18 Total
4 High severity
11 Medium severity
3 Low severity

Key Facts

How does Cursor communicate critical incidents to affected users?
Cursor communicates critical incidents to affected users via email.
Does Cursor use any infrastructure in China?
Cursor does not use or maintain any infrastructure in China and does not use any companies headquartered in China as subprocessors.
Does Cursor use any companies headquartered in China as subprocessors?
Cursor does not use or maintain any infrastructure in China and does not use any companies headquartered in China as subprocessors.
What will Cursor not do when Privacy Mode is enabled?
When Privacy Mode is enabled, Cursor will not train on the user's data.
Does Cursor train on the user's data when Privacy Mode is enabled?
When Privacy Mode is enabled, Cursor will not train on the user's data.
What does Cursor implement with its model providers to protect user data?
Cursor implements technical controls and contractual requirements with its model providers to protect user data.
How does Cursor evaluate and review subprocessors?
Cursor evaluates each subprocessor under its vendor risk management program and re-reviews each subprocessor annually.
Does Cursor re-review each subprocessor annually?
Cursor evaluates each subprocessor under its vendor risk management program and re-reviews each subprocessor annually.
Does Cursor commit to penetration testing by reputable third parties at least annually?
Cursor commits to penetration testing by reputable third parties at least annually.
According to what principle does Cursor grant infrastructure access?
Cursor grants infrastructure access according to the principle of least privilege.
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Summary

This document describes how Cursor secures its systems and handles your data. The most user-facing features are Privacy Mode — which, when enabled, prevents Cursor from training on your data — and the ability to delete your account at any time from Settings. Cursor also commits to notifying you by email if a critical incident affects you.

Analysis

This document establishes Cursor's security and data-handling practices, including conditional restrictions on training data use (Privacy Mode disables training on user data), subprocessor controls (no China-based infrastructure or subprocessors, annual vendor risk re-review, contractual and technical requirements imposed on model providers), and operational security commitments (least-privilege access, multi-factor authentication, cybersecurity tooling, continuous log monitoring, and at least annual third-party penetration testing). Cursor commits to acknowledging vulnerability reports within 5 business days and notifying affected users of critical incidents via email. Users retain a self-service right to delete their account at any time from the Settings dashboard, and Privacy Mode is available across all plan tiers including free.

What this means for you

For an individual user, the most direct impact is that enabling Privacy Mode prevents Cursor from using your data for model training. This option is available to every user, including those on the free tier, and can be enabled without upgrading. You can also delete your account at any time directly from the Settings dashboard without needing to contact support. If a critical incident affects you, Cursor will notify you via email.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

4 important changes detected

6 versions captured · Last updated: August 2026

What changed Cursor removed the word 'indexing' from its description of backend functionality in an update detected on August 29, 2026. Previously, the policy stated the app makes requests to deliver 'API, indexing, update, and marketplace functionality.' The updated language now states the app makes requests to deliver 'API, update, and marketplace functionality.' This removes explicit mention of indexing as a stated backend service purpose.
Why this matters The updated policy removes explicit mention of 'indexing' from the list of backend services Cursor's app uses. This is a clarification of the stated backend functionality rather than a material change to data handling practices or user rights. The revised language now describes backend requests as delivering 'API, update, and marketplace functionality' without indexing listed as a discrete purpose.
View full change record →
What changed Cursor expanded its security certifications section in an update detected on August 27, 2026. Previously, the policy listed only SOC 2 Type II attestation availability. The updated language now states that Cursor holds AIUC-1, ISO/IEC 27001:2022, and ISO/IEC 42001:2023 certifications in addition to SOC 2 Type II attestation, with all certificates and reports available on request at trust.cursor.com.
Why this matters The updated terms disclose additional security certifications that Cursor holds. The policy now states that Cursor holds AIUC-1, ISO/IEC 27001:2022, and ISO/IEC 42001:2023 certifications along with SOC 2 Type II attestation. Certificates and reports remain available on request at trust.cursor.com, consistent with the prior availability of attestation reports.
View full change record →

July 16, 2026 low

Cursor added a new documentation reference titled 'Security and Privacy Hardening' to its list of security best practices in the Cursor Security Practices document, detected on July 16, 2026. The …

View change record →
June 10, 2026 low

Cursor updated its Privacy Mode documentation on June 10, 2026 to clarify how the feature operates. The updated language separates the availability of Privacy Mode (available to all users, free …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

18 provisions
12 featured
7 clause types
4 high severity
Stay ahead of the changes

Monitoring

Cursor has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Critical incident notification to affected users via email and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured September 11, 2026 00:56 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000832
Version ID CA-V-006766
SHA-256 066bc9710d892f2db89b9bf07d4148382f378c943f64c5bc9d4881180f6ea79f
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans