Cursor · Cursor Privacy Policy · View original document ↗

No Sale or Targeted Advertising

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Cursor Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Cursor states it does not sell your personal data or use it for targeted advertising across different websites or services, as those practices are defined under US state privacy laws like the CCPA.

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision addresses CCPA and US state privacy law opt-out rights directly; by stating it does not engage in these practices, Anysphere asserts that no opt-out mechanism is required for these specific uses.

Consumer impact (what this means for users)

The policy states personal data is not sold or shared for cross-contextual behavioral advertising; this means users do not need to exercise a CCPA opt-out for sale or sharing, as the policy asserts these activities do not occur.

How other platforms handle this

Groq Medium

There is certain information that we collect automatically from your use of our online Services and from your device(s) used to access those Services, for example by using the types of technologies discussed in the 'Online Analytics' section below. This information includes your IP address, page vie...

Starbucks Medium

We share personal information with third-party advertising and marketing partners, and with social media companies, to provide you with targeted ads, promotions, and offers both on and off our platforms. Under California law, some of these disclosures may constitute a 'sale' or 'sharing' of personal...

Whatnot Medium

We may share your personal information with third-party advertising partners to provide you with advertisements we believe you may find of interest. We do not control these third parties' tracking technologies or how they may be used. If you have questions about an advertisement or other targeted co...

See all platforms with this clause type →

Monitoring

Cursor has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
No sale or targeted advertising: We do not "sell" or "share" personal data for cross-contextual behavioral advertising, and we do not process personal data for "targeted advertising" purposes (as those terms are defined under applicable US state privacy laws). We also do not process sensitive personal data for the purposes of inferring characteristics about a consumer.

— Excerpt from Cursor's Cursor Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly addresses CCPA definitions of 'sale' and 'sharing' of personal data (California Civil Code Section 1798.140), as well as analogous definitions in Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and other US state privacy laws. The FTC and California Privacy Protection Agency (CPPA) have enforcement authority. The assertion that these practices do not occur is a material representation that could be subject to regulatory scrutiny if data flows to advertising technology vendors are later identified. (2) GOVERNANCE EXPOSURE: Low to medium. The explicit no-sale and no-targeted-advertising statement is a clear compliance position. However, the policy does disclose disclosure of data to analytics providers and third-party integrations, which may warrant evaluation against the definitions of 'sale' or 'sharing' under specific state laws depending on whether any consideration flows to or from those parties. (3) JURISDICTION FLAGS: California CPPA enforcement is the primary jurisdiction of heightened concern. Virginia, Colorado, Connecticut, Texas, and other US states with comprehensive privacy laws have similar definitions that this provision addresses. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that analytics and third-party integration vendors receiving personal data are operating under service provider or processor agreements that prevent them from using data for their own advertising purposes, which would otherwise constitute a 'sale' or 'sharing' under CCPA. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that all third-party data disclosures are operationally consistent with the no-sale representation, including reviewing analytics provider agreements for data use restrictions. If any advertising-adjacent technology is later deployed, the policy would require updating and potentially regulatory notification.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive representations about data sale or sharing practices.
    File a complaint →
  • State AG
    California and other state AGs enforce state privacy law requirements related to sale and sharing of personal data.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
ePrivacy Directive
European Union
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union

Provision details

Document information
Document
Cursor Privacy Policy
Entity
Cursor
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 12, 2026
Record ID
CA-P-008153
Document ID
CA-D-00452
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1e5849a4a5fbaa739f760d04f8a003ee1ec366c9f4216cb1cb0ea9b8cf9d01f3
Analysis generated
May 7, 2026 17:01 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cursor
Document: Cursor Privacy Policy
Record ID: CA-P-008153
Captured: 2026-05-07 17:01:07 UTC
SHA-256: 1e5849a4a5fbaa73…
URL: https://conductatlas.com/platform/cursor/cursor-privacy-policy/no-sale-or-targeted-advertising/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Cursor's No Sale or Targeted Advertising clause do?

This provision addresses CCPA and US state privacy law opt-out rights directly; by stating it does not engage in these practices, Anysphere asserts that no opt-out mechanism is required for these specific uses.

How does this clause affect you?

The policy states personal data is not sold or shared for cross-contextual behavioral advertising; this means users do not need to exercise a CCPA opt-out for sale or sharing, as the policy asserts these activities do not occur.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.