Change record
CA-C-004721
Cursor Data Use & Privacy Overview
Entity
Date detected
August 29, 2026
Effective date
August 29, 2026
Severity
Direction
Negative
Taxonomy
Transparency removal
Changes
−4 sentences removed · 2 sentences modified

Impact Summary

Medium Negative for users
Affected users
All users Cursor users with indexed codebases

Cursor removed two sentences from its Data Use & Privacy Overview that previously described how codebase embeddings and metadata are handled during the indexing process. The removed language stated that plaintext code used for computing embeddings ceases to exist after each request, and that embeddings and metadata (including hashes and file names) may be stored in the database. The updated policy no longer includes these specific disclosures about data retention practices.

1 protection removed

Consumers: Users no longer have explicit written assurance about when their code is deleted during the indexing process.

Consumers: Users no longer have explicit written notice about what data from their codebase may be retained long-term.

Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated policy no longer explicitly discloses how Cursor handles plaintext code and metadata during codebase indexing. Previously, the policy stated that plaintext code ceases to exist after each request and that embeddings and metadata may be stored in the database. The removal of this language creates ambiguity about current data handling practices for users who index their codebases.

What you can do

Contact Cursor directly at hi@cursor.com to request written clarification of current codebase data retention and deletion practices

Review your use of Cursor's codebase indexing feature and consider whether sensitive or proprietary code should continue to be indexed

Historical Context

ConductAtlas has recorded 2 material changes to this document over 79 days of monitoring (since June 2026). An additional minor or cosmetic changes were excluded.

Across all monitored documents, Cursor has made 3 significant changes.

Key Clauses Affected

Codebase embedding and plaintext code retention disclosure

Removed explicit statement that plaintext code ceases to exist after request completion and that embeddings/metadata may be stored in database.

Data retention transparency

Policy no longer contains specific language describing which codebase-related data is retained or deleted.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
4f7a1c9d0f7f64616b1732b642e2904c7a7d7cfac8becaf85a5c5ffa4e6501fd
July 16, 2026 00:55 UTC
✓ Verified
Current Version
54414f25926f2f0e3cbb4cbf7e5c72c33183d8d7c9d66b8112431c8b2c499c95
August 29, 2026 00:57 UTC
✓ Verified
Change Detected
August 29, 2026 00:57 UTC
Analysis Methodology
✓ Verified
Source Document
https://cursor.com/data-use
Citation Record
Entity: Cursor
Document: Cursor Data Use & Privacy Overview
Record ID: CA-C-004721
Captured: 2026-08-29 00:57:05 UTC
URL: https://conductatlas.com/change/2026-08-29-cursor-cursor-data-use-privacy-overview-4721/
Accessed: Sept. 2, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Cursor removed specific language from its privacy policy disclosing how it processes and retains codebase data during indexing. This removal eliminates explicit representations about data deletion timelines and storage practices. Organizations evaluating Cursor's compliance posture …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004721.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
Cursor Data Use & Privacy Overview
Entity
Cursor
Captured
August 29, 2026
Source URL
https://cursor.com/data-use
Other changes to Cursor Data Use & Privacy Overview
Previous change Jul 16, 2026
Cursor's privacy policy was updated in an update detected on July 16, 2026, with changes to how it describes data …
Low Neutral
View full version history →
More from Cursor
Aug 29, 2026 Low
Cursor Security Practices

Cursor removed the word 'indexing' from its description of backend functionality in an update detected on August 29, 2026. Previously, …

Aug 27, 2026 Low
Cursor Security Practices

Cursor expanded its security certifications section in an update detected on August 27, 2026. Previously, the policy listed only SOC …

Aug 14, 2026 High
Cursor Terms of Service

Cursor replaced its arbitration-based dispute resolution system with a litigation-based one governed by Texas law and filed exclusively in Texas …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track Cursor policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All Cursor changes →