Windsurf · Windsurf Terms of Service · View original document ↗

Sensitive Personal Data Prohibition

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Windsurf changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Windsurf recorded 6 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Windsurf Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits customers from submitting or processing medical information, social security numbers, birth dates, passport information, bank account numbers, and credit card numbers through the Services.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes an affirmative contractual prohibition on using the platform to process specific categories of sensitive personal data. Violation of this prohibition may constitute a breach of the agreement, potentially triggering suspension or termination rights under Sections 2.4 and 7.2.

Recent Activity

This document changed recently

Medium Jul 1, 2026

The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.

View change record →

Change history

added Jul 24, 2026

Explicitly prohibits processing of sensitive data types, limiting user ability to process HIPAA-regulated or PCI-DSS data and defining acceptable use scope.

View full change record →

Consumer impact (what this means for users)

The agreement prohibits submission of defined sensitive data categories, including medical information, government identification numbers, and financial account numbers, through the platform. Customers are responsible for implementing controls to prevent Authorized Users from submitting such data.

Cross-platform context

See how other platforms handle Sensitive Personal Data Prohibition and similar clauses.

Compare across platforms →

Monitoring

Windsurf has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You agree not to process any medical information or sensitive personal data such as social security numbers, birth dates, passport information, bank account, and credit card numbers in using the Services.

Excerpt from Windsurf's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This prohibition engages HIPAA for medical information, the Gramm-Leach-Bliley Act for financial account data, and GDPR Article 9 for special categories of personal data. The listed categories align with heightened-risk data types under CCPA and state privacy laws. Customers in healthcare or financial services who inadvertently submit prohibited data categories may face independent regulatory exposure under these frameworks, separate from the contractual breach. (2) GOVERNANCE EXPOSURE: Medium. The contractual prohibition does not include a technical enforcement mechanism described in the document; compliance depends on customer-side controls and Authorized User training. The agreement's customer responsibility clause in Section 2.2 makes the customer liable for all Authorized User actions, meaning inadvertent submission by any Authorized User constitutes a customer breach. (3) JURISDICTION FLAGS: Healthcare customers in the U.S. face HIPAA enforcement exposure. Financial services customers face GLBA and state financial privacy law exposure. EU customers must assess whether this prohibition adequately addresses GDPR Article 9 special category data restrictions, which extend beyond the listed categories to include racial or ethnic origin, political opinions, religious beliefs, biometric data, and other categories not enumerated in this clause. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should assess whether the listed prohibited categories are sufficiently broad to cover all sensitive data types relevant to their operations, and whether additional data processing restrictions should be negotiated. The absence of a technical prevention mechanism means vendor risk assessments should include documentation of customer-side controls. (5) COMPLIANCE CONSIDERATIONS: Customers should implement technical controls, including content filtering or access restrictions, to prevent submission of prohibited data categories. Authorized User training should include explicit guidance on this prohibition. Data classification policies should identify whether any ordinary workflow data could inadvertently include prohibited categories such as birth dates or partial financial account numbers.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA, which applies to medical information, a category explicitly prohibited from processing under this agreement.
    File a complaint →

Provision details

Document information
Document
Windsurf Terms of Service
Entity
Windsurf
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014096
Document ID
CA-D-00487
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f6e8d9d0bd5f9547549794c5f7e89d7dbd456e727e5d9c631d8366f1a48c326f
Analysis generated
July 9, 2026 04:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Terms of Service
Record ID: CA-P-014096
Captured: 2026-07-09 04:42:52 UTC
SHA-256: f6e8d9d0bd5f9547…
URL: https://conductatlas.com/platform/windsurf/windsurf-terms-of-service/provision/CA-P-014096/sensitive-personal-data-prohibition/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Windsurf's Sensitive Personal Data Prohibition clause do?

This provision establishes an affirmative contractual prohibition on using the platform to process specific categories of sensitive personal data. Violation of this prohibition may constitute a breach of the agreement, potentially triggering suspension or termination rights under Sections 2.4 and 7.2.

How does this clause affect you?

The agreement prohibits submission of defined sensitive data categories, including medical information, government identification numbers, and financial account numbers, through the platform. Customers are responsible for implementing controls to prevent Authorized Users from submitting such data.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.