Privacy Mode is on. Where does your client code go?
You work inside a local editor, but its AI features need context from your repository. Terminal commands, your own API keys, and Cloud Agents add more paths to assess. One toggle can’t answer every question.
Cursor and GDPR require a review of the actual workflow. I’ll show you how to check the contract and Privacy Mode, restrict context, and review agent permissions. You’ll then assess API keys and cloud execution separately.
For a shared team policy, use the company AI policy guide alongside these technical checks.
- Enable Privacy Mode and check the appropriate DPA. Cursor distinguishes Individual plans from team contracts.
- Use .cursorignore to limit context. Terminal and MCP access need separate controls, while BYOK still involves Cursor's backend.
- Assess Cloud Agents as a separate cloud workflow. Repository contents, credentials, networking, and retained artifacts all matter.
1. Sanitize the repository before enabling AI features
Source files aren’t the only contents of a development project. Fixtures, logs, comments, and database exports may contain personal data. An ordinary debugging request can collect those details indirectly.
I’d start with fictional fixtures and limited test credentials. Keep production secrets outside the agent’s accessible workspace. Check generated output and archives as carefully as the visible source files.
Cursor’s data usage overview describes several processing paths. Separate them when assessing client work.
Separate Cursor data paths. Documentation checked in October 2026.
The local editor describes where you work. It doesn’t establish the contractual handling of data sent to other services. Check that handling before configuring the product.
2. Confirm that your account has the required DPA
For client projects, I’d assign accounts through an approved team organization. This makes access and contractual responsibility traceable. A personal account with Privacy Mode enabled doesn’t resolve the contract question.
The Cursor privacy documentation provides a DPA for Teams and Enterprise. It explicitly says that this DPA doesn’t apply to Individual plans.
A Data Processing Addendum defines obligations for processing personal data on your behalf. Review its scope, subprocessors, and international-transfer provisions. Your own processing purpose still needs an assessment.
Annex 1 of the published DPA prohibits customers and their personnel from providing sensitive or special-category personal data under the applicable Agreement. The clause states that the vendor isn’t liable for processing sensitive data nevertheless provided. Privacy Mode doesn’t change that contractual scope.
Agency work may require additional approval under the client’s contract.
Record which projects, data categories, and users the approved arrangement covers.
A DPA doesn’t supply the lawful basis for your own processing. Document the purpose and basis, applicable information duties, and procedures for access, rectification, and erasure. The German supervisory authorities’ AI guidance also calls for a prior risk assessment. A likely high risk generally requires a data protection impact assessment under Article 35 GDPR.
Cursor directs security and subprocessor inquiries to its Trust Center. Keep the relevant current documents with your approval record. A general certification doesn’t validate every individual configuration.
Claude models inside Cursor still follow Cursor’s product route. The Claude Code privacy guide covers a different client and contract path.
Once the contract fits, configure how Cursor uses submitted content. Privacy Mode handles part of that decision.
3. Enable Privacy Mode before sharing project context
Open Cursor settings and find ‘Privacy Mode’. Enable it before using AI features with confidential code. In a team, also check the administrator’s enforced policy.
Cursor states that this mode excludes your content from its training use. It also describes Zero Data Retention arrangements with model providers. ZDR concerns a specified retention commitment rather than every possible stored artifact.
Prompts and necessary code context still travel to the services handling your request.
Temporary caches and safety exceptions require separate consideration. Risk or abuse classifiers can retain content under their applicable policies.
Don’t assume every available model has the same ZDR coverage. Check the selected model’s designation and approval. The enterprise hardening guide describes central controls for Privacy Mode and model access.
I’d enforce the approved settings for client projects instead of relying on each user to remember them. File-context rules then reduce what gets collected in the first place.
4. Reduce code context with .cursorignore
Create a .cursorignore file in the project root. Review its effect using the official ignore documentation. Nested ignore files require the optional hierarchical ignore setting.
This starting point excludes common secret-file names and a private data directory. Adapt the paths to your actual project structure.
.env
.env.*
**/credentials.json
**/secrets.json
**/*.pem
**/id_rsa
private-data/Check which files Cursor actually includes after the change.
Ignore rules help limit context, while operating-system permissions enforce a different boundary.
Keep production secrets outside the accessible project and use an appropriate secret store. A required test credential should have only the permissions that test needs.
Also inspect archives and database exports. Removing visible customer records won’t help if a backup containing the same records remains accessible. Next, constrain the tools that can read those files.
5. Review terminal execution and integrations
The agent can read files and start programs through the terminal. A build script may launch additional processes, so inspect it like a direct command.
Cursor’s agent run modes provide different execution controls. Its hardening guidance recommends ‘Auto-review’ rather than ‘Run Everything’, together with sandboxing.
I’d avoid unrestricted automatic execution for sensitive projects. Review commands that access unrelated files or send data to external hosts. Automated review doesn’t replace enforceable filesystem isolation.
