Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
Cursor's privacy document explains how your code, prompts, and editor activity are handled. Whether Privacy Mode is on or off is the most consequential setting: with it on, Cursor will not use your data for training and will not permanently store cached files; with it off, your codebase data, prompts, and actions may be used to train Cursor's models. If you index your codebase, it is uploaded to Cursor's servers, and metadata such as file names and hashes may be stored even after processing.
This document establishes Cursor's data collection, usage, retention, and sharing practices for its AI-powered code editor. A central axis is Privacy Mode: when enabled, Cursor does not use Customer Data for training, does not permanently store cached file contents, and does not use cached file contents as training data; when disabled, Cursor may use and store codebase data, prompts, editor actions, and code snippets to improve AI features and train models. Account creation date determines data-sharing eligibility with model providers — accounts created before October 15, 2025 are not subject to such sharing — while explicit model selection by a user may trigger sharing of prompts and limited telemetry with the chosen provider. Cursor maintains zero data retention agreements with all model providers, contractually prohibiting those providers from storing or training on user data, subject to an explicit exception for abuse-flagged data, which may be retained by Cursor or model providers for investigation before deletion under retention policies. All requests, including those made with a user's own API key, are routed through Cursor's backend.
Whether your data is used for AI training depends entirely on whether Privacy Mode is active in your Cursor account — enabling Privacy Mode is the direct action that prevents your Customer Data, cached files, and codebase data from being used for training. If your account was created before October 15, 2025, your data will not be shared with model providers regardless of other settings. When you explicitly choose a third-party model provider's model, your prompts and limited telemetry may be shared with that provider, though Cursor's zero data retention agreements contractually bar those providers from storing or training on that data — except if your prompts trigger abuse detection, in which case that data may be stored for investigation. Choosing to index your codebase results in it being uploaded to Cursor's servers, where embeddings and metadata including file names may be retained.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
3 important changes detected
4 versions captured · Last updated: August 2026
Cursor updated its privacy policy to clarify that in Privacy Mode, customer data will not be used for training by Cursor, and the company maintains zero data retention (ZDR) agreements …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Cursor has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Pre-October-2025 accounts exempt from provider data sharing and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.