59 Total
17 High severity
36 Medium severity
6 Low severity

Key Facts

May Cursor disclose account-related information to an organization associated with a user's email?
Cursor may disclose account-related information to an organization associated with a user's email, and administrators of business or enterprise accounts may access and manage that user's account use.
Who may access and manage a user's account use?
Cursor may disclose account-related information to an organization associated with a user's email, and administrators of business or enterprise accounts may access and manage that user's account use.
What may Cursor disclose personal data to in the event of a merger, acquisition, restructuring, bankruptcy, or other corporate transaction?
In the event of a merger, acquisition, restructuring, bankruptcy, or other corporate transaction, Cursor may disclose personal data to counterparties and advisers as part of due diligence or transfer it as part of the transaction.
May Cursor disclose personal data as part of due diligence or transfer it as part of a corporate transaction?
In the event of a merger, acquisition, restructuring, bankruptcy, or other corporate transaction, Cursor may disclose personal data to counterparties and advisers as part of due diligence or transfer it as part of the transaction.
Does Cursor knowingly collect information from children under 18?
Cursor does not knowingly collect information from children under 18, and if it learns or has reason to suspect a user is under 18, it will investigate and, if appropriate, delete that information.
What will Cursor do if it learns or has reason to suspect a user is under 18?
Cursor does not knowingly collect information from children under 18, and if it learns or has reason to suspect a user is under 18, it will investigate and, if appropriate, delete that information.
Where does Cursor's Privacy Policy not apply?
Cursor's Privacy Policy does not apply where Cursor acts as a data processor and processes personal data on behalf of commercial customers using commercial services, as that data use is governed by customer agreements.
What governs data use where Cursor acts as a data processor and processes personal data on behalf of commercial customers using commercial services?
Cursor's Privacy Policy does not apply where Cursor acts as a data processor and processes personal data on behalf of commercial customers using commercial services, as that data use is governed by customer agreements.
How does Cursor treat a user's continued use of the site after any change to the Privacy Policy?
Cursor treats a user's continued use of the site after any change to the Privacy Policy as that user's acceptance of the change.
What does Cursor not use Inputs or Suggestions to do?
Cursor does not use Inputs or Suggestions to train its models, or permit third parties to use them for training, unless they are flagged for security review or the user has explicitly agreed to their use for such training purposes.
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Summary

This document sets out what personal data Cursor collects, how long it keeps it, and who it may share it with. Cursor will not use what you type into the service to train AI models unless you explicitly agree, and it does not sell your data for advertising. If your account is tied to a work email, your employer's administrators may access and manage your account information.

Analysis

Cursor's Privacy Policy establishes the conditions under which Cursor collects, uses, retains, shares, and protects personal data in connection with its Service. It prohibits using Inputs or Suggestions to train AI models absent explicit user agreement or a security-review flag, and commits to no automated decision-making with legally significant effects. Data sharing is authorized in defined circumstances: corporate transactions, legal compliance, and disclosure to organizations associated with a user's account email. Retention is limited to operational necessity and enumerated legitimate business purposes, and Cursor explicitly does not sell or share personal data for cross-contextual behavioral or targeted advertising. The Policy does not apply where Cursor acts as a data processor for commercial customers, whose data practices are governed solely by their customer agreements.

What this means for you

Your Inputs and any personal data embedded in them are collected by Cursor and may appear in the Suggestions returned to you, but Cursor will not use that content to train AI models unless you have explicitly agreed. If your account is linked to an organizational email address, Cursor may share your account information with that organization's administrators, who may manage your usage. Cursor treats your continued use of the Service after any Privacy Policy change as acceptance of that change. If you are a user of a commercial customer's deployment of Cursor, this Privacy Policy does not govern your data — your protections are determined by that customer's agreement with Cursor. To avoid model-training use of your content, do not affirmatively agree to training use when that option is presented.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

59 provisions
12 featured
13 clause types
17 high severity
AI / Automated Decision-Making 1 1 high
Targeting and Audience Restrictions 1 1 high
Disclosure and Transparency Requirements 1
Stay ahead of the changes

Monitoring

Cursor has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Business Account Admin Access to Data and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 29, 2026 08:12 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000452
Version ID CA-V-001029
SHA-256 8bd4582800da5507b60be4304dd6ff41cd4be54d51cf12059e3f0e1d9698cba9
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans