Cursor
- Your data trains their AI only if you opt in.
- The policy rules out using your data for targeted ads.
- Data is shared only with the providers who run the service.
- The policy describes staff access for safety and legal checks.
You own your code; they say they do not train on it unless you opt in, but they can close you anytime and cap .
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account and payment info, your prompts and code, plus device, logs, cookies, and IP location.
Read the exact line
Privacy policy
“We collect information about your use of the Service, such as the dates and times of access, browsing history, search, information about the links you click, pages you view”
Training
They say they do not train on your chats unless you agree, report them, or they are flagged for security.
Read the exact line
Privacy policy
“We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review”
Sharing
Vendors, affiliates, and your employer if you use a work email; they say they do not sell for ads.
Read the exact line
Privacy policy
“We may disclose personal data to third-party vendors and service providers who support our business operations and help us deliver and improve the Service.”
Kept
They keep data as long as they think they need it; no clear delete-in-app deadline.
Read the exact line
Privacy policy
“Anysphere retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements.”
Controls
You can email hi@cursor.com to access or delete data and manage training preferences in the app.
Read the exact line
Privacy policy
“To exercise any of these rights, you or your authorized agent may contact us at hi@cursor.com.”
Fine print
They can cut off access without notice, fees are usually non-refundable, and you must cover their legal costs.
Read the exact line
Terms of service
“We reserve the right to modify, suspend, or discontinue the Services or your access to the Services, in whole or in part, at any time without notice to you.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Manage training preferences in the Service
Instructions in the Service on how to manage preferences regarding Inputs and Suggestions for training
Request access or deletion of personal data
Email hi@cursor.com
Cancel a subscription at least 24 hours before renewal
Cancellation in your billing menu or hi@cursor.com
Opt out of promotional emails
Unsubscribe link in promotional emails
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
If someone sues them over how you used Cursor, you may have to pay their legal bills.
Read the exact line
Terms of service
“you will defend and Anysphere, its affiliates and each of their respective shareholders, directors, managers, members, officers, employees, consultants, and agents”
For example, if a company claims your pasted code was stolen and sues Cursor, you could be on the hook for their lawyers.
They can shut off your account or the product without warning.
Read the exact line
Terms of service
“We reserve the right to modify, suspend, or discontinue the Services or your access to the Services, in whole or in part, at any time without notice to you.”
For example, you could lose access to a paid project overnight with no email first.
Paid plans generally do not get money back.
Read the exact line
Terms of service
“Unless otherwise specifically provided for in these Terms, all fees are in U.S. Dollars and are non-refundable, except as required by law.”
For example, if you cancel a yearly plan after a week, they may keep the full payment unless the law says otherwise.
If they mess up, they usually owe you at most six months of fees or $100.
Read the exact line
Terms of service
“THE OF THE ANYSPHERE ENTITIES TO YOU FOR ALL CLAIMS, DAMAGES AND LOSSES ARISING OUT OF OR RELATING TO THESE TERMS, THE SERVICE, AND CONTENT, WHETHER IN CONTRACT, TORT, OR OTHERWISE, IS LIMITED TO THE GREATER OF: (A) THE AMOUNT YOU HAVE PAID TO ANYSPHERE FOR ACCESS TO AND USE OF THE SERVICE IN THE SIX (6) MONTHS PRIOR”
For example, if a bug wipes a repo and costs you thousands, their contract still caps most payouts at a small amount.
Training is off unless you opt in, but security-flagged chats and feedback can still be used.
Read the exact line
Privacy policy
“We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review (in which case we may analyze them to improve our ability to detect and enforce our Terms of Service), (2) you explicitly report them to us (for example, as Feedback), or (3) you’ve explicitly agreed to their use for such training purposes.”
For example, a prompt they think broke the rules could still be studied to improve filters even if you never turned training on.
You keep rights in what you type, and they assign you rights in the AI’s output.
Read the exact line
Terms of service
“You retain all of your right, title, and interest that you have in Inputs, and Anysphere hereby assigns to you all of our right, title, and interest if any in and to any Suggestions.”
For example, code Cursor writes for you is treated as yours, not Cursor’s product.
They say they do not sell your data for ad targeting across other sites.
Read the exact line
Privacy policy
“We do not “sell” or “share” personal data for cross-contextual behavioral advertising, and we do not process personal data for “targeted advertising” purposes”
For example, they claim they will not build an ad profile from your coding sessions to show you ads elsewhere.
You cannot join a ; you must sue alone in Texas courts.
Read the exact line
Terms of service
“YOU AND ANYSPHERE AGREE THAT EACH OF US MAY BRING CLAIMS AGAINST THE OTHER ONLY ON AN INDIVIDUAL BASIS AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED OR PROCEEDING.”
For example, if many users were overcharged, you could not join them in one lawsuit.
A work email can let your company see that you have an account.
Read the exact line
Privacy policy
“If you create an account using an email associated with an organization (e.g., your employer), we may disclose account-related information (such as your email address and account status) to that organization.”
For example, signing up with you@company.com may let IT see your Cursor account status.
Words to know
Legal words from the lines above, in plain English.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- service providers
- Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
- retention
- How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
- indemnify
- You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
- affiliates
- Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
- limitation of liability
- A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- targeted advertising
- Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
- class action waiver
- You agree not to join with other users in one lawsuit; each person must complain alone. For example, if a bug overcharges a million people, you cannot all sue together for a refund.
How we got here · grade A+ · score 66/100 · 15 of 15 policy answers backed by a verified quote · 1 not stated
What does the app collect beyond what it needs to work?
They collect account and payment data, your Inputs, plus device, logs, cookies, usage, and IP-based location.
Does it record your voice, face or body, and what happens to that?
They say they do not knowingly collect biometric data used to uniquely identify a person.
Are your chats and uploads used to train AI models, and is that off by default?
They say they will not train on your Content unless you explicitly agree, with extra use of security-flagged items and Feedback.
Can employees or contractors read your conversations, and when?
They describe analyzing Inputs flagged for security review to enforce the terms, not routine sampling of all chats.
Are you profiled or tracked for advertising?
They say they do not sell or share for cross-context ads and do not process data for targeted advertising.
Do they sell or share your data, and can you opt out?
They share with service providers, affiliates, and in legal or corporate deals; they say they do not sell for ads.
What rights do they take over what you type and what the AI makes?
You keep rights in Inputs and they assign you any rights they have in Suggestions.
How long do they keep your data after you delete it, and can you delete it in the app?
Deletion is by contacting them; they keep data as long as they say they need it, with no 30- or 90-day in-app promise.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe commercially reasonable technical and organizational measures, with no audit or VDP named.
Is there a real age gate, and are teens protected?
You must be 18 or the age of majority, by your own representation; they say they do not target children under 18.
Will they tell you when the rules change, and is the policy specific?
They post an updated date; continued use counts as accepting the new privacy policy and terms.
Can they close your account without warning, and can you get your data out first?
They may suspend access without notice and may delete Content tied to your account when it ends.
If something goes wrong, who pays?
The service is as-is with a low liability cap, and you must indemnify them for several kinds of claims.
Do subscriptions renew on their own, and can you get a refund?
Subscriptions auto-renew; cancel at least 24 hours before renewal; fees are non-refundable except as required by law.
The privacy policy is 2,373 words at a college graduate level (Flesch reading ease 37.2); the terms are 4,828 words at a college level.