Is Windsurf safe with your data?
Windsurf
Cognition AI, Inc.
Partial disclosure · high confidence
Windsurf earns a C (60/100) because it discloses its data practices only in part.
#67
of 116 apps ranked
60
score · Coding avg 55
+5
vs category average
Windsurf runs on the Cognition AI privacy policy, which names Windsurf as a covered Service. The policy lists a full set of data-subject rights and states that it does not sell or share personal information for targeted advertising. It names Standard Contractual Clauses and the UK International Data Transfer Addendum for international transfers. Three areas are weak: the model-training opt-out is conditional with no named mechanism, retention is given only as as needed with no timeline, and security rests on commercially reasonable measures with no named controls, breach notice, or certification. The policy scores at the top of band C.
What Windsurf's privacy policy says about your data
Training opt-out unclear
Section 2 says it may use User Content to train, fine-tune and improve its models depending on the terms that apply to your use of the Services, and the policy names no opt-out mechanism.
Full rights suite
Section 8 grants access, portability in a structured machine-readable format, deletion, rectification, objection, consent withdrawal, and appeal, all exercisable at privacy@cognition.ai.
Does not sell or share for ads
Section 3 states it does not sell or share personal information for targeted advertising and has not done so in the past 12 months.
Vague retention and generic security
Section 5 keeps data as needed with no stated timeline, and Section 4 relies on commercially reasonable measures with no named controls, breach-notice commitment, or certification.
What the policy is silent or vague on
- Not stated: keeping user inputs out of model training
- Not stated: a way to opt out of training
- Not stated: your ownership of generated outputs
- Not stated: shorter retention for AI conversation logs
Windsurf privacy rating
Details
- Category
- Coding
- Modalities
- text
- Processes biometrics
- No
- Policy last updated
- 2026-03-09
- Region scored
- Global / US-default
- Assessed
- 2026-06-20
Other coding apps
Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.