Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement prohibits customers from submitting or processing medical information, social security numbers, birth dates, passport information, bank account numbers, and credit card numbers through the Services.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes an affirmative contractual prohibition on using the platform to process specific categories of sensitive personal data. Violation of this prohibition may constitute a breach of the agreement, potentially triggering suspension or termination rights under Sections 2.4 and 7.2.
The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.
View change record →Explicitly prohibits processing of sensitive data types, limiting user ability to process HIPAA-regulated or PCI-DSS data and defining acceptable use scope.
View full change record →The agreement prohibits submission of defined sensitive data categories, including medical information, government identification numbers, and financial account numbers, through the platform. Customers are responsible for implementing controls to prevent Authorized Users from submitting such data.
Cross-platform context
See how other platforms handle Sensitive Personal Data Prohibition and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"You agree not to process any medical information or sensitive personal data such as social security numbers, birth dates, passport information, bank account, and credit card numbers in using the Services.Excerpt from Windsurf's Terms of Service
(1) REGULATORY LANDSCAPE: This prohibition engages HIPAA for medical information, the Gramm-Leach-Bliley Act for financial account data, and GDPR Article 9 for special categories of personal data. The listed categories align with heightened-risk data types under CCPA and state privacy laws. Customers in healthcare or financial services who inadvertently submit prohibited data categories may face independent regulatory exposure under these frameworks, separate from the contractual breach. (2) GOVERNANCE EXPOSURE: Medium. The contractual prohibition does not include a technical enforcement mechanism described in the document; compliance depends on customer-side controls and Authorized User training. The agreement's customer responsibility clause in Section 2.2 makes the customer liable for all Authorized User actions, meaning inadvertent submission by any Authorized User constitutes a customer breach. (3) JURISDICTION FLAGS: Healthcare customers in the U.S. face HIPAA enforcement exposure. Financial services customers face GLBA and state financial privacy law exposure. EU customers must assess whether this prohibition adequately addresses GDPR Article 9 special category data restrictions, which extend beyond the listed categories to include racial or ethnic origin, political opinions, religious beliefs, biometric data, and other categories not enumerated in this clause. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should assess whether the listed prohibited categories are sufficiently broad to cover all sensitive data types relevant to their operations, and whether additional data processing restrictions should be negotiated. The absence of a technical prevention mechanism means vendor risk assessments should include documentation of customer-side controls. (5) COMPLIANCE CONSIDERATIONS: Customers should implement technical controls, including content filtering or access restrictions, to prevent submission of prohibited data categories. Authorized User training should include explicit guidance on this prohibition. Data classification policies should identify whether any ordinary workflow data could inadvertently include prohibited categories such as birth dates or partial financial account numbers.
This provision establishes an affirmative contractual prohibition on using the platform to process specific categories of sensitive personal data. Violation of this prohibition may constitute a breach of the agreement, potentially triggering suspension or termination rights under Sections 2.4 and 7.2.
The agreement prohibits submission of defined sensitive data categories, including medical information, government identification numbers, and financial account numbers, through the platform. Customers are responsible for implementing controls to prevent Authorized Users from submitting such data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.