Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document describes how Cursor secures its systems and handles your data. The most user-facing features are Privacy Mode — which, when enabled, prevents Cursor from training on your data — and the ability to delete your account at any time from Settings. Cursor also commits to notifying you by email if a critical incident affects you.
This document establishes Cursor's security and data-handling practices, including conditional restrictions on training data use (Privacy Mode disables training on user data), subprocessor controls (no China-based infrastructure or subprocessors, annual vendor risk re-review, contractual and technical requirements imposed on model providers), and operational security commitments (least-privilege access, multi-factor authentication, cybersecurity tooling, continuous log monitoring, and at least annual third-party penetration testing). Cursor commits to acknowledging vulnerability reports within 5 business days and notifying affected users of critical incidents via email. Users retain a self-service right to delete their account at any time from the Settings dashboard, and Privacy Mode is available across all plan tiers including free.
For an individual user, the most direct impact is that enabling Privacy Mode prevents Cursor from using your data for model training. This option is available to every user, including those on the free tier, and can be enabled without upgrading. You can also delete your account at any time directly from the Settings dashboard without needing to contact support. If a critical incident affects you, Cursor will notify you via email.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
4 important changes detected
6 versions captured · Last updated: August 2026
Cursor added a new documentation reference titled 'Security and Privacy Hardening' to its list of security best practices in the Cursor Security Practices document, detected on July 16, 2026. The …
View change record →Cursor updated its Privacy Mode documentation on June 10, 2026 to clarify how the feature operates. The updated language separates the availability of Privacy Mode (available to all users, free …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Cursor has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Critical incident notification to affected users via email and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.