18 Total
4 High severity
11 Medium severity
3 Low severity

Key Facts

How does Cursor communicate critical incidents to affected users?
Cursor communicates critical incidents to affected users via email.
Does Cursor use any infrastructure in China?
Cursor does not use or maintain any infrastructure in China and does not use any companies headquartered in China as subprocessors.
Does Cursor use any companies headquartered in China as subprocessors?
Cursor does not use or maintain any infrastructure in China and does not use any companies headquartered in China as subprocessors.
What will Cursor not do when Privacy Mode is enabled?
When Privacy Mode is enabled, Cursor will not train on the user's data.
Does Cursor train on the user's data when Privacy Mode is enabled?
When Privacy Mode is enabled, Cursor will not train on the user's data.
What does Cursor implement with its model providers to protect user data?
Cursor implements technical controls and contractual requirements with its model providers to protect user data.
How does Cursor evaluate and review subprocessors?
Cursor evaluates each subprocessor under its vendor risk management program and re-reviews each subprocessor annually.
Does Cursor re-review each subprocessor annually?
Cursor evaluates each subprocessor under its vendor risk management program and re-reviews each subprocessor annually.
Does Cursor commit to penetration testing by reputable third parties at least annually?
Cursor commits to penetration testing by reputable third parties at least annually.
According to what principle does Cursor grant infrastructure access?
Cursor grants infrastructure access according to the principle of least privilege.
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Summary

This document describes how Cursor secures its systems and handles your data. The most user-facing features are Privacy Mode — which, when enabled, prevents Cursor from training on your data — and the ability to delete your account at any time from Settings. Cursor also commits to notifying you by email if a critical incident affects you.

Analysis

This document establishes Cursor's security and data-handling practices, including conditional restrictions on training data use (Privacy Mode disables training on user data), subprocessor controls (no China-based infrastructure or subprocessors, annual vendor risk re-review, contractual and technical requirements imposed on model providers), and operational security commitments (least-privilege access, multi-factor authentication, cybersecurity tooling, continuous log monitoring, and at least annual third-party penetration testing). Cursor commits to acknowledging vulnerability reports within 5 business days and notifying affected users of critical incidents via email. Users retain a self-service right to delete their account at any time from the Settings dashboard, and Privacy Mode is available across all plan tiers including free.

What this means for you

For an individual user, the most direct impact is that enabling Privacy Mode prevents Cursor from using your data for model training. This option is available to every user, including those on the free tier, and can be enabled without upgrading. You can also delete your account at any time directly from the Settings dashboard without needing to contact support. If a critical incident affects you, Cursor will notify you via email.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: July 2026

What changed Cursor added a new documentation reference titled 'Security and Privacy Hardening' to its list of security best practices in the Cursor Security Practices document, detected on July 16, 2026. The change reorganizes the documentation hierarchy by inserting this new topic between 'Data Encryption and CMEK' and 'Enterprise administration'. This addition points users toward an additional resource on hardening security and privacy configurations but does not alter existing security requirements or user obligations.
Why this matters The updated security practices documentation now references an additional resource on 'Security and Privacy Hardening' alongside existing security guidance. This change adds a documentation link but does not modify any security requirements, user obligations, or operational procedures. Developers may optionally review this additional resource to understand hardening best practices.
View full change record →
What changed Cursor updated its Privacy Mode documentation on June 10, 2026 to clarify how the feature operates. The updated language separates the availability of Privacy Mode (available to all users, free or Pro) from its default status (enabled by default for team members, inherited by new joiners). New language explicitly states that when Privacy Mode is enabled, Cursor will not train on user data, and adds that technical controls and contractual requirements with model providers protect user data. The practical effect is clearer disclosure of what Privacy Mode does and how it applies to team settings.
Why this matters The updated terms clarify how Cursor's Privacy Mode functions and when it applies. When enabled, the policy now explicitly states that Cursor will not train on user data, and that technical controls and contractual requirements with model providers protect data. For teams, new members automatically inherit the team's Privacy Mode settings. This is a clarification of existing functionality rather than a new operational restriction or expanded authority.
View full change record →

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

18 provisions
12 featured
7 clause types
4 high severity
Stay ahead of the changes

Monitoring

Cursor has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Critical incident notification to affected users via email and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured July 16, 2026 00:55 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000832
Version ID CA-V-004953
SHA-256 f24454a79c9ebf50546fbadf74a477d37b7ebb4e90d448f8ed765178c245b62a
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans