Cursor removed two sentences from its Data Use & Privacy Overview that previously described how codebase embeddings and metadata are handled during the indexing process. The removed language stated that plaintext code used for computing embeddings ceases to exist after each request, and that embeddings and metadata (including hashes and file names) may be stored in the database. The updated policy no longer includes these specific disclosures about data retention practices.
Consumers: Users no longer have explicit written assurance about when their code is deleted during the indexing process.
Consumers: Users no longer have explicit written notice about what data from their codebase may be retained long-term.
The updated policy no longer explicitly discloses how Cursor handles plaintext code and metadata during codebase indexing. Previously, the policy stated that plaintext code ceases to exist after each request and that embeddings and metadata may be stored in the database. The removal of this language creates ambiguity about current data handling practices for users who index their codebases.
→ Contact Cursor directly at hi@cursor.com to request written clarification of current codebase data retention and deletion practices
→ Review your use of Cursor's codebase indexing feature and consider whether sensitive or proprietary code should continue to be indexed
ConductAtlas has recorded 2 material changes to this document over 79 days of monitoring (since June 2026). An additional minor or cosmetic changes were excluded.
Across all monitored documents, Cursor has made 3 significant changes.
Removed explicit statement that plaintext code ceases to exist after request completion and that embeddings/metadata may be stored in database.
Policy no longer contains specific language describing which codebase-related data is retained or deleted.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Cursor removed specific language from its privacy policy disclosing how it processes and retains codebase data during indexing. This removal eliminates explicit representations about data deletion timelines and storage practices. Organizations evaluating Cursor's compliance posture …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004721.
Cursor removed the word 'indexing' from its description of backend functionality in an update detected on August 29, 2026. Previously, …
Cursor expanded its security certifications section in an update detected on August 27, 2026. Previously, the policy listed only SOC …
Cursor replaced its arbitration-based dispute resolution system with a litigation-based one governed by Texas law and filed exclusively in Texas …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.