list and the conditional code data access descriptions create a data mapping and vendor assessment obligation for organizations deploying Windsurf, particularly for regulated industries. The disclosure is detailed and specific, which reduces transparency risk but does not eliminate the underlying third-party data exposure. 3. JURISDICTION FLAGS: EU/EEA organizations must verify that each subprocessor listed has adequate data processing agreements and that cross-border data transfer mechanisms are in place where applicable. The Oracle Cloud cluster in Frankfurt is disclosed, which may assist with EU data residency requirements for enterprise deployments. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should add each subprocessor that may access code data to their vendor risk management registers. The conditional nature of access for GCP, Retool, Raindrop, Metabase, and Tableau depending on plan and zero-data retention status should be documented in data processing agreements and data flow maps. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should conduct data mapping exercises using this subprocessor list to ensure all code data flows are documented. For GDPR compliance, organizations should verify that Windsurf maintains current data processing agreements with each listed subprocessor and that these are available for review upon request.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive data practices and the accuracy of subprocessor disclosure representations affecting US consumers.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Windsurf Security & Data Handling
Entity
Windsurf
Document last updated
May 11, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-013137
Document ID
CA-D-00783
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
09f15224ef746c31f64489deed565c66e77ca519b3c55d45f54937824fef52f0
Analysis generated
May 21, 2026 05:27 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Security & Data Handling
Record ID: CA-P-013137
Captured: 2026-05-21 05:27:25 UTC
SHA-256: 09f15224ef746c31…
URL: https://conductatlas.com/platform/windsurf/windsurf-security-data-handling/subprocessor-code-data-access-disclosure/
Accessed: June 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Windsurf's Subprocessor Code Data Access Disclosure clause do?

This provision discloses the full subprocessor chain and the conditions under which each provider may access code-derived data, enabling enterprise compliance teams to conduct third-party risk assessments and verify alignment with their vendor approval requirements. The disclosure that multiple analytics dashboard tools may expose code logs for users not on zero-data retention mode is operationally significant for individual user data …

How does this clause affect you?

Under these terms, individual plan users not in zero-data retention mode may have code snippet logs accessible to multiple internal analytics and dashboard subprocessors including Retool, Raindrop, Metabase, and Tableau for debugging and analytics purposes. Enterprise and Teams plan users operating under zero-data retention defaults are not subject to this subprocessor code data exposure under normal operation.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.