All apps

Is Windsurf safe with your data?

C
Windsurf icon

Windsurf

Cognition AI, Inc.

57/100

Partial disclosure · high confidence

Windsurf earns a C (57/100) because it discloses its data practices only in part.

#68

of 211 apps ranked

57

score · Coding avg 47

+10

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Windsurf discloses a workable data framework with a defined Zero Data Retention mode and a clear no-sale commitment, but most of its strongest protections are gated behind paid tiers or hedged with discretionary language that weakens them for the default free user.

What Windsurf's privacy policy and terms of service say about your data

Training opt-out is paid-tier only

Cognition trains on Customer Data by default and the Opt-Out is available only to paid subscribers, with Teams requiring an administrator to exercise it, so free-tier users get no training choice at all.

Zero Data Retention is conditional, not default

ZDR is precisely defined as data not saved to disk and deleted on Output generation, but it is enabled only as a consequence of a paid-tier Opt-Out, so the retention ladder cannot be credited at the top value.

Privacy rights are hedged with absolute discretion

Every access, deletion, portability and correction right is framed as "you may have the right," and the policy states that where a right is not provided by local law, "we have absolute discretion in providing these rights.

Age gate contradicts itself across documents

The privacy policy says users must be at least 18 years old while the Platform Terms twice state "You must be at least 13 years old to use the Services," leaving the children's protection undefined in practice.

What the policy is silent or vague on

  • Not stated: a deletion timeline after closure or request
  • Not stated: breach notification
  • Only partial: keeping user inputs out of model training
  • Only partial: a way to opt out of training

Windsurf privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inPartial
Names a way to opt out of or into trainingPartial
Says whether training use differs by plan or tierPartial
Lets the user keep ownership of generated outputsPartial
Data-subject rights1 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsPartial
Commits to collecting only the data it needsPartial
Third-party sharing2 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outDisclosed
Names a safeguard for international data transfersPartial
States a standard for government and law-enforcement accessPartial
Transparency2 of 4 disclosed
Discloses that you are interacting with AIPartial
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children1 of 2 disclosed
Discloses automated decisions and a human-review pathNot applicable
Limits the use of special-category dataDisclosed
Governs biometric data specificallyNot applicable
States protections for children's dataPartial
Security and accountability0 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactPartial
DisclosedPartialSilentAdverseNot applicable

Details

Category
Coding
Modalities
text
Processes biometrics
No
Policy last updated
2026-03-09
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Windsurf safe with your data? Grade C | AI App Trust & Transparency Index