FinanceGadget
Review

Is it safe to put client code into Cursor?

Desk research only

This app has not yet been installed and tested. Treat the record below as provisional.

Cursor

Free and Pro, individual · tested 10 Aug 2026
Input retention
No period stated. The privacy policy says data is retained 'only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements'. No figure is given for any data category.
Used for training
Committed against, with three named exceptions: 'We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review... (2) you explicitly report them to us... or (3) you've explicitly agreed to their use for such training purposes.'
Opt-out
Privacy Mode — 'When enabled, we will not train on your data.' Documented on the security page and available to free and Pro users. Not mentioned anywhere in the privacy policy read on this date.
Sub-processors
Not named in the privacy policy, which lists only categories: 'third-party hosting, cloud infrastructure, model, analytics, customer support, safety monitoring, communications, payment processing, compliance services, and IT providers'. A named list is published at trust.cursor.com/subprocessors for commercial accounts.
Consumer vs business
Privacy Mode is stated to be available to free and Pro users alike. The privacy policy does not differentiate training practices by plan.
Provider
Anysphere, Inc.
Jurisdiction
United States — servers 'located in various jurisdictions, including in the United States'
Data residency
Not stated. The security page says only that Cursor 'does not use or maintain any infrastructure in China'. Inference location is not specified.
Known incidents
None found in primary sources during this pass, 10 Aug 2026
Proceed with caution

Anysphere commits not to train on inputs, with three named exceptions. But the privacy policy states no retention period at all, and Privacy Mode — the control users rely on — appears on the security page and not in the policy.

The short answer

Cursor’s training commitment is clearer than most: Anysphere states plainly that it does not use your inputs or suggestions to train models, and does not let third parties do so, subject to three named exceptions. That is a stronger default than several competitors offer.

The gap is retention. The privacy policy read on this date states no retention period for anything — not for inputs, not for suggestions, not for logs. It commits only to keeping data “as long as necessary”. For work under an NDA, “how long do you keep my client’s code” is a question this document does not answer.

The two-document problem

This is the finding worth carrying away, and it is structural rather than sinister.

Privacy Mode is the control Cursor users actually rely on. It is documented on the security page, last updated 24 April 2026, which says: “When enabled, we will not train on your data,” and notes that Cursor also implements “technical controls and contractual requirements with our model providers to protect your data.”

The privacy policy, last updated 6 October 2025, does not mention Privacy Mode at all. The term appears nowhere in it.

Both documents are real, both are published by the same company, and they are not in conflict — the policy’s training clause and the security page’s Privacy Mode describe compatible positions. But the security page is a marketing-adjacent surface that can be edited at any time, and the privacy policy is the document with legal weight. A commitment that lives only on the former is a weaker commitment than one written into the latter, and the eighteen-month gap between their update dates is itself informative.

If you need Privacy Mode’s guarantee to be contractual rather than descriptive, that is a question for Anysphere’s commercial terms, not for either of these pages.

What the training clause actually says

Quoted in full from the privacy policy, because the exceptions are the substance:

We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review (in which case we may analyze them to improve our ability to detect and enforce our Terms of Service), (2) you explicitly report them to us (for example, as Feedback), or (3) you’ve explicitly agreed to their use for such training purposes.

Exceptions two and three are consent-based and unobjectionable. Exception one is the one to understand: content flagged for security review may be analysed, and you are not told when flagging occurs. This is the same abuse-monitoring carve-out that appears across the industry in different words, and it is the reason “we don’t train on your data” and “nobody at this company will ever look at your data” are different sentences. How to get a DPA for an AI tool covers the five questions that pin this down for any provider.

Where the data goes

Anysphere, Inc. is a United States company, and the policy states data may be processed on “servers located in various jurisdictions, including in the United States”.

For EEA users the policy says: “when you access our Service, your personal data may be transferred to our United States servers to other countries outside the EEA and the UK. Where information is transferred outside the EEA or the UK, we require an adequate level of data protection.”

Two things are worth noting about that. It asserts an adequate level of protection without naming the mechanism — standard contractual clauses, an adequacy decision, or the EU-US Data Privacy Framework are not identified in the policy text read here. And no data residency option is described anywhere; the only geographic commitment found was the security page’s statement that Cursor “does not use or maintain any infrastructure in China”.

If EU data residency is a requirement for you, this record does not establish that Cursor offers it. See EU data residency for AI: inference or storage? for why that distinction matters more than the headline claim.

Sub-processors, and who is missing from the list

The privacy policy names no sub-processors. It lists categories — “third-party hosting, cloud infrastructure, model, analytics, customer support, safety monitoring, communications, payment processing, compliance services, and IT providers” — and directs commercial accounts to a named list at trust.cursor.com/subprocessors.

The category doing the most work there is model. Cursor is a client over frontier models it does not train, which means your code reaches at least one other company whose own terms govern what happens next. The privacy policy read here does not name which. For anyone assessing this under a client contract, the identity of that downstream provider is not an optional detail, and it is the first thing to ask for.

A SOC 2 Type II attestation report is stated to be available on request at trust.cursor.com, and the security page commits to “at-least-annual penetration testing by reputable third parties”. Both are meaningful signals — see “bank-level security” and other claims that mean nothing for why a report available on request beats a badge.

What to change today

  1. Turn Privacy Mode on. It is available on free and Pro plans and it is the control the training commitment is built around.
  2. Ask for the sub-processor list before putting client code in, and confirm which model provider serves your requests. This is the gap in the public documentation.
  3. Ask for a stated retention period in writing. The public policy gives none. Under an NDA, that answer needs to exist somewhere you can point to.
  4. Configure ignore rules before opening a client repository, using the IDE ignore file generator, and test that they took effect rather than assuming — the canary method is in how to stop secrets leaking into an AI assistant.
  5. If you need contractual rather than descriptive commitments, that means a commercial agreement and a DPA, not the consumer plans assessed here.

What this record is, and is not

This is desk research read on 10 August 2026 against Anysphere’s own published privacy policy and security page. The app has not been installed, no traffic has been observed, and the page carries a “desk research only” badge for that reason.

Everything above is what Cursor says about itself. Whether the client behaves that way on the wire is a separate question requiring a hands-on test, and that test has not happened.

Two dates matter for how long this page stays true: the privacy policy was last updated 6 October 2025 and the security page 24 April 2026. Providers revise these quietly. If you are reading this well after publication, re-check both before relying on it — and tell me if something has moved, which gets fixed with the change noted.