Cursor · Cursor Data Use & Privacy Overview · View original document ↗

Pre-October 15, 2025 Account Carve-Out for Third-Party Model Provider Sharing

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Cursor changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Cursor recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Cursor Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

A footnote in the document states that prompts and limited telemetry will not be shared with model providers when Privacy Mode is off if the user's account was created before October 15, 2025.

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision creates a data sharing exemption that is account-creation-date-dependent, meaning the applicable data handling terms differ between users based on when they registered, without a mechanism described in this document for users to verify or confirm their account creation date eligibility.

Interpretive note: The document does not describe how users can verify their account creation date or confirm exemption status, and does not clarify whether the carve-out applies at the individual user level or the organizational account level in enterprise deployments.

Recent Activity

This document changed recently

Medium Jun 10, 2026

The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.

View change record →

Consumer impact (what this means for users)

Under this clause, users with accounts created before October 15, 2025 are exempt from third-party model provider data sharing when Privacy Mode is disabled, while users with accounts created on or after that date are subject to prompt and telemetry sharing with model providers they select.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Cursor at hi@cursor.com to confirm your account creation date and verify whether the pre-October 15, 2025 data sharing exemption applies to your account.

Cross-platform context

See how other platforms handle Pre-October 15, 2025 Account Carve-Out for Third-Party Model Provider Sharing and similar clauses.

Compare across platforms →

Monitoring

Cursor has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
[1]: This data will not be shared with model providers if your account was created before Oct 15, 2025.

Excerpt from Cursor's Data Use & Privacy Overview

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR consent and legitimate interests frameworks, as the distinction between pre- and post-October 15, 2025 accounts may reflect a change in data sharing practices that required documented consent for new users but not existing users under prior terms. CCPA disclosure requirements may apply to the scope and accuracy of this account-date-based distinction. (2) GOVERNANCE EXPOSURE: Medium. The operational implementation of this carve-out depends on Cursor's internal account management systems accurately flagging pre-October 15, 2025 accounts as exempt from third-party sharing; this document does not describe a mechanism by which users can verify their exemption status. (3) JURISDICTION FLAGS: EU and EEA users with accounts created before October 15, 2025 should assess whether this carve-out reflects a prior consent-based data sharing restriction that may have different implications under GDPR compared to newer users. Enterprise accounts that onboarded prior to the carve-out date should document this exemption in their data processing records. (4) VENDOR AND CONTRACT IMPLICATIONS: Enterprise procurement teams should confirm with Cursor whether the account creation date determination is based on the primary account holder's registration date or on individual user accounts within a workspace, as this distinction is not clarified in the document. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify the account creation dates of enterprise deployments and confirm with Cursor whether exemption status is automatically applied or requires user or admin action; document this determination in data processing records; and assess whether the footnote disclosure format is sufficient under applicable transparency requirements.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer privacy disclosures and unfair or deceptive practices relevant to the accuracy and clarity of account-date-based data sharing distinctions.
    File a complaint →

Provision details

Document information
Document
Cursor Data Use & Privacy Overview
Entity
Cursor
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016534
Document ID
CA-D-00764
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b99e852f1ad6e7f2138edb3e355e61411f60e79b811fb2af6c88fcd7ff48ef25
Analysis generated
July 9, 2026 14:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cursor
Document: Cursor Data Use & Privacy Overview
Record ID: CA-P-016534
Captured: 2026-07-09 14:51:27 UTC
SHA-256: b99e852f1ad6e7f2…
URL: https://conductatlas.com/platform/cursor/cursor-data-use-privacy-overview/provision/CA-P-016534/pre-october-15-2025-account-carve-out-for-third-party-model-provider-sharing/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Cursor's Pre-October 15, 2025 Account Carve-Out for Third-Party Model Provider Sharing clause do?

This provision creates a data sharing exemption that is account-creation-date-dependent, meaning the applicable data handling terms differ between users based on when they registered, without a mechanism described in this document for users to verify or confirm their account creation date eligibility.

How does this clause affect you?

Under this clause, users with accounts created before October 15, 2025 are exempt from third-party model provider data sharing when Privacy Mode is disabled, while users with accounts created on or after that date are subject to prompt and telemetry sharing with model providers they select.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.