Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Privacy Mode activates zero data retention agreements with all model providers, preventing training use of Customer Data, but the document states that prompts or conversations triggering abuse detection classifiers may be stored by model providers including Cursor for investigation under their own retention policies.
This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Privacy Mode does not constitute an absolute data retention barrier; a carve-out permits storage of user data triggered by abuse detectors, with retention duration and deletion governed by the individual model provider's policies rather than Cursor's own terms.
Interpretive note: The scope of what triggers abuse detectors is not defined in the document, and retention duration under third-party provider policies is not specified, creating uncertainty about the practical breadth of this exception.
The updated policy clarifies that Cursor maintains zero data retention agreements with all AI model providers and customer data will not be used for training by Cursor. However, the policy now explicitly discloses that model providers may run risk classifiers to detect policy violations, and if your prompts or conversations trigger abuse detectors, your data may be stored for investigation and deleted according to the provider's retention policies. The policy removed the previous blanket statement that code would never be trained on by Cursor or third parties, replacing it with more specific disclosure of abuse detection practices. You can review OpenAI and Anthropic's documentation directly for details on their specific retention policies.
View change record →Under this clause, users who enable Privacy Mode receive zero data retention protections for standard usage, but data flagged by abuse detection systems may be stored and retained under model provider policies that are referenced but not reproduced in this document, including policies of providers other than Cursor.
Cross-platform context
See how other platforms handle Privacy Mode Zero Data Retention with Abuse Detection Exception and similar clauses.
Compare across platforms →Monitoring
Cursor has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you enable 'Privacy Mode' in Cursor's settings: Customer Data will not be used for training by Cursor. Cursor maintains zero data retention (ZDR) agreements with all providers, and AI model providers will not store or train on your data. However, please note that subject to their policies, model providers (including Cursor) may run risk classifiers to detect violations of terms and usage policies, and if your prompts or conversations trigger abuse detectors your data may be stored for investigation and deleted in accordance with their retention policies.Excerpt from Cursor's Data Use & Privacy Overview
(1) REGULATORY LANDSCAPE: This provision implicates GDPR data minimization and purpose limitation principles, as the abuse detection exception introduces a secondary retention pathway not fully defined within the document itself. CCPA transparency requirements may apply to the extent that data stored under the abuse detection carve-out constitutes personal information subject to disclosure obligations. The FTC Act's prohibition on unfair or deceptive practices is relevant to the clarity and prominence of this exception within a document that otherwise prominently features zero data retention. (2) GOVERNANCE EXPOSURE: Medium. The provision creates compliance exposure through its delegation of retention terms to third-party model provider policies that are not incorporated into this document and are subject to change independently. The scope of what constitutes an abuse detection trigger is not defined, creating operational uncertainty about how broadly this exception may apply in practice. (3) JURISDICTION FLAGS: EU and EEA users face heightened exposure because the delegation of retention decisions to third-party provider policies may not satisfy GDPR requirements for documented data processing agreements with defined retention schedules. California users may have CCPA rights that apply to data retained under this exception that are not addressed in this document. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether Cursor's zero data retention agreements with model providers contractually bind those providers to the abuse detection exception terms described, and whether those agreements define the scope of risk classifier triggering. The document does not assert audit rights over model provider retention practices under the abuse detection carve-out. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the abuse detection exception is disclosed with sufficient prominence and specificity to satisfy transparency obligations under GDPR and CCPA; map which model providers are covered by ZDR agreements and which are not; and determine whether enterprise data processed through Cursor may trigger abuse detectors in ways that expose proprietary code to extended retention.
This provision establishes that Privacy Mode does not constitute an absolute data retention barrier; a carve-out permits storage of user data triggered by abuse detectors, with retention duration and deletion governed by the individual model provider's policies rather than Cursor's own terms.
Under this clause, users who enable Privacy Mode receive zero data retention protections for standard usage, but data flagged by abuse detection systems may be stored and retained under model provider policies that are referenced but not reproduced in this document, including policies of providers other than Cursor.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.