Cursor

Cursor · Coding agent · US · cursor.com

Last verified 2026-09-16
Entry services/cursor.yaml
Training on your data (default tier)
Inputs and suggestions not used for training unless flagged, reported, or explicitly agreed
Retention
As long as necessary to operate the Service; no fixed period stated
Data residency
Servers in various jurisdictions including the United States; EEA data may be transferred to the US

Vendor data-handling terms

Training on your data (default tier)
Inputs and suggestions not used for training unless flagged, reported, or explicitly agreed

Privacy Mode preferences in the app control whether inputs may be used; the policy's default statement excludes training with three exceptions.

We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review (in which case we may analyze them to improve our ability to detect and enforce our Terms of Service ), (2) you explicitly report them to us (for example, as Feedback), or (3) you’ve explicitly agreed to their use for such training purposes.
checked 2026-09-16
Anysphere (Cursor) Privacy Policy
Retention
As long as necessary to operate the Service; no fixed period stated
Anysphere retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements.
checked 2026-09-16
Anysphere (Cursor) Privacy Policy, Retention
Data residency
Servers in various jurisdictions including the United States; EEA data may be transferred to the US
Anysphere processes your personal data for the purposes described in this Privacy Policy on servers located in various jurisdictions, including in the United States. / For users in the European Economic Area, (“EEA”), when you access our Service, your personal data may be transferred to our United States servers to other countries outside the EEA and the UK.
checked 2026-09-16
Anysphere (Cursor) Privacy Policy, International transfers

Domains and endpoints

observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.

HostRoleSource
cursor.comappobserved
cursor.shappobserved

Assessment

All plans: medium

Reasoning: Training on code and prompts is excluded by default with narrow exceptions, which is better than most consumer assistants. The exposure is what a coding agent reads: with tool servers attached it sees repositories, credentials in config files, and whatever the developer's account can reach, and that content is processed on US servers with no fixed retention period stated. The sandbox-escape flaws disclosed in 2026 (CVE-2026-50548, CVE-2026-50549) are fixed in Cursor 3.0; earlier versions remain exposed.

Flags: GDPR Chapter V (US processing of EEA data) · Agent tool access (MCP servers run with the developer's credentials) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.

Changelog

  • 2026-09-16Documented. Training, retention, and transfer terms verified against the Anysphere privacy policy.
  • 2026-09-15Listed from the Unseen catalogue with observed domains.

Corrections

Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.

Edit on GitHub