Key Facts
How does Cursor communicate critical incidents to affected users?
Cursor communicates critical incidents to affected users via email.
Does Cursor use any infrastructure in China?
Cursor does not use or maintain any infrastructure in China and does not use any companies headquartered in China as subprocessors.
Does Cursor use any companies headquartered in China as subprocessors?
Cursor does not use or maintain any infrastructure in China and does not use any companies headquartered in China as subprocessors.
What will Cursor not do when Privacy Mode is enabled?
When Privacy Mode is enabled, Cursor will not train on the user's data.
Does Cursor train on the user's data when Privacy Mode is enabled?
When Privacy Mode is enabled, Cursor will not train on the user's data.
What does Cursor implement with its model providers to protect user data?
Cursor implements technical controls and contractual requirements with its model providers to protect user data.
How does Cursor evaluate and review subprocessors?
Cursor evaluates each subprocessor under its vendor risk management program and re-reviews each subprocessor annually.
Does Cursor re-review each subprocessor annually?
Cursor evaluates each subprocessor under its vendor risk management program and re-reviews each subprocessor annually.
Does Cursor commit to penetration testing by reputable third parties at least annually?
Cursor commits to penetration testing by reputable third parties at least annually.
According to what principle does Cursor grant infrastructure access?
Cursor grants infrastructure access according to the principle of least privilege.
Summary
This document describes how Cursor secures its systems and handles your data. The most user-facing features are Privacy Mode — which, when enabled, prevents Cursor from training on your data — and the ability to delete your account at any time from Settings. Cursor also commits to notifying you by email if a critical incident affects you.
Analysis
This document establishes Cursor's security and data-handling practices, including conditional restrictions on training data use (Privacy Mode disables training on user data), subprocessor controls (no China-based infrastructure or subprocessors, annual vendor risk re-review, contractual and technical requirements imposed on model providers), and operational security commitments (least-privilege access, multi-factor authentication, cybersecurity tooling, continuous log monitoring, and at least annual third-party penetration testing). Cursor commits to acknowledging vulnerability reports within 5 business days and notifying affected users of critical incidents via email. Users retain a self-service right to delete their account at any time from the Settings dashboard, and Privacy Mode is available across all plan tiers including free.
What this means for you
For an individual user, the most direct impact is that enabling Privacy Mode prevents Cursor from using your data for model training. This option is available to every user, including those on the free tier, and can be enabled without upgrading. You can also delete your account at any time directly from the Settings dashboard without needing to contact support. If a critical incident affects you, Cursor will notify you via email.
2 important changes detected
3 versions captured · Last updated: July 2026
What changed
Cursor added a new documentation reference titled 'Security and Privacy Hardening' to its list of security best practices in the Cursor Security Practices document, detected on July 16, 2026. The change reorganizes the documentation hierarchy by inserting this new topic between 'Data Encryption and CMEK' and 'Enterprise administration'. This addition points users toward an additional resource on hardening security and privacy configurations but does not alter existing security requirements or user obligations.
Why this matters
The updated security practices documentation now references an additional resource on 'Security and Privacy Hardening' alongside existing security guidance. This change adds a documentation link but does not modify any security requirements, user obligations, or operational procedures. Developers may optionally review this additional resource to understand hardening best practices.
View full change record →
What changed
Cursor updated its Privacy Mode documentation on June 10, 2026 to clarify how the feature operates. The updated language separates the availability of Privacy Mode (available to all users, free or Pro) from its default status (enabled by default for team members, inherited by new joiners). New language explicitly states that when Privacy Mode is enabled, Cursor will not train on user data, and adds that technical controls and contractual requirements with model providers protect user data. The practical effect is clearer disclosure of what Privacy Mode does and how it applies to team settings.
Why this matters
The updated terms clarify how Cursor's Privacy Mode functions and when it applies. When enabled, the policy now explicitly states that Cursor will not train on user data, and that technical controls and contractual requirements with model providers protect data. For teams, new members automatically inherit the team's Privacy Mode settings. This is a clarification of existing functionality rather than a new operational restriction or expanded authority.
View full change record →
Archival ProvenanceSource & Archival Record
Last Captured
July 16, 2026 00:55 UTC
Capture Method
Automated scheduled archival capture
Document ID
CA-D-000832
Version ID
CA-V-004953
SHA-256
f24454a79c9ebf50546fbadf74a477d37b7ebb4e90d448f8ed765178c245b62a
✓ Snapshot stored
✓ Text extracted
✓ Change verified
✓ Hash verified