Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
A footnote in the document states that prompts and limited telemetry will not be shared with model providers when Privacy Mode is off if the user's account was created before October 15, 2025.
This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a data sharing exemption that is account-creation-date-dependent, meaning the applicable data handling terms differ between users based on when they registered, without a mechanism described in this document for users to verify or confirm their account creation date eligibility.
Interpretive note: The document does not describe how users can verify their account creation date or confirm exemption status, and does not clarify whether the carve-out applies at the individual user level or the organizational account level in enterprise deployments.
The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.
View change record →Under this clause, users with accounts created before October 15, 2025 are exempt from third-party model provider data sharing when Privacy Mode is disabled, while users with accounts created on or after that date are subject to prompt and telemetry sharing with model providers they select.
Cross-platform context
See how other platforms handle Pre-October 15, 2025 Account Carve-Out for Third-Party Model Provider Sharing and similar clauses.
Compare across platforms →Monitoring
Cursor has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"[1]: This data will not be shared with model providers if your account was created before Oct 15, 2025.Excerpt from Cursor's Data Use & Privacy Overview
(1) REGULATORY LANDSCAPE: This provision engages GDPR consent and legitimate interests frameworks, as the distinction between pre- and post-October 15, 2025 accounts may reflect a change in data sharing practices that required documented consent for new users but not existing users under prior terms. CCPA disclosure requirements may apply to the scope and accuracy of this account-date-based distinction. (2) GOVERNANCE EXPOSURE: Medium. The operational implementation of this carve-out depends on Cursor's internal account management systems accurately flagging pre-October 15, 2025 accounts as exempt from third-party sharing; this document does not describe a mechanism by which users can verify their exemption status. (3) JURISDICTION FLAGS: EU and EEA users with accounts created before October 15, 2025 should assess whether this carve-out reflects a prior consent-based data sharing restriction that may have different implications under GDPR compared to newer users. Enterprise accounts that onboarded prior to the carve-out date should document this exemption in their data processing records. (4) VENDOR AND CONTRACT IMPLICATIONS: Enterprise procurement teams should confirm with Cursor whether the account creation date determination is based on the primary account holder's registration date or on individual user accounts within a workspace, as this distinction is not clarified in the document. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify the account creation dates of enterprise deployments and confirm with Cursor whether exemption status is automatically applied or requires user or admin action; document this determination in data processing records; and assess whether the footnote disclosure format is sufficient under applicable transparency requirements.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision creates a data sharing exemption that is account-creation-date-dependent, meaning the applicable data handling terms differ between users based on when they registered, without a mechanism described in this document for users to verify or confirm their account creation date eligibility.
Under this clause, users with accounts created before October 15, 2025 are exempt from third-party model provider data sharing when Privacy Mode is disabled, while users with accounts created on or after that date are subject to prompt and telemetry sharing with model providers they select.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.