Windsurf
- The policy allows AI training; it does not describe an opt-out.
- The policy rules out using your data for targeted ads.
- Data is shared only with the providers who run the service.
- The policy describes staff access for safety and legal checks.
Your code and chats can train their models unless you pay and opt out.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
- Capped at C (the answers alone would give B): Uses your content for AI training with no opt-out
Collected
Account info, your prompts and files, device and usage data, and voice if you use it.
Read the exact line
Privacy policy
“User ContentAny personal information collected when you use our Services, including personal information that may be provided in the input, file uploads, feedback or output.”
Training
They run the product, improve it, and may train models on your content unless a paid user opts out.
Read the exact line
Terms of service
“Cognition may use Customer Data for model training purposes and to improve and enhance the Services. If you subscribe to a paid Service Tier, you may opt out of this use”
Sharing
Service providers, affiliates, and sometimes your employer or admins can see account or content data.
Read the exact line
Privacy policy
“We do not sell or share your personal information with third parties for targeted advertising purposes, nor have we done so in the past 12 months.”
Kept
They keep data as long as they need it for the service, law, or safety; no set clock is given.
Read the exact line
Privacy policy
“We retain your personal information as needed to provide our Service to you, comply with legal obligations, or protect ours or others interests.”
Controls
You can email privacy@cognition.ai to ask for access or deletion; paid users can opt out of training.
Read the exact line
Privacy policy
“You may submit a request to exercise these rights by contacting us at privacy@cognition.ai.”
Fine print
Auto-renewing paid plans, as-is service, and they can close you without notice.
No exact line could be verified.
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
If you pay, opt out of model training
Paid Service Tier opt-out in the Terms (Teams: only an administrator)
Request access or deletion of your data
Email privacy@cognition.ai
Cancel before the renewal date
Your subscription settings; cancellation must be received before the renewal date
Opt out of promotional emails
Unsubscribe link in the promotional email
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
They can train on your code and chats by default. Only paying customers get a way to turn that off.
Read the exact line
Terms of service
“Cognition may use Customer Data for model training purposes and to improve and enhance the Services. If you subscribe to a paid Service Tier, you may opt out of this use (“Opt-Out”).”
For example, if you use the free tier, a private repo snippet you paste could be used to improve their models.
Even a zero-retention setting still lets them keep chats that look unsafe or that they need for legal reasons.
Read the exact line
Terms of service
“ZDR does not preclude retention or disclosure of Customer Data (i) flagged on automated safety and abuse-detection classifiers; (ii) to perform safety, security, and AUP compliance review; or (iii) as compelled by applicable law or legal process.”
For example, a prompt that trips a safety filter can be stored even after you opted out of training.
They can shut off your account without warning if they think you broke the rules.
Read the exact line
Terms of service
“We may suspend or terminate your access to your subscription at any time without notice to you if we believe that you have breached these Terms, or if we must do so in order to comply with law.”
For example, they could lock you out mid-project and, if they say you violated terms, keep your money.
If you pay, you usually cannot get the money back, and subscriptions renew unless you cancel in time.
Read the exact line
Terms of service
“Except as expressly provided in these Terms or where required by law, all payments are non-refundable.”
For example, if you forget to cancel before the renewal date, they charge you again and will not refund it.
If someone sues them because of what you uploaded, you may have to pay their legal costs.
Read the exact line
Terms of service
“Customer shall , , and, at Cognition's option, defend Cognition from and against any losses resulting from any Third-Party Claim (i) that the Customer Data”
For example, if you paste copyrighted code and a company sues Cognition, you could be on the hook.
You own what you put in and what the AI writes back, as far as the law allows.
Read the exact line
Terms of service
“You own all right, title, and interest, including all intellectual property rights, in and to Customer Data, including Outputs to the fullest extent permitted by applicable law.”
For example, generated code is yours to keep, though similar output may be given to other users too.
Voice is turned into text and the recording is then deleted unless they say otherwise.
Read the exact line
Privacy policy
“If you use voice features, we process the audio to generate transcriptions or commands. Audio is deleted after transcription unless otherwise stated.”
For example, a spoken command is transcribed, then the sound file is not kept.
They say they do not sell your data to ad networks for targeted ads.
Read the exact line
Privacy policy
“We do not sell or share your personal information with third parties for targeted advertising purposes, nor have we done so in the past 12 months.”
For example, your coding chats should not be used to build an ad profile about you.
If you sign up with a work email, your boss or company admin may read your content.
Read the exact line
Privacy policy
“administrators of any enterprise or business account may be able to access certain information associated with your account, including your User Content, and be able to control your account and such information.”
For example, an IT admin could open your Devin or Windsurf chats tied to the company plan.
The terms set a 13-year minimum you declare yourself; the privacy policy separately says 18.
Read the exact line
Terms of service
“You must be at least 13 years old to use the Services.”
For example, a 14-year-old could click through the terms even though the privacy page says 18.
Words to know
Legal words from the lines above, in plain English.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- opt out
- Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- targeted advertising
- Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
- retention
- How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
- indemnify
- You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
How we got here · grade C · score 58/100 · 15 of 15 policy answers backed by a verified quote · 1 not stated
What does the app collect beyond what it needs to work?
They collect account details, user content, communications, plus app, browser, device, and usage data.
Does it record your voice, face or body, and what happens to that?
If you use voice, they process audio for transcription and say the audio is deleted afterward unless they state otherwise.
Are your chats and uploads used to train AI models, and is that off by default?
They may train on customer data by default. Only paid tiers may opt out; free individual users are not given an opt-out.
Can employees or contractors read your conversations, and when?
They describe keeping or reviewing data for safety, abuse, AUP compliance, and legal process, not routine sampling of all chats.
Are you profiled or tracked for advertising?
They say they do not sell or share personal information for targeted advertising.
Do they sell or share your data, and can you opt out?
They share with service providers, affiliates, advisors, and sometimes your employer or admins, and say they do not sell for ads.
What rights do they take over what you type and what the AI makes?
You own inputs and outputs. They take a license only as needed to provide the service.
How long do they keep your data after you delete it, and can you delete it in the app?
You request deletion by contacting them. They keep data as needed for the service, law, or safety, with no set number of days.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe commercially reasonable technical and organizational security measures, not audits or a VDP.
Is there a real age gate, and are teens protected?
Terms require you to be at least 13; the privacy policy says 18. There is no described age check beyond self-declaration.
Will they tell you when the rules change, and is the policy specific?
They say they post changes and will give reasonable or 30-day notice for material updates, but the copies here have no date line and retention stays vague.
Can they close your account without warning, and can you get your data out first?
They may suspend or terminate without notice for breach or law, and may delete your data when the account ends.
If something goes wrong, who pays?
The service is as-is, liability is capped at six months of fees or $100, and you must indemnify them for claims about your data.
Do subscriptions renew on their own, and can you get a refund?
Subscriptions auto-renew unless you cancel before the renewal date, and payments are generally non-refundable.
The privacy policy is 2,436 words at a professional or legal expert level (Flesch reading ease 0); the terms are 5,668 words at a professional or legal expert level.