Skip to content

Security changed Cursor, Jul 1, 2025

Cursor · Jul 1, 2025 · 6 added, 6 removed · found in an Internet Archive capture

  1. Added: We use Cloudflare as a reverse proxy in front of parts of our API and website in order to improve performance and security.
  2. Added: We use Mistral to parse public PDFs found on the internet. No private data reaches Mistral (unless you manually use a Mistral model with your own API key).
  3. Added: ' marketplace.cursorapi.com ' , ' cursor-cdn.com ' , ' downloads.cursor.com ' , ' anysphere-binaries.s3.us-east-1.amazonaws.com ' : Used for client updates and for downloading extensions from the extension marketplace.
  4. Removed: ' marketplace.cursorapi.com ' , ' cursor-cdn.com ' : Used for downloading extensions from the extension marketplace.
  5. Removed: You own all the code generated by Cursor.
  6. Added: Privacy mode can be enabled in settings or by a team admin. When it is enabled, we guarantee that code data is never stored by our model providers or used for training. Privacy mode can be enabled by anyone (free or Pro user), and is by default forcibly enabled for any user that is a member of a team.
  7. Added: We take the privacy mode guarantee very seriously. More than 50% of all Cursor users have privacy mode enabled.
  8. Added: Each request to our server includes an ' x-ghost-mode ' header, containing a boolean value denoting if the user is on privacy mode. To prevent accidentally treating a privacy mode user as a non-privacy mode user, we always default to assuming that a user is on privacy mode if the header is missing.
  9. Removed: Privacy mode can be enabled during onboarding or in settings. When it is enabled, we guarantee that code data is not stored in plaintext at our servers or by our subprocessors. Privacy mode can be enabled by anyone (free or Pro user), and is by default forcibly enabled for any user that is a member of a team.
  10. Removed: We take the privacy mode guarantee very seriously. About 50% of all Cursor users have privacy mode enabled. You can read more about the privacy guarantee in our Privacy Policy .
  11. Removed: With privacy mode enabled, code data is not persisted at our servers or by any of our subprocessors. The code data is still visible to our servers in memory for the lifetime of the request, and may exist for a slightly longer period (on the order of minutes to hours) for long-running background jobs, KV caching, or temporary file caching. For file caching specifically, all data is encrypted with client-generated keys that are only retained for the duration of the request. The code data submitted by privacy mode users will never be trained on.
  12. Removed: A user's privacy mode setting is stored on the client. Each request to our server includes an ' x-ghost-mode ' header. To prevent accidentally treating a privacy mode user as a non-privacy mode user, we always default to assuming that a user is on privacy mode if the header is missing.
About this change
Page
cursor.com/security
Kind
Documentation
Text hash
d15ddf28fa53 to 6aca484250d6
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.