Provision record
Cursor · Cursor Terms of Service · View original document ↗

Prohibition on Regulated Data Submission

High severity Common · 282 of 352 platforms
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The restriction establishes a contractual boundary on data categories the service will process, allocating responsibility to users to identify and exclude regulated data streams before submission. This operates as a protective measure defining the scope of data Anysphere accepts under its stated security and compliance posture.

Clause Stability Stable

0
Changes
3
Months Monitored
Apr 30, 2026
First Seen
Apr 30, 2026
Last Seen
This clause type exists across 4244 other provisions on other platforms.

Consumer impact (what this means for users)

Users are required to independently identify and withhold submission of health information, payment card data, financial account information, and other data subject to industry-specific regulatory regimes before providing content to the service. Submitting such data in violation of this restriction constitutes a breach of the terms.

How other platforms handle this

Tinder Medium

You may not display any personal contact, banking, or peer-to-peer payment information, whether in relation to you or any other person (for example, names, home addresses or postcodes, telephone numbers, email addresses, URLs, credit/debit card...)

ActiveCampaign Medium

Bypass or ignore instructions contained in our robots.txt file that controls automated access to portions of our Services;

Mailchimp Medium

Send content created in Mailchimp through another service.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
you may not: ... (x) send or otherwise provide to Anysphere data or information that is subject to specific protections under applicable laws beyond any requirements that apply to "personal information" or "personal data" generally, such as for illustrative purposes, information that is regulated by the Health Insurance Portability and Accountability Act, the Payment Card Industry Data Security Standard, the Gramm-Leach-Bliley Act, and other U.S. federal, state or foreign laws applying specific security standards

Excerpt from Cursor's Terms of Service

Applicable regulations

CFAA
United States Federal
Trump Executive Order on AI Policy Framework
US

Provision details

Document information
Document
Cursor Terms of Service
Entity
Cursor
Document last updated
May 5, 2026
Tracking information
First tracked
April 30, 2026
Last verified
May 12, 2026
Record ID
CA-P-004343
Document ID
CA-D-00453
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
43f1d1b81f2bbb689af2a3a9e66bd45d4b0226b8fabfcd5adee69e1049877d90
Analysis generated
April 30, 2026 08:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cursor
Document: Cursor Terms of Service
Record ID: CA-P-004343
Captured: 2026-04-30 08:53:33 UTC
SHA-256: 43f1d1b81f2bbb68…
URL: https://conductatlas.com/platform/cursor/cursor-terms-of-service/provision/CA-P-004343/prohibition-on-regulated-data-submission/
Accessed: Aug. 6, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Cursor's Prohibition on Regulated Data Submission clause do?

The restriction establishes a contractual boundary on data categories the service will process, allocating responsibility to users to identify and exclude regulated data streams before submission. This operates as a protective measure defining the scope of data Anysphere accepts under its stated security and compliance posture.

How does this clause affect you?

Users are required to independently identify and withhold submission of health information, payment card data, financial account information, and other data subject to industry-specific regulatory regimes before providing content to the service. Submitting such data in violation of this restriction constitutes a breach of the terms.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 282 platforms. See the full comparison.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.