AI Vendor Directory · Coding assistants

Does Cursor train on your data?

No — does not train on your data by default. Vendor-stated default: no (Teams/Business — Privacy Mode on by default). Cursor's docs: 'For teams, Privacy Mode is enabled by default for all team members' and admins can enforce it org-wide so members cannot disable it; 'With Privacy Mode enabled your code is never used for training by Cursor or other AI model providers.' Most models run under Cursor's zero-data-retention agreements with providers. Exceptions to verify: (1) bring-your-own API keys fall outside ZDR; (2) a few models require provider-side retention (e.g. Claude Fable 5) and are blocked for Privacy Mode/Enterprise customers until an admin approves them; (3) Cloud Agents store encrypted repo copies while running. Privacy policy states inputs/suggestions are not used for training unless flagged for security review, reported as feedback, or explicitly agreed.

What is Cursor (Business)?

AI-native code editor (VS Code fork) with agentic coding; routes prompts/code context to OpenAI, Anthropic, Google and Cursor's own models. Teams/Business is the standard SMB tier.

Key facts

  • Vendor: Anysphere — https://cursor.com
  • Trains on customer data by default: no (Teams/Business — Privacy Mode on by default)
  • Source for the training answer: https://cursor.com/help/security-and-privacy/privacy.md
  • Data residency: US (Enterprise can enroll in US-only data residency)
  • Last verified: 2026-07-29

What certifications does Cursor hold?

  • SOC 2 Type II

Security, DPA, and subprocessor links

  • Security / trust page: https://cursor.com/security
  • Data processing agreement (DPA): https://cursor.com/terms/dpa
  • Subprocessor list: https://trust.cursor.com/subprocessors

What is your EU AI Act role when you build on Cursor?

Deployer of a third-party AI coding tool used internally; Anysphere and its model providers are the providers. No Article 50 transparency trigger for internal use.

What to record in your AI registry

  • Provider: Anysphere (Cursor)
  • Model type: third party api
  • Data typically flowing to the vendor: source code, prompts and chat, codebase embeddings/index, repository content (Cloud Agents only)

Sources

  • https://cursor.com/security
  • https://cursor.com/privacy
  • https://cursor.com/docs/enterprise/privacy-and-data-governance.md
  • https://cursor.com/help/security-and-privacy/privacy.md
  • https://cursor.com/help/security-and-privacy/compliance.md
  • https://cursor.com/help/security-and-privacy/regions.md

Disclaimer

Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.

Frequently asked questions

Does Cursor train AI models on your data?

No — does not train on your data by default. Vendor-stated default: no (Teams/Business — Privacy Mode on by default). Cursor's docs: 'For teams, Privacy Mode is enabled by default for all team members' and admins can enforce it org-wide so members cannot disable it; 'With Privacy Mode enabled your code is never used for training by Cursor or other AI model providers.' Most models run under Cursor's zero-data-retention agreements with providers. Exceptions to verify: (1) bring-your-own API keys fall outside ZDR; (2) a few models require provider-side retention (e.g. Claude Fable 5) and are blocked for Privacy Mode/Enterprise customers until an admin approves them; (3) Cloud Agents store encrypted repo copies while running. Privacy policy states inputs/suggestions are not used for training unless flagged for security review, reported as feedback, or explicitly agreed.

What certifications does Cursor hold?

Per the vendor's published pages as of 2026-07-29: SOC 2 Type II.

Where does Cursor store your data?

Vendor-listed data residency options as of 2026-07-29: US (Enterprise can enroll in US-only data residency).

What is your EU AI Act role when you build on Cursor?

Deployer of a third-party AI coding tool used internally; Anysphere and its model providers are the providers. No Article 50 transparency trigger for internal use.