Provision record
Cursor · Cursor Terms of Service · View original document ↗

Regulated Data Submission Prohibition

High severity High confidence Explicit document language Common · 282 of 352 platforms
Stay ahead of the changes
Track Cursor and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what Cursor's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The clause establishes a categorical restriction on the types of regulated information that may be processed through the service, requiring users to maintain compliance responsibility for data subject to sector-specific security regimes that impose obligations exceeding the service's standard data handling practices.

Clause Stability Stable

0
Changes
3
Months Monitored
May 9, 2026
First Seen
May 11, 2026
Last Seen
This clause type exists across 4244 other provisions on other platforms.

Consumer impact (what this means for users)

Users are contractually obligated to exclude regulated data categories from submission to the service. This mechanism places responsibility on users to identify and withhold data classified under heightened protection regimes (health information, payment card data, financial records, etc.) rather than relying on Anysphere's processing infrastructure for such information.

How other platforms handle this

Tinder Medium

You may not display any personal contact, banking, or peer-to-peer payment information, whether in relation to you or any other person (for example, names, home addresses or postcodes, telephone numbers, email addresses, URLs, credit/debit card...)

ActiveCampaign Medium

Bypass or ignore instructions contained in our robots.txt file that controls automated access to portions of our Services;

Mailchimp Medium

Send content created in Mailchimp through another service.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
(x) send or otherwise provide to Anysphere data or information that is subject to specific protections under applicable laws beyond any requirements that apply to "personal information" or "personal data" generally, such as for illustrative purposes, information that is regulated by the Health Insurance Portability and Accountability Act, the Payment Card Industry Data Security Standard, the Gramm-Leach-Bliley Act, and other U.S. federal, state or foreign laws applying specific security standards

Excerpt from Cursor's Terms of Service

Applicable regulations

CFAA
United States Federal
Trump Executive Order on AI Policy Framework
US

Provision details

Document information
Document
Cursor Terms of Service
Entity
Cursor
Document last updated
May 5, 2026
Tracking information
First tracked
April 30, 2026
Last verified
May 12, 2026
Record ID
CA-P-007793
Document ID
CA-D-00453
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
43f1d1b81f2bbb689af2a3a9e66bd45d4b0226b8fabfcd5adee69e1049877d90
Analysis generated
April 30, 2026 08:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cursor
Document: Cursor Terms of Service
Record ID: CA-P-007793
Captured: 2026-04-30 08:53:33 UTC
SHA-256: 43f1d1b81f2bbb68…
URL: https://conductatlas.com/platform/cursor/cursor-terms-of-service/provision/CA-P-007793/regulated-data-submission-prohibition/
Accessed: Aug. 7, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Cursor's Regulated Data Submission Prohibition clause do?

The clause establishes a categorical restriction on the types of regulated information that may be processed through the service, requiring users to maintain compliance responsibility for data subject to sector-specific security regimes that impose obligations exceeding the service's standard data handling practices.

How does this clause affect you?

Users are contractually obligated to exclude regulated data categories from submission to the service. This mechanism places responsibility on users to identify and withhold data classified under heightened protection regimes (health information, payment card data, financial records, etc.) rather than relying on Anysphere's processing infrastructure for such information.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 282 platforms. See the full comparison.

Is ConductAtlas affiliated with Cursor?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cursor.