232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE
RECORD OPENED 5 OCT 2026 · 1 CLAUSES ON FILE
dev

Does Cursor train on your data?

With Privacy Mode off, Cursor trains on your codebase, prompts and editor actions. The switch is free on every plan — but you have to find it.

LAST CHECKED
5 Oct 2026 · 5 days ago
CONFIDENCE
high
RIGHT OF REPLY
Asked · no reply
Verdict
D
Trains on you by default
A self-serve opt-out exists

Evidence 1 — All plans (free and Pro)
AI Addendum · All plans (free and Pro)
EVIDENCE 01 OF 01
"If you choose to turn off "Privacy Mode": we may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models."
CHECKED
23 Sept 2026
STILL LIVE AS OF
5 Oct 2026
APPLIES TO
All plans (free and Pro)
JURISDICTION
global
HOW IT WAS TAKEN
Fetched from the company
SHA-256
AD25A417…7714

How we read it: What gets used is unusually broad and unusually clearly stated: codebase data, prompts, editor actions and code snippets. Turning Privacy Mode on stops all of it, and Cursor's security page says the setting is "available to anyone (free or Pro)" — so no privacy paywall. Two caveats hold this at D. First, the privacy policy answers nothing itself; it forwards to this Privacy Overview and does not even link it. Second, neither document states which way Privacy Mode ships: this page says both "if you enable" and "if you choose to turn off". Default-off is read from that framing plus the security page's "can be enabled", not from an explicit statement, and it is the weakest link in this grade.

CONTROLS SEARCHED FOR · 24 Aug 2026

opt out, opt-out, object to, settings, toggle, turn off, disable, by default

What the document does offer

  • on the privacy overview: "If you enable 'Privacy Mode' in Cursor's settings: Customer Data will not be used for training by Cursor" — a named, free setting
  • the inverse, quoted as this tier's clause: "If you choose to turn off 'Privacy Mode': we may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models"
  • "All cached file contents are temporary, never permanently stored, and never used as training data when privacy mode is enabled"
  • "Non-ZDR models will be designated as such or require an admin to opt-in to enable the model for your workspace"
  • "default" appears zero times, in the 2,237-character privacy overview and in the 15,494-character full policy alike

Why none of it applies: The switch is real, free, named and in settings, which is the C shape — but neither document says which way it ships. "default" appears nowhere in either, and every sentence is framed as what happens if you enable or turn off Privacy Mode, which is how you write about a setting whose starting state you are not stating. D on the same rule as Figma and Wispr Flow: a reader of the published pages cannot learn whether they are already opted in.

What each plan can refuse

The same questions, asked of every plan we could identify. Every cell comes from a quoted clause or a documented search - see the evidence above.

All plans (free and Pro)TRAINS: YES
OPT-OUT
Self-serve toggle
RETENTION
Not stated
EXPOSURE
53 / 100
DE-IDENTIFIED
Not stated
HUMAN REVIEW
Unknown

How to opt out of Cursor AI training

Plan by plan, from what Cursor's own policy says about refusing. Where it publishes the steps, they're listed here with the limits they carry. Where there's nothing to switch off, or nothing graded, this says so instead of inventing a menu path.

All plans (free and Pro)

Yes. Cursor has a self-serve setting.

Cursor Settings
  1. Open Cursor Settings: Cmd+Shift+J on a Mac, Ctrl+Shift+J on Windows or Linux.
  2. Click General in the sidebar.
  3. Turn Privacy Mode on.

The switch runs the other way here: Privacy Mode ON is the opt-out. Cursor states no default for individual accounts.

Each step's source and archived copy →

What this policy has done since we started watching

5 CAPTURES SINCE 14 AUG 2026

1 change detected since 14 Aug 2026. Each one is a diff between two archived copies, and each links to the passage that moved.

  1. MinorTouched retention and plan tiers. Not yet reviewed by a human.

Everything we read

DOCUMENT
CHECKED
SNAPSHOT
AI Addendum
5 Sept 2026
Privacy Policy
1 Oct 2026
AI Addendumquoted
23 Sept 2026
Security Page
1 Sept 2026

Vendor response

From the company? What a reply does and what moves a grade.

We wrote to Cursor on 20 Aug 2026, quoting the clauses above and inviting a correction. Nothing has come back. That's published because a company declining to comment on its own policy is something a reader should know, and because the invitation should be on the record whether or not it's taken up. Any reply goes here, word for word.

Report a wrong clause

Compared with GitHub, Windsurf (Codeium) and JetBrains · Writing about Cursor? Embed this verdict as a card that stays current.