Does Cursor train on your data?
With Privacy Mode off, Cursor trains on your codebase, prompts and editor actions. The switch is free on every plan — but you have to find it.
A self-serve opt-out exists
"If you choose to turn off "Privacy Mode": we may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models."
- 23 Sept 2026
- 5 Oct 2026
- All plans (free and Pro)
- global
- Fetched from the company
- AD25A417…7714
How we read it: What gets used is unusually broad and unusually clearly stated: codebase data, prompts, editor actions and code snippets. Turning Privacy Mode on stops all of it, and Cursor's security page says the setting is "available to anyone (free or Pro)" — so no privacy paywall. Two caveats hold this at D. First, the privacy policy answers nothing itself; it forwards to this Privacy Overview and does not even link it. Second, neither document states which way Privacy Mode ships: this page says both "if you enable" and "if you choose to turn off". Default-off is read from that framing plus the security page's "can be enabled", not from an explicit statement, and it is the weakest link in this grade.
opt out, opt-out, object to, settings, toggle, turn off, disable, by default
What the document does offer
- on the privacy overview: "If you enable 'Privacy Mode' in Cursor's settings: Customer Data will not be used for training by Cursor" — a named, free setting
- the inverse, quoted as this tier's clause: "If you choose to turn off 'Privacy Mode': we may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models"
- "All cached file contents are temporary, never permanently stored, and never used as training data when privacy mode is enabled"
- "Non-ZDR models will be designated as such or require an admin to opt-in to enable the model for your workspace"
- "default" appears zero times, in the 2,237-character privacy overview and in the 15,494-character full policy alike
Why none of it applies: The switch is real, free, named and in settings, which is the C shape — but neither document says which way it ships. "default" appears nowhere in either, and every sentence is framed as what happens if you enable or turn off Privacy Mode, which is how you write about a setting whose starting state you are not stating. D on the same rule as Figma and Wispr Flow: a reader of the published pages cannot learn whether they are already opted in.
What each plan can refuse
The same questions, asked of every plan we could identify. Every cell comes from a quoted clause or a documented search - see the evidence above.
- Self-serve toggle
- Not stated
- 53 / 100
- Not stated
- Unknown
How to opt out of Cursor AI training
Plan by plan, from what Cursor's own policy says about refusing. Where it publishes the steps, they're listed here with the limits they carry. Where there's nothing to switch off, or nothing graded, this says so instead of inventing a menu path.
All plans (free and Pro)
Yes. Cursor has a self-serve setting.
- Open Cursor Settings: Cmd+Shift+J on a Mac, Ctrl+Shift+J on Windows or Linux.
- Click General in the sidebar.
- Turn Privacy Mode on.
The switch runs the other way here: Privacy Mode ON is the opt-out. Cursor states no default for individual accounts.
What this policy has done since we started watching
1 change detected since 14 Aug 2026. Each one is a diff between two archived copies, and each links to the passage that moved.
Everything we read
Vendor response
We wrote to Cursor on 20 Aug 2026, quoting the clauses above and inviting a correction. Nothing has come back. That's published because a company declining to comment on its own policy is something a reader should know, and because the invitation should be on the record whether or not it's taken up. Any reply goes here, word for word.
Report a wrong clause