Cursor temporarily caches file contents on its servers using encryption keys that exist only for the duration of a request; cached files are stated to be temporary, never permanently stored, and not used as training data when Privacy Mode is on.
This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision describes a temporary server-side file caching mechanism with a client-generated encryption model, and conditionally states that cached content is not used as training data, but only when Privacy Mode is enabled.
Interpretive note: The document does not define the maximum duration of 'temporary' caching, and the training data exclusion is conditional on Privacy Mode being enabled, which is not the explicit default state according to this document.
The updated policy no longer explicitly discloses how Cursor handles plaintext code and metadata during codebase indexing. Previously, the policy stated that plaintext code ceases to exist after each request and that embeddings and metadata may be stored in the database. The removal of this language creates ambiguity about current data handling practices for users who index their codebases.
View change record →The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.
View change record →The document states that cached file contents are never permanently stored and are not used as training data when Privacy Mode is enabled; the training data exclusion is conditional on Privacy Mode being active, meaning cached content may be used as training data when Privacy Mode is off.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
to object to profiling activities based on our own legitimate interests
"We temporarily cache file contents on our servers to reduce latency and network usage. The files are encrypted using unique client-generated keys, and these encryption keys only exist on our servers for the duration of a request. All cached file contents are temporary, never permanently stored, and never used as training data when privacy mode is enabled.Excerpt from Cursor's Data Use & Privacy Overview
(1) REGULATORY LANDSCAPE: This provision implicates GDPR data minimization and security principles, as well as CCPA disclosure requirements for temporary processing of file content on third-party servers.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision describes a temporary server-side file caching mechanism with a client-generated encryption model, and conditionally states that cached content is not used as training data, but only when Privacy Mode is enabled.
The document states that cached file contents are never permanently stored and are not used as training data when Privacy Mode is enabled; the training data exclusion is conditional on Privacy Mode being active, meaning cached content may be used as training data when Privacy Mode is off.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.