Cursor · Cursor Data Use & Privacy Overview · View original document ↗

Privacy Mode Zero Data Retention with Abuse Detection Exception

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Cursor changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Cursor recorded 2 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Cursor Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Privacy Mode activates zero data retention agreements with all model providers, preventing training use of Customer Data, but the document states that prompts or conversations triggering abuse detection classifiers may be stored by model providers including Cursor for investigation under their own retention policies.

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Privacy Mode does not constitute an absolute data retention barrier; a carve-out permits storage of user data triggered by abuse detectors, with retention duration and deletion governed by the individual model provider's policies rather than Cursor's own terms.

Interpretive note: The scope of what triggers abuse detectors is not defined in the document, and retention duration under third-party provider policies is not specified, creating uncertainty about the practical breadth of this exception.

Recent Activity

This document changed recently

Medium Jun 10, 2026

The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.

View change record →

Consumer impact (what this means for users)

Under this clause, users who enable Privacy Mode receive zero data retention protections for standard usage, but data flagged by abuse detection systems may be stored and retained under model provider policies that are referenced but not reproduced in this document, including policies of providers other than Cursor.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Cursor at hi@cursor.com to inquire about data stored under the abuse detection exception and request deletion in accordance with applicable retention policies.

Cross-platform context

See how other platforms handle Privacy Mode Zero Data Retention with Abuse Detection Exception and similar clauses.

Compare across platforms →

Monitoring

Cursor has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you enable 'Privacy Mode' in Cursor's settings: Customer Data will not be used for training by Cursor. Cursor maintains zero data retention (ZDR) agreements with all providers, and AI model providers will not store or train on your data. However, please note that subject to their policies, model providers (including Cursor) may run risk classifiers to detect violations of terms and usage policies, and if your prompts or conversations trigger abuse detectors your data may be stored for investigation and deleted in accordance with their retention policies.

Excerpt from Cursor's Data Use & Privacy Overview

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision implicates GDPR data minimization and purpose limitation principles, as the abuse detection exception introduces a secondary retention pathway not fully defined within the document itself. CCPA transparency requirements may apply to the extent that data stored under the abuse detection carve-out constitutes personal information subject to disclosure obligations. The FTC Act's prohibition on unfair or deceptive practices is relevant to the clarity and prominence of this exception within a document that otherwise prominently features zero data retention. (2) GOVERNANCE EXPOSURE: Medium. The provision creates compliance exposure through its delegation of retention terms to third-party model provider policies that are not incorporated into this document and are subject to change independently. The scope of what constitutes an abuse detection trigger is not defined, creating operational uncertainty about how broadly this exception may apply in practice. (3) JURISDICTION FLAGS: EU and EEA users face heightened exposure because the delegation of retention decisions to third-party provider policies may not satisfy GDPR requirements for documented data processing agreements with defined retention schedules. California users may have CCPA rights that apply to data retained under this exception that are not addressed in this document. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether Cursor's zero data retention agreements with model providers contractually bind those providers to the abuse detection exception terms described, and whether those agreements define the scope of risk classifier triggering. The document does not assert audit rights over model provider retention practices under the abuse detection carve-out. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the abuse detection exception is disclosed with sufficient prominence and specificity to satisfy transparency obligations under GDPR and CCPA; map which model providers are covered by ZDR agreements and which are not; and determine whether enterprise data processed through Cursor may trigger abuse detectors in ways that expose proprietary code to extended retention.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer privacy representations and unfair or deceptive practices relevant to the scope and disclosure of the abuse detection exception within a document that prominently features zero data retention.
    File a complaint →

Provision details

Document information
Document
Cursor Data Use & Privacy Overview
Entity
Cursor
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016530
Document ID
CA-D-00764
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b99e852f1ad6e7f2138edb3e355e61411f60e79b811fb2af6c88fcd7ff48ef25
Analysis generated
July 9, 2026 14:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cursor
Document: Cursor Data Use & Privacy Overview
Record ID: CA-P-016530
Captured: 2026-07-09 14:51:27 UTC
SHA-256: b99e852f1ad6e7f2…
URL: https://conductatlas.com/platform/cursor/cursor-data-use-privacy-overview/provision/CA-P-016530/privacy-mode-zero-data-retention-with-abuse-detection-exception/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Cursor's Privacy Mode Zero Data Retention with Abuse Detection Exception clause do?

This provision establishes that Privacy Mode does not constitute an absolute data retention barrier; a carve-out permits storage of user data triggered by abuse detectors, with retention duration and deletion governed by the individual model provider's policies rather than Cursor's own terms.

How does this clause affect you?

Under this clause, users who enable Privacy Mode receive zero data retention protections for standard usage, but data flagged by abuse detection systems may be stored and retained under model provider policies that are referenced but not reproduced in this document, including policies of providers other than Cursor.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.