This is Cursor's legal agreement governing your use of its AI-powered coding assistant, covering how your code inputs are used, how you're billed, and what rights you have when things go wrong. The single most important thing to know is that your subscription auto-renews automatically and all fees are non-refundable — you must cancel at least 24 hours before your renewal date or you will be charged for the next full period. Do not submit any health, payment card, or financial account data to Cursor — the terms explicitly prohibit it and shift all liability to you if you do.
This document constitutes the Terms of Service for Anysphere, Inc.'s Cursor software platform, governing access to and use of its AI-powered coding tools, APIs, documentation, and related services, on a clickwrap contractual basis effective January 13, 2026. The most significant obligations include: users bear sole responsibility for evaluating and acting upon AI-generated code Suggestions; subscription fees auto-renew and are non-refundable; users must cancel at least 24 hours before renewal to avoid charges; and Anysphere retains broad rights to modify, suspend, or terminate service without notice. Notable deviations from industry standard include an explicit prohibition on submitting HIPAA, PCI DSS, and GLBA-regulated data to the platform, a blanket disclaimer of liability for paid-for functionalities modified or discontinued, mandatory binding arbitration with class action waiver (likely in surviving sections 13–17, partially truncated), and user assumption of all risk for auto-executing code without review. The document engages CCPA/CPRA (California consumer privacy rights), GDPR (for EU/EEA users referenced in the Privacy Policy cross-reference), COPPA (age eligibility set to 18+), FTC Act Section 5 (unfair/deceptive practices in auto-renewal and modification notices), and potentially the EU AI Act given the AI model-generated output disclosures. Material compliance considerations include the explicit exclusion of HIPAA/PCI/GLBA data from permissible inputs, creating significant liability for enterprise users who inadvertently submit regulated data, and the Stripe payment integration subjecting users to a separate third-party agreement that Stripe may modify unilaterally.
🔒 Institutional analysis locked
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Upgrade to Professional — $149/moCross-platform context
See how other platforms handle Account Deletion for Non-Payment and similar clauses.
Compare across platforms →