17 Total
6 High severity
9 Medium severity
2 Low severity

Key Facts

Will Cursor share data with model providers for accounts created before October 15, 2025?
Cursor will not share data with model providers for accounts created before October 15, 2025.
Does Cursor use Customer Data for training when Privacy Mode is enabled?
Cursor does not use Customer Data for training when Privacy Mode is enabled.
What may Cursor use and store when Privacy Mode is off?
When Privacy Mode is off, Cursor may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve its AI features and train its models.
What may Cursor do with codebase data, prompts, and code data when Privacy Mode is off?
When Privacy Mode is off, Cursor may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve its AI features and train its models.
When may Cursor share prompts and limited telemetry with a model provider?
When a user explicitly selects a model provider's model, Cursor may share prompts and limited telemetry with that model provider.
What agreements does Cursor maintain with providers?
Cursor maintains zero data retention agreements with all providers, under which AI model providers will not store or train on user data.
What may model providers run to detect policy violations?
Model providers, including Cursor, may run risk classifiers to detect policy violations, and if a user's prompts or conversations trigger abuse detectors, that data may be stored for investigation.
Where does Cursor route all requests?
Cursor routes all requests through its backend, including those made with a user's own API key.
When is data triggered by abuse detectors deleted?
Cursor stores data triggered by abuse detectors for investigation and deletes it in accordance with retention policies.
Does Cursor permanently store cached file contents when privacy mode is enabled?
Cursor never permanently stores cached file contents when privacy mode is enabled.
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Summary

Cursor's privacy document explains how your code, prompts, and editor activity are handled. Whether Privacy Mode is on or off is the most consequential setting: with it on, Cursor will not use your data for training and will not permanently store cached files; with it off, your codebase data, prompts, and actions may be used to train Cursor's models. If you index your codebase, it is uploaded to Cursor's servers, and metadata such as file names and hashes may be stored even after processing.

Analysis

This document establishes Cursor's data collection, usage, retention, and sharing practices for its AI-powered code editor. A central axis is Privacy Mode: when enabled, Cursor does not use Customer Data for training, does not permanently store cached file contents, and does not use cached file contents as training data; when disabled, Cursor may use and store codebase data, prompts, editor actions, and code snippets to improve AI features and train models. Account creation date determines data-sharing eligibility with model providers — accounts created before October 15, 2025 are not subject to such sharing — while explicit model selection by a user may trigger sharing of prompts and limited telemetry with the chosen provider. Cursor maintains zero data retention agreements with all model providers, contractually prohibiting those providers from storing or training on user data, subject to an explicit exception for abuse-flagged data, which may be retained by Cursor or model providers for investigation before deletion under retention policies. All requests, including those made with a user's own API key, are routed through Cursor's backend.

What this means for you

Whether your data is used for AI training depends entirely on whether Privacy Mode is active in your Cursor account — enabling Privacy Mode is the direct action that prevents your Customer Data, cached files, and codebase data from being used for training. If your account was created before October 15, 2025, your data will not be shared with model providers regardless of other settings. When you explicitly choose a third-party model provider's model, your prompts and limited telemetry may be shared with that provider, though Cursor's zero data retention agreements contractually bar those providers from storing or training on that data — except if your prompts trigger abuse detection, in which case that data may be stored for investigation. Choosing to index your codebase results in it being uploaded to Cursor's servers, where embeddings and metadata including file names may be retained.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: July 2026

What changed Cursor's privacy policy was updated in an update detected on July 16, 2026, with changes to how it describes data sharing with inference providers and model documentation references. The updated policy removes specific naming of inference providers (Baseten, Together AI, Fireworks) and replaces the statement about data sharing with model providers when they are explicitly selected with a more general statement that inference providers may temporarily access and store inputs and outputs for performance improvement, with deletion after use. The policy also adds SpaceXAI to the list of providers whose documentation users should review.
Why this matters The updated policy revises how Cursor describes data handling by inference providers. Previously, the policy named specific providers (Baseten, Together AI, Fireworks) and stated that prompts and telemetry may be shared with model providers when explicitly selected. The updated language generalizes this to state that inference providers may temporarily access and store model inputs and outputs to improve inference performance, with data deleted after use. The policy also adds SpaceXAI to the external documentation references. These changes clarify data handling procedures without materially altering the stated protections around temporary access and deletion.
View full change record →

June 10, 2026

medium
What changed Cursor updated its privacy policy to clarify that in Privacy Mode, customer data will not be used for training by Cursor, and the company maintains zero data retention (ZDR) agreements with all AI model providers. However, the updated terms now explicitly state that model providers may run risk classifiers to detect policy violations, and if your prompts trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. This represents a shift from the previous language, which stated that code would never be trained on by Cursor or third parties, to a more detailed disclosure of abuse detection and retention practices.
Why this matters The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.
View full change record →

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

17 provisions
12 featured
6 clause types
6 high severity
Account Control 1
Stay ahead of the changes

Monitoring

Cursor has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Pre-October-2025 accounts exempt from provider data sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 16, 2026 00:55 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000764
Version ID CA-V-004952
SHA-256 4f7a1c9d0f7f64616b1732b642e2904c7a7d7cfac8becaf85a5c5ffa4e6501fd
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans