Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that Zero Data Retention, even when enabled, does not prevent Cognition from retaining or disclosing Customer Data that is flagged by automated safety or abuse-detection systems, reviewed for safety or AUP compliance, or subject to legal compulsion.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that ZDR, which the agreement otherwise describes as preventing persistent storage of Customer Data, does not apply when automated classifiers flag content, when safety or compliance review occurs, or when legal process requires disclosure. Customers who subscribe to paid tiers and elect ZDR should be aware that these carve-outs qualify the data retention protection.
The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.
View change record →Clarifies that Zero Data Retention can be overridden for safety/abuse flagging and legal compliance, creating exceptions that may retain data despite user opt-out election.
View full change record →Under this clause, even when Zero Data Retention is enabled, Customer Data may be retained and disclosed if flagged by automated safety systems, reviewed for compliance purposes, or required by law. The ZDR election does not provide an absolute guarantee against data retention or disclosure under these conditions.
Cross-platform context
See how other platforms handle Zero Data Retention Carve-Outs and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"ZDR does not preclude retention or disclosure of Customer Data (i) flagged on automated safety and abuse-detection classifiers; (ii) to perform safety, security, and AUP compliance review; or (iii) as compelled by applicable law or legal process.Excerpt from Windsurf's Terms of Service
(1) REGULATORY LANDSCAPE: The automated flagging and retention carve-out engages GDPR data minimization and purpose limitation principles, as retained data must have a documented legal basis under GDPR. CCPA's service provider restrictions may be implicated if retained data is used beyond the stated safety and compliance purposes. Law enforcement access carve-outs interact with Electronic Communications Privacy Act (ECPA) provisions in the U.S. and equivalent national law frameworks in the EU. (2) GOVERNANCE EXPOSURE: Medium. Customers who select ZDR as a privacy control should understand that the carve-outs mean automated classifier flags or internal compliance reviews can result in retention of data that would otherwise be deleted. The agreement does not specify how long flagged data may be retained, under what criteria automated classifiers operate, or what notice, if any, is provided to customers when data is retained under these carve-outs. (3) JURISDICTION FLAGS: EU and EEA customers must assess whether retention triggered by automated safety classifiers constitutes a compatible purpose under GDPR and whether the retention period is documented and proportionate. Healthcare and legal services customers processing privileged or regulated data should assess the law enforcement disclosure carve-out in the context of applicable privilege and confidentiality rules. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers selecting ZDR as a contractual data protection measure should request documentation of the automated classifier criteria and retention timelines from Cognition. The Data Processing Addendum at cognition.ai/dpa should address these carve-outs and their compliance implications. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should document the ZDR carve-outs in their data processing records and assess whether they affect the legal basis relied upon for processing under GDPR or CCPA. Internal policies should reflect that ZDR does not constitute a guarantee of non-retention in all circumstances.
This provision establishes that ZDR, which the agreement otherwise describes as preventing persistent storage of Customer Data, does not apply when automated classifiers flag content, when safety or compliance review occurs, or when legal process requires disclosure. Customers who subscribe to paid tiers and elect ZDR should be aware that these carve-outs qualify the data retention protection.
Under this clause, even when Zero Data Retention is enabled, Customer Data may be retained and disclosed if flagged by automated safety systems, reviewed for compliance purposes, or required by law. The ZDR election does not provide an absolute guarantee against data retention or disclosure under these conditions.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.