723 words, 47 clausesno date on the pageread 25/09/2026source
·Cursor is designed to keep your code private. Here's how data handling works.
·Privacy Mode ensures your code is never used for training by Cursor or other AI model providers.
·Learn more about how your data is used.
·For more information about subprocessors and data handling, see the Security page.
1Open Cursor Settings: Mac: Press CmdCtrl + Shift + J Windows/Linux: Press Ctrl + Shift + J
2Click General in the sidebar
3Toggle Privacy Mode on
·For teams, Privacy Mode is enabled by default for all team members. Admins can enforce it organization-wide via cursor.com/dashboard so members cannot disable it.
·When you use AI features, Cursor sends prompts and code context to model providers like OpenAI, Anthropic, and Google. With Privacy Mode enabled, your code is not used for training.
·When you use AI features, Cursor sends prompts and code context to model providers like OpenAI, Anthropic, and Google. All sub-processors have data processing agreements.
·See the Security page for details.
·With Privacy Mode enabled, your code is never used for training.
·Privacy Mode is on by default for Enterprise teams. Teams and Enterprise admins can enforce it organization-wide so members cannot disable it.
·Yes. Privacy Mode works the same for Grok 4.5 as for every other model. With Privacy Mode enabled, your code is never used for training.
·Like other models, Grok 4.5 is hosted by the model provider, a trusted partner, or Cursor. See the list of sub-processors for details.
·Cursor's Data Processing Agreement governs how Cursor processes personal data under enterprise contracts. For Teams and Enterprise customers, the DPA and privacy and data governance docs describe processor commitments and sub-processor coverage.
·Current sub-processors are listed at trust.cursor.com/subprocessors. If you are on an individual plan, the DPA does not apply; your data handling follows the Privacy Policy.
·Privacy Mode in the Cursor editor prevents your code from being used for training by Cursor or model providers. Grok Bot runs on a separate product surface with its own data flows.
·For how your data is handled across Cursor products, see How your data is used and the sub-processor list.
·Grok Bot can copy or create files on a cloud computer during agent runs. Storage location, retention period, and deletion options for that data depend on your account type and how the files were created.
·To request deletion of files that contain personal data, contact support with your account email, the agent name, and a description of the files. This follows the same data-deletion process as the rest of Cursor; see How your data is used.
·ZDR doesn't apply when you use your own API keys. In that case, your data handling follows your provider's privacy policy.
·Some models also require data retention with their provider and fall outside Cursor's ZDR agreements. These models are off by default and require admin approval before use. See Models with data retention for details.
·Enterprise plans include additional controls beyond Privacy Mode:
·AI code tracking API and audit logs: Track how AI features are used across your organization
·Granular admin and model controls: Restrict model access, enforce Privacy Mode org-wide, and manage agent permissions
·Compliance certifications: SOC 2 Type II and more (see Security and compliance documents)
·Customer Managed Encryption Keys (CMEK): Encrypt Cloud Agent data with your own keys, with full control over key rotation and access
·See the full Enterprise feature list on cursor.com/pricing or contact sales for details.
·With Self-Hosted Machines, tool execution stays on your machine and the agent loop stays in Cursor's cloud. Privacy Mode applies the same way it does for managed Cloud Agents.
·See Self-Hosted Machines for the full data split.
·Security and compliance documents Privacy and data governance Agent security API keys