Skip to content

Security changed Cursor, Jan 1, 2026

Cursor · Jan 1, 2026 · 19 added, 42 removed · found in an Internet Archive capture

  1. Added: Please submit potential vulnerabilities via email to security-reports@cursor.com .
  2. Removed: Please submit potential vulnerabilities to our GitHub Security page .
  3. Added: We depend on the following subprocessors, roughly organized from most critical to least. Note that code data is sent up to our servers to power all of Cursor's AI features (see AI Requests section ), and that code data for users on privacy mode (legacy) is never persisted (see Privacy Mode Guarantee section).
  4. Added: Explore how each mode affects how data is sent and stored:
  5. Removed: We depend on the following subprocessors, roughly organized from most critical to least. Note that code data is sent up to our servers to power all of Cursor's AI features (see AI Requests section ), and that code data for users on privacy mode is never persisted (see Privacy Mode Guarantee section).
  6. Added: AWS Sees and stores code data : Our infrastructure is primarily hosted on AWS, with all servers located in the US.
  7. Added: Cloudflare Sees code data : We use Cloudflare as a reverse proxy in front of parts of our API and website in order to improve performance and security.
  8. Added: Microsoft Azure Sees code data : Some secondary infrastructure is hosted on Microsoft Azure. All of our Azure servers are in the US.
  9. Added: Google Cloud Platform (GCP) Sees code data : Some secondary infrastructure is hosted on Google Cloud Platform (GCP). All of our GCP servers are in the US.
  10. Added: Fireworks Sees code data : Our custom models are hosted with Fireworks, on servers in the US, Europe, or Japan. We have a zero data retention agreement with Fireworks for users in Privacy Mode and Privacy Mode (Legacy). For Share Data users, Fireworks may temporarily access and store model inputs and outputs to improve our inference performance, for the minimum duration required to perform such tasks, after which it is securely deleted. Fireworks does not reuse the data for any other purpose.
  11. Added: Baseten Sees code data : Our custom models are hosted with Baseten, on servers in the US and Canada. We have a zero data retention agreement with Baseten for users in Privacy Mode and Privacy Mode (Legacy). For Share Data users, Baseten may temporarily access and store model inputs and outputs to improve our inference performance, for the minimum duration required to perform such tasks, after which it is securely deleted. Baseten does not reuse the data for any other purpose.
  12. Added: Together Sees code data : Our custom models are hosted with Together, on servers in the US. We have a zero data retention agreement with Together for users in Privacy Mode and Privacy Mode (Legacy). For Share Data users, Together may temporarily access and store model inputs and outputs to improve our inference performance, for the minimum duration required to perform such tasks, after which it is securely deleted. Together does not reuse the data for any other purpose.
  13. Added: OpenAI Sees code data : We rely on OpenAI's models to provide AI responses. In Privacy Mode and Privacy Mode (Legacy), we have a zero data retention agreement with OpenAI. Additionally, requests may be sent to OpenAI for certain background or summarization tasks with zero data retention, regardless of which model provider you have selected*. For users that created their account after October 15, 2025, in Share Data mode, prompts and limited telemetry may also be shared with OpenAI when directly using their models.
  14. Added: Anthropic Sees code data : We rely on many of Anthropic's models to give AI responses. Additionally, requests may be sent to Anthropic for certain background or summarization tasks with zero data retention, regardless of which model provider you have selected*. We have a zero data retention agreement with Anthropic.
  15. Added: Google Cloud Vertex API Sees code data : We rely on some Gemini models offered over Google Cloud's Vertex API to give AI responses. Requests may be sent to Google Cloud Vertex API for certain background or summarization tasks with zero data retention, regardless of which model provider you have selected*. We have a zero data retention agreement with Vertex.
  16. Added: xAI Sees code data : We rely on some Grok models offered over the xAI API to give AI responses. We have a zero data retention agreement with xAI.
  17. Added: Turbopuffer Stores obfuscated code data : Embeddings of indexed codebases, as well as metadata associated with the embeddings (obfuscated file names), are stored with Turbopuffer on Google Cloud's servers in the US. You can read more on the Turbopuffer security page. Users can disable codebase indexing; read more about it in the Codebase Indexing section of this document.
  18. Added: Exa See search requests (potentially derived from code data) : Used for web search functionality. Search requests are potentially derived from code data (e.g., when using "@web" in the chat, a separate language model will look at your message, conversation history and current file to determine what to search for, and Exa/SerpApi will see the resulting search query).
  19. Added: * Cursor respects model blocklists and will not send any requests to models on a blocklist.
  20. Removed: AWS Sees and stores code data :
  21. Removed: Our infrastructure is primarily hosted on AWS. Most of our servers are in the US, with some latency-critical servers located in AWS regions in (Tokyo) and Europe (London).
  22. Removed: We use Cloudflare as a reverse proxy in front of parts of our API and website in order to improve performance and security.
  23. Removed: Microsoft Azure Sees code data :
