Cursor updated its privacy policy to clarify that in Privacy Mode, customer data will not be used for training by Cursor, and the company maintains zero data retention (ZDR) agreements with all AI model providers. However, the updated terms now explicitly state that model providers may run risk classifiers to detect policy violations, and if your prompts trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. This represents a shift from the previous language, which stated that code would never be trained on by Cursor or third parties, to a more detailed disclosure of abuse detection and retention practices.
Consumers: Cursor now tells users that if their prompts trigger abuse detection systems, their data may be saved for investigation, even with Privacy Mode enabled.
Consumers: The policy no longer makes an absolute promise that your code will never be used for training anywhere.
The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.
→ Review OpenAI and Anthropic documentation referenced in the policy to understand their specific abuse detection and retention practices.
→ Evaluate whether Privacy Mode's qualified zero retention guarantee aligns with your data sensitivity requirements.
Updated to clarify zero data retention with model providers, but added caveat that abuse detectors may trigger storage.
Newly explicit language that model providers may run risk classifiers and store data if prompts trigger abuse detectors.
Removed legacy designation; users are now directed to current Privacy Mode disclosure and third-party documentation.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Cursor updated its privacy disclosure to add explicit language about abuse detection and data retention practices that were not previously described in plain language. The change removes the legacy Privacy Mode designation and adds a …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002807.
Cursor added a new documentation reference titled 'Security and Privacy Hardening' to its list of security best practices in the …
Cursor's privacy policy was updated in an update detected on July 16, 2026, with changes to how it describes data …
Cursor updated its Privacy Mode documentation on June 10, 2026 to clarify how the feature operates. The updated language separates …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.