cursor.com — 62/100 (Medelhög integritetsrisk)
Senast analyserad
Anysphere, Inc. · cursor.com
Rapportdetaljer
Medelhög integritetsriskCursor (Anysphere) lovar att inte använda dina kodinmatningar för AI-träning som standard och säljer inte din data, men de samlar in ett brett spektrum av personlig och användningsrelaterad data, skickar den till USA med vaga överföringsgarantier och lämnar nyckeldetaljer som lagringstider och rättsliga grunder ospecificerade.
Integritetspolicyn för Cursor (Anysphere, Inc.) täcker ett brett spektrum av datainsamling från kontodetaljer till alla användarinmatningar och förslag. Även om policyn utmärker sig positivt genom sitt standardförbud mot att använda inmatningar/förslag för modellträning och sitt åtagande att inte sälja data eller bedriva riktad reklam, kvarstår betydande brister. Lagringstider är odefinierade, de rättsliga grunderna för behandling hänvisas till i en tom tabell, mekanismer för internationell överföring är ospecificerade utöver generella försäkringar, och flera kritiska dokument (Integritetsöversikt, Cookie-policy, lista över underbehandlare) hänvisas till men tillhandahålls inte. Den breda insamlingen av inmatningar – vilka i ett kodningsverktyg kan innehålla proprietär eller känslig information – kombinerat med delning med modellleverantörer och molninfrastrukturpartners, väcker farhågor om dataminimering.
Bedömning per kategori
Uppdelning av policyn över viktiga efterlevnadsområden. Bra = stark, rimlig = blandad, dålig = oroande.
The policy collects all user Inputs and Suggestions, device/log/usage data, and location information without clearly limiting collection to what is strictly necessary for service provision.
The policy is clearly written and structured, but it references multiple external documents (Privacy Overview, Cookie Policy, subprocessor list) that are not included, and the jurisdiction-specific legal basis table appears empty.
Data is shared with a broad range of service providers including model providers and cloud infrastructure, but no specific subprocessors are named in the policy itself and the referenced list is external.
EEA users' data is transferred to US servers with only a generic commitment to 'legally valid transfer mechanisms' and 'adequate level of data protection'—no specific mechanism (SCCs, DPF, BCRs) is identified.
Inputs and Suggestions are explicitly not used for model training by default, with only narrow exceptions (security review, explicit Feedback, or explicit opt-in), and users can manage their preferences.
The policy lists access, deletion, correction, portability, objection, restriction, and consent withdrawal rights, but provides only a generic email contact and does not mention a DPO or EU representative.
Viktiga fynd
Anmärkningsvärda klausuler, problem eller positiva rutiner (kritiska först)
Broad collection of user Inputs and Suggestions without clear minimization
Section 1(A) states that all Inputs (content submitted by the user) and Suggestions (AI-generated responses) are collected. For a coding tool, Inputs may contain proprietary source code, API keys, credentials, or other sensitive data. The policy does not describe any technical measures to filter or minimize what is retained from Inputs, only that they are collected in full.
Vague and undefined retention periods
Section 4 states only that data is retained 'as long as necessary to operate the Service effectively and to support legitimate business needs' and that 'the appropriate retention period varies.' No specific timeframes or criteria are provided for any data category, making it impossible for users to understand how long their data persists.
International transfer mechanism unspecified
Section 6 acknowledges that EEA users' data is transferred to US servers but only states that 'we only transfer data in accordance with legally valid transfer mechanisms' and 'we require an adequate level of data protection.' The specific legal mechanism (Standard Contractual Clauses, EU-US Data Privacy Framework certification, Binding Corporate Rules) is not identified, which is a GDPR transparency requirement.
Jurisdiction-specific legal basis table is empty or not provided
Section 7 references a table that 'supplements this Privacy Policy by providing additional details about the purpose of data collection, type of data collected, and legal basis,' but the table content is not included in the provided text. Without this, GDPR Article 13 requirements for specifying legal bases are unmet.
Security review exception could expand data use beyond user expectations
Section 2's first exception to the no-training rule allows use of Inputs/Suggestions 'flagged for security review' to 'improve our ability to detect and enforce our Terms of Service.' This is a potentially broad exception that could allow model training on user data without explicit consent if it is deemed a security concern.
No Data Protection Officer or EU representative identified
The policy provides only a generic contact email (hi@cursor.com) and does not identify a Data Protection Officer, EU representative under GDPR Article 27, or any dedicated privacy contact role, which may be required given processing of EEA residents' data.
Default opt-out from AI training is a strong positive
Section 2 explicitly states: 'We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review... (2) you explicitly report them to us... or (3) you've explicitly agreed to their use for such training purposes.' This is a privacy-protective default that exceeds industry norms for AI tools.