  24. Removed: Some secondary infrastructure is hosted on Microsoft Azure. All of our Azure servers are in the US.
  25. Removed: Google Cloud Platform (GCP) Sees code data :
  26. Removed: Some secondary infrastructure is hosted on Google Cloud Platform (GCP). All of our GCP servers are in the US.
  27. Removed: Our custom models are hosted with Fireworks, on servers in the US, Asia (Tokyo), and Europe. Fireworks may store some code data if privacy mode is disabled to speed up inference for our models. We have a zero data retention agreement with Fireworks.
  28. Removed: We rely on many of OpenAI's models to give AI responses. Requests may be sent to OpenAI even if you have an Anthropic (or someone else's) model selected in chat (e.g., for summarization)*. We have a zero data retention agreement with OpenAI.
  29. Removed: We rely on many of Anthropic's models to give AI responses. Requests may be sent to Anthropic even if you have an OpenAI (or someone else's) model selected in chat (e.g., for summarization)*. We have a zero data retention agreement with Anthropic.
  30. Removed: Google Cloud Vertex API Sees code data :
  31. Removed: We rely on some Gemini models offered over Google Cloud's Vertex API to give AI responses. Requests may be sent to Google Cloud Vertex API even if you have an OpenAI (or someone else's) model selected in chat (e.g. for summarization)*. We have a zero data retention agreement with Vertex.
  32. Removed: We rely on some Grok models offered over the xAI API to give AI responses. We have a zero data retention agreement with xAI.
  33. Removed: Turbopuffer Stores obfuscated code data :
  34. Removed: Embeddings of indexed codebases, as well as metadata associated with the embeddings (obfuscated file names), are stored with Turbopuffer on Google Cloud's servers in the US. You can read more on the Turbopuffer security page . Users can disable codebase indexing; read more about it in the Codebase Indexing section of this document.
  35. Removed: Exa See search requests (potentially derived from code data) :
  36. Removed: Used for web search functionality. Search requests are potentially derived from code data (e.g., when using "@web" in the chat, a separate language model will look at your message, conversation history and current file to determine what to search for, and Exa/SerpApi will see the resulting search query).
  37. Removed: SerpApi See search requests (potentially derived from code data) :
  38. Removed: Used for web search functionality. Search requests are potentially derived from code data (e.g. when using "@web" in the chat, a separate language model will look at your message, conversation history and current file to determine what to search for, and Exa/SerpApi will see the resulting search query).
  39. Removed: We use MongoDB for some of our analytics data, for users who do not have privacy mode enabled.
  40. Removed: We use Datadog for logging and monitoring. As discussed in the Privacy Mode Guarantee section, logs related to privacy mode users do not contain any code data.
  41. Removed: Databricks Sees no code data :
  42. Removed: We use Databricks MosaicML for training some of our custom models. Data from privacy mode users never reaches Databricks.
  43. Removed: We use Foundry for training some of our custom models. Data from privacy mode users never reaches Foundry.
  44. Removed: Voltage Park Sees no code data :
  45. Removed: We use Voltage Park for training some of our custom models. Data from privacy mode users never reaches Voltage Park.
  46. Removed: We use Slack as our internal communication tool. We may send snippets of prompts of non-privacy users in our internal chats for debugging.
  47. Removed: Google Workspace Sees no code data :
  48. Removed: We use Google Workspace to collaborate. We may send snippets of prompts of non-privacy users in our internal emails for debugging.
  49. Removed: We use Sentry to monitor errors and performance in our app. Code data is never explicitly sent, but may show up in reported errors. Data from privacy mode users never reaches Sentry.
  50. Removed: We use Mistral to parse public PDFs found on the internet. No private data reaches Mistral (unless you manually use a Mistral model with your own API key).
  51. Removed: Embeddings and metadata of some indexed docs are stored on Pinecone. These docs are fetched from the public web.
  52. Removed: We use Amplitude for some of our analytics data. No code data is stored with Amplitude; only event data such as "number of Cursor Tab requests".
  53. Removed: We use HashiCorp Terraform to manage our infrastructure.
  54. Removed: We use Stripe to handle billing. Stripe will store your personal data (name, credit card, address).
  55. Removed: We use Vercel to deploy our website. The website has no way of accessing code data.
  56. Removed: We use WorkOS to handle auth. WorkOS may store some personal data (name, email address).
  57. Removed: *Cursor respects model blocklists and will not send any requests to models on a blocklist.
  58. Added: If you believe you have found a vulnerability in Cursor, please submit the report to us at security-reports@cursor.com .
  59. Added: We commit to acknowledging vulnerability reports within 5 business days, and addressing them as soon as we are able to. Critical incidents will be communicated via email to all users.
  60. Removed: If you believe you have found a vulnerability in Cursor, please follow the guide on our GitHub Security page and submit the report there. If you're unable to use GitHub, you may also reach us at security@cursor.com .

1 more changed paragraphs are on the page itself.

About this change
Page
cursor.com/security
Kind
Documentation
Text hash
1409a1314d82 to 0db052043343
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.