This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The restriction establishes a contractual boundary on data categories the service will process, allocating responsibility to users to identify and exclude regulated data streams before submission. This operates as a protective measure defining the scope of data Anysphere accepts under its stated security and compliance posture.
Users are required to independently identify and withhold submission of health information, payment card data, financial account information, and other data subject to industry-specific regulatory regimes before providing content to the service. Submitting such data in violation of this restriction constitutes a breach of the terms.
How other platforms handle this
You may not display any personal contact, banking, or peer-to-peer payment information, whether in relation to you or any other person (for example, names, home addresses or postcodes, telephone numbers, email addresses, URLs, credit/debit card...)
Bypass or ignore instructions contained in our robots.txt file that controls automated access to portions of our Services;
Send content created in Mailchimp through another service.
"you may not: ... (x) send or otherwise provide to Anysphere data or information that is subject to specific protections under applicable laws beyond any requirements that apply to "personal information" or "personal data" generally, such as for illustrative purposes, information that is regulated by the Health Insurance Portability and Accountability Act, the Payment Card Industry Data Security Standard, the Gramm-Leach-Bliley Act, and other U.S. federal, state or foreign laws applying specific security standardsExcerpt from Cursor's Terms of Service
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The restriction establishes a contractual boundary on data categories the service will process, allocating responsibility to users to identify and exclude regulated data streams before submission. This operates as a protective measure defining the scope of data Anysphere accepts under its stated security and compliance posture.
Users are required to independently identify and withhold submission of health information, payment card data, financial account information, and other data subject to industry-specific regulatory regimes before providing content to the service. Submitting such data in violation of this restriction constitutes a breach of the terms.
ConductAtlas has identified this type of provision across 282 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.