Use a restricted account, container, or suitable isolated development environment.
Limit its files and credentials to the approved project. Grant additional access only when a specific task needs it.
Assess each MCP server and extension individually. Record where it runs, what it can access, and which recipient receives its inputs. Cursor’s contract doesn’t automatically cover unrelated tool providers.
Your team needs to understand the consequences of granting tool access. The EU AI literacy guide supports your training planning.
An API key changes the model connection but won’t enforce these execution boundaries. It also leaves an important backend path intact.
6. Check BYOK and the actual processing region
BYOK changes model access while Cursor still builds the final prompt. It means ‘Bring Your Own Key’.
You provide a key for a supported model provider.
This can change access and billing without removing Cursor’s own infrastructure.
The API key documentation says Cursor still builds the final prompt on its backend. Cursor’s ZDR agreement also doesn’t apply to BYOK requests.
Assess both services rather than treating the key as a privacy guarantee. The model provider adds its own contract, retention, and regional settings. A European model endpoint doesn’t relocate the entire Cursor product.
The current governance documentation separates two options. US-only residency covers inference, processing, and storage for supported features and models. EU plus Iceland inference-only coverage is available on request. Broader EU support is still in development.
The US commitment excludes, among other paths, BYOK, custom model gateways, authentication, and external integrations. Confirm your team’s enrollment, model, and exclusions. European inference alone doesn’t establish European storage and processing throughout the product.
Processing outside the EU isn’t automatically prohibited under GDPR.
It needs an appropriate legal and protection framework. An EU-only client requirement nevertheless needs a route that actually satisfies that restriction.
Using OpenAI models outside Cursor creates a different product route. The Codex privacy guide covers that setup and its controls.
Cloud Agents add another processing environment to this assessment. Review it separately before connecting a confidential repository.
7. Assess the selected Cloud Agent hosting option
Cursor-hosted Cloud Agents run in remote virtual machines with a cloned repository. Dependencies, credentials, and generated artifacts can become part of that environment.
With Self-Hosted Machines, file edits, terminal commands, and local MCP servers run on a machine you manage. Cursor still runs the agent loop, inference, and planning. Required file contents, tool output, and artifacts can be sent to Cursor. This isn’t fully local model processing.
For Cursor-hosted Cloud Agents, the detailed security documentation specifies VM snapshots expiring after 90 days of inactivity. Conversations remain by default until deletion or an applicable Enterprise retention policy.
The retention and network controls explain an important limit. The Delete Agent API removes the transcript and artifacts, but not the VM snapshot. Snapshots can’t be deleted on demand.
The governance overview instead describes repository copies as deleted after completion. These statements are too unclear to establish a deletion commitment. Obtain written confirmation of the applicable scope and retention periods for your account before approving repositories subject to that requirement.
Enabling Privacy Mode during a Cursor-hosted run that started without it leaves that run’s existing privacy setting unchanged. Set the mode before starting the agent.
Training and workflow storage serve different purposes.
Privacy Mode can be enabled while cloud conversations remain stored. Check both commitments for confidential client work.
Cursor-hosted Cloud Agents execute terminal commands automatically and have internet access by default. Review secrets and network settings, including permitted outbound destinations. Self-hosted workers require a separate assessment of your execution environment and its network permissions.
Before approving this route, document the following answers.
- Which repositories may the Git integration clone?
- Which credentials are provided, and what data can they access?
- Which external hosts may the environment contact?
- Who can view conversations and generated artifacts?
- How are stored content and credentials deleted or revoked?
If those answers are missing, I’d keep Cloud Agents disabled for that project. You can assess a local workflow first, while still reviewing its hosted model requests.
If you want a separate terminal agent, see the Claude Code and Codex comparison. That workflow still requires its own privacy assessment.
The final check now needs to verify each approved path in practice.
8. Test context, tools, and cloud execution independently
Create a repository containing fictional data and clearly recognizable test values. Include an allowed file and an ignored file with harmless content. That lets you detect unexpected access without disclosing actual secrets.
Use the account and settings intended for the real project. Perform these checks separately.
- Confirm the organization, Privacy Mode, and selected model.
- Check that the ignored file stays outside direct agent context.
- Test the same file through terminal commands and approved MCP tools.
- Verify filesystem permissions and allowed network destinations.
- Assess cloud Git access, artifacts, retention, and deletion independently.
Record the client version, configuration, and outcome per path. A working ignore rule doesn’t prove terminal isolation or suitable cloud retention.
If a test exposes the wrong boundary, disable the affected feature. Correct the underlying permissions or configuration, then repeat that test. An extra chat instruction won’t establish the missing protection.
Record the approved projects and capabilities in your company AI policy. Start with one sanitized test repository using the intended Cursor account.






