Draft — pending approval
Privacy policy
This draft covers Cursor Style Chat (Android package style.cursor.chat), its web chat at cursor.style, and related account services. Website and Chrome extension practices are distinguished below. It is pending approval, not an assertion that the planned app release has shipped.
[OWNER: Supply the legal operator/controller name, postal address, jurisdiction and effective date.]
Information collected and its use
- Account and profile: name/display name, username, email where supplied, internal user ID, avatar and preferences. Google sign-in can provide a Google ID, name, email, profile-photo URL, given/family names and locale. These support sign-in, account linking and displaying a profile. Guest accounts also have a user ID, username, activity and chat data; they are not data-free accounts.
- Birth year: we collect a year rather than a full birth date for data quality. The accepted range is 1940 through the current year minus six (2020 in 2026). This input validation is not age verification. There is no age gate or age-based feature policy in this release; a stored year does not establish a person's actual age.
- Conversations and activity: room, group and direct messages, timestamps, sender/recipient IDs, replies, reactions, poll votes, friendships, blocks, reports and moderation records. Messages are processed to deliver conversations and enforce service rules; direct messages are server-processed and must not be treated as end-to-end encrypted.
- Uploads and optional features: avatars, images/photos, GIF references, audio/voice clips and other supported media, associated descriptions/metadata, posts and comments; optional linked gaming/social profiles and call history/recordings where the web feature is used. Visibility depends on the feature and audience. Do not put private information in public messages or uploads. This list describes server/web capabilities, not availability of every feature in each Android version.
- Technical data: IP addresses, approximate country derived from IP/Cloudflare country headers, session/authentication identifiers, last activity and operational/security logs. Country is used for country rooms and profile privacy settings, not precise GPS tracking. Website referral/landing-page information and activity counters also support site administration.
- Push after the app's push release ships: Firebase Cloud Messaging (FCM) registration token, installation ID, platform, app version, locale and notification preferences, associated with the account/device session, to deliver notifications. The planned default is a generic “New message” without sender name or message text. [VERIFY: Confirm the shipped push payload, registration lifetime and token deletion/revocation behavior against the final app and server release.]
Service providers and disclosures
Content and technical information can reach providers needed for these functions; a blanket “no third-party sharing” promise would be inaccurate.
- Google: optional Google sign-in; browser translation can send selected message text directly to Google Translate. Google Fonts and other external web assets receive browser requests.
- Giphy: the server searches/browses Giphy; some GIF media is fetched directly from Giphy by clients, while other GIFs are mirrored. Queries and requested GIFs are processed by Giphy; direct media requests expose connection information such as IP.
- OpenAI: server translation (including moderation-panel translation) and text/image moderation can send message text, usernames or image content to OpenAI.
- Amazon Web Services Rekognition and Microsoft Azure AI Content Safety: configured optional image-moderation integrations can receive uploaded images, including in shadow mode. [VERIFY: Confirm which moderation integrations are enabled for the deployed release, their regions, agreements and provider retention/training settings.]
- Google Firebase Cloud Messaging: after push ships, Google processes the registration token and notification-routing payload.
- Hosting, storage, delivery and email: the service uses k3s; Cloudflare country headers and Cloudflare R2 media-storage integrations are present. [OWNER: Name the hosting operator, hosting/storage regions, email-delivery provider and any other active infrastructure processors.]
[VERIFY: Confirm the complete provider inventory, processing agreements, international transfers and safeguards for the release; code alone does not establish these legal arrangements.]
Website, extension and app distinction
The existing website layout includes Google Analytics and Google AdSense scripts, external fonts, and configurable diagnostic reporting. Website cookies/local storage support sessions, language, themes and extension linking. This draft does not introduce these scripts or any new ad/analytics SDK. The native app release has an owner requirement of no ad or analytics SDKs. [VERIFY: Audit the final Android/Flutter web/extension builds, website diagnostic settings and browser consent controls; do not present the website's tracking behavior as the native app's behavior.]
Storage and retention
Accounts, conversations and uploads persist until deleted or otherwise cleaned up; no universal message/account retention deadline was established from the code. The translation service defines cache expiry at 90 days after last use and translation-event expiry at 30 days; these depend on its Mongo TTL indexes being provisioned. The web call-recording purge is scheduled with a seven-day window; this is not a retention promise for ordinary messages or uploads.
[VERIFY: Confirm deployed cleanup schedules/TTL indexes and actual retention for messages, uploads, reports, logs, call history, guest accounts, push registrations and backups, including deletion from providers.]
[OWNER: Approve a retention schedule and any specific lawful preservation exceptions, with their duration.]
Account deletion and choices
The v2 app release is intended to offer Settings → Delete account. [VERIFY: Confirm this entry point, guest-account handling and completion behavior in the final app; it is not proven for shipped 1.0.0+3 or 1.1.0 here.]
You can also start an email-confirmed deletion without logging in at https://cursor.style/account/delete. Follow the email link and submit the final confirmation form. Links expire after 24 hours. The service attempts to delete the account and associated chat records; public-room messages may remain with display identifiers masked. Message text may still identify you, and internal IDs can remain. Read the account deletion information for limits, media and backup questions. Guests or people without access to the account email can contact support; identity verification and completion require assistance.
Profile privacy, block/report and notification controls depend on the available client/feature. [VERIFY: Confirm applicable access, correction, objection and other privacy rights, legal bases, response periods and complaint authority for the operator's jurisdictions.]
[VERIFY: Confirm transport encryption and storage-access controls for all deployed app, web, media, provider and backup paths; this draft makes no blanket encryption guarantee.]
Contact
The existing support address is [email protected]. [OWNER: Confirm this monitored privacy contact and designate any privacy representative required for the operator.]
See also child safety standards, terms and the website's cookie policy.