Sammanfattning för användaren
Din kod och dina promptar används inte för att träna Cursors AI som standard, vilket är ett sällsynt och välkommet skydd, men allt du skriver flödar fortfarande genom deras system och kan nås för säkerhetsgranskning, och din data skickas till USA utan tydliga rättsliga skyddsgarantier.
Efterlevnadsställning
Delvis efterlevnad av dataskyddsförordningens (GDPR) principer; stark när det gäller ändamålsbegränsning för AI-träning men svag när det gäller dataminimering, lagringsbegränsning och specificitet kring internationell överföring.
EU-överföringar
Data överförs uttryckligen till USA. Policyn anger att överföringar använder
Upptäckta signaler
Specifika datapunkter och rutiner identifierade i texten
Bevisutdrag
Direkta citat från policyn som stödjer dessa fynd
We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review (in which case we may analyze them to improve our ability to detect and enforce our Terms of Service), (2) you explicitly report them to us (for example, as Feedback), or (3) you've explicitly agreed to their use for such training purposes.
Anysphere retains your personal data only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements.
For users in the European Economic Area, ('EEA'), when you access our Service, your personal data may be transferred to our United States servers to other countries outside the EEA and the UK. Where information is transferred outside the EEA or the UK, we require an adequate level of data protection.
We do not 'sell' or 'share' personal data for cross-contextual behavioral advertising, and we do not process personal data for 'targeted advertising' purposes (as those terms are defined under applicable US state privacy laws).
The Service allows you to submit content ('Inputs'), which generate responses ('Suggestions') based on your Inputs. If you include personal data or reference external content in your Inputs, we will collect that information and it may be reproduced in the Suggestions we provide.
Saknas eller otydligt
- Specific legal bases for each processing purpose (GDPR Article 13(1)(c))
- Specific retention periods or criteria per data category
- Identification of Data Protection Officer
- Identification of EU representative under GDPR Article 27
- Specific international transfer mechanism (SCCs, DPF, BCRs)
- Content of the jurisdiction-specific disclosures table referenced in Section 7
- Privacy Overview document referenced in the Introduction for model training details
- Cookie Policy details
- Subprocessor list content
- Details on how security review flagging works and its scope
- Whether DPIAs have been conducted
Frågor att ställa
- What specific legal transfer mechanism do you rely on for EEA-to-US data transfers (Standard Contractual Clauses, EU-US Data Privacy Framework, or other), and can you provide the relevant documentation?
- What are the specific retention periods for each category of personal data, particularly for Inputs and Suggestions?
- Under what specific criteria is an Input 'flagged for security review,' and can you provide statistics on how often this exception is invoked?
- Who is your designated Data Protection Officer or EU representative, and how can data subjects contact them directly?
- Can you provide the complete subprocessor list including model providers, and specify which subprocessors have access to user Inputs?
- Have you conducted a Data Protection Impact Assessment for the processing of user Inputs, given the potential for sensitive or proprietary code content?
- What are the specific legal bases (consent, legitimate interest, contract performance) for each processing purpose listed in Section 2?
- How does the 'manage your preferences' mechanism for AI training opt-in/opt-out work technically, and is it enabled by default for all users?
Dela den här analysen
Alla med den här länken kan se resultatet ovan.
Byggd av DentroChat
100 % europeisk AI-chatt för alla
Chatta med AI, arbeta med filer, generera bilder och sök på webben. Data stannar i Europa.
Andra analyserade integritetspolicyer
Visa allaapp.klang.ai
62/100
Medelhög integritetsriskKlang AI collects potentially sensitive audio and video content, shares it with multiple AI providers, and reserves the right to use your uploaded data to improve its own algorithms without offering an opt-out — though it does keep most processing in the EU and enforces zero data retention with its AI sub-processors.
Visa rapport →eustella.com
62/100
Medelhög integritetsriskeustella gör starka integritetslöften — ingen försäljning av data, ingen delning med tredje part, ingen AI-träning på din data, och all bearbetning sker inom EU — men detta är marknadsföringstext, inte en bindande integritetspolicy, och kritiska detaljer om datainsamling, lagring, underbiträden och användarrättigheter saknas i den tillhandahållna texten.
Visa rapport →lhv.com
62/100
Medelhög integritetsriskLHV Bank samlar in en omfattande mängd personuppgifter och finansiell data, delar den i stor utsträckning med bedrägeriförebyggande byråer och betalningsförmedlare, och förlitar sig tungt på berättigat intresse för marknadsföring och analys — men de täcker GDPR-rättigheter och använder manuell granskning för profilbeslut.
Visa rapport →cake.com
62/100
Medelhög integritetsriskCAKE.com tillhandahåller standardiserade EU-dataskyddsrättigheter och överföringssäkerheter men samlar in mycket intrusiv arbetsplatsövervakningsdata – som skärmdumpar, bakgrundsplats och appanvändning – för arbetsgivarens räkning, vilka fungerar som personuppgiftsansvariga för sina anställda.
Visa rapport →