Cursor
Cursor is an AI coding agent from Anysphere that reads your repository, plans the work and writes code across desktop, terminal, web and iOS. A permanent free tier exists, and paid plans start at twenty US dollars monthly.
What is Cursor?
Cursor is an AI coding agent published by Anysphere, Inc., a San Francisco company. It comes in four shapes: a desktop application for macOS, Windows and Linux, a command line interface, a web workspace at cursor.com/agents, and a native iOS application. The premise stated on the site is that the agent learns the codebase before writing a single line, then plans, edits and verifies rather than merely completing the line under the cursor.
Model choice is deliberately open. Cursor exposes frontier models from OpenAI, Anthropic, Gemini and SpaceXAI alongside its own Composer family, and lets subagents run in parallel with a different model on each, picked for the task at hand. Retrieval rests on secure codebase indexing and on Instant Grep, which the site describes as searching millions of files in milliseconds.
Three working modes are documented. Plan asks clarifying questions, builds a plan, then executes in the background. Design lets you select an element on a page and rewrite, resize or move it. Debug instruments the code and uses real execution data to pinpoint a fault. Beyond the editor, cloud agents each receive an isolated virtual machine with a full development environment and can work for hours or days; Automations keep agents running on schedules or triggers; and Bugbot reviews pull requests automatically once enabled.
The product is built to sit inside an existing workflow. Documented integrations cover Slack, Microsoft Teams, Jira, Linear, Notion, GitHub, GitLab, Azure DevOps, Bitbucket, JetBrains and Xcode, while TypeScript, Python and Bridge SDKs and a documented API let teams drive agents programmatically, including headless in continuous integration. Behaviour is tuned through rules, skills, hooks, subagents, MCP servers and plugins, shareable across a team marketplace.
Adoption claims on the site are substantial: more than half of the Fortune 500, over fifty thousand companies, and more than a hundred million lines of enterprise code written per day, with named endorsements from NVIDIA, Stripe, OpenAI and Y Combinator and customer stories from Vercel, Coinbase, Wayfair and Faire.
What it does
- Hand a task to an agent that reads the repository, plans the work and carries it out
- Run several cloud agents in parallel, each in its own isolated virtual machine
- Have Bugbot review pull requests agentically as they are opened
- Search millions of files in milliseconds with Instant Grep
- Drive an agent from the terminal, from Slack, GitHub or Linear, or from a JetBrains IDE
- Schedule always-on automations triggered by time or by events, such as fixing CI failures on main
- Edit a page visually by selecting an element, or debug from real execution data
When to use Cursor / When not to
A quick filter to help you decide if Cursor is the right fit.
When to use Cursor
- Software engineering teams that want to delegate whole tasks to an agent rather than accept line-by-line completions
- Developers working in very large repositories or monorepos, where the agent indexes millions of lines across hundreds of thousands of files
- Engineering organisations with security requirements: SAML or OIDC single sign-on, SCIM provisioning, audit logs and access controls over repositories, models and MCP servers
- Teams that want agents inside the workflow they already use, from Slack, GitHub, GitLab, Jira and Linear to JetBrains IDEs and the terminal
- Students and technical founders, who can start on the permanently free Hobby tier without a credit card
When not to use Cursor
- Organisations that require an on-premises or private VPC deployment, which Cursor states it does not offer today
- Android users who need a native mobile application, since the mobile app ships on iOS only
- Buyers who procure software through resellers or distributors, as subscriptions are sold directly on cursor.com and nowhere else
- Anyone under eighteen, which the privacy policy sets as the minimum age for the service
- People with no codebase and no programming practice, because the product reasons about and edits existing repositories
How to use Cursor
A typical end-to-end flow, from setup to results.
- Download the desktop application from cursor.com/download for macOS (ARM64, x64 or universal), Windows (x64 or ARM64, system or user install) or Linux (.deb, RPM or AppImage)
- Alternatively install the command line agent with the single shell command published on the home page
- Create an account through cursor.com/login; the free Hobby tier asks for no credit card
- Open a repository and describe the task in plain language, using / for commands, @ for files and ! for the shell in the CLI
- Press Cmd+K for a targeted edit, or hand the whole task to the agent when it should work on its own
- Enable Privacy Mode in settings if your code must never reach a training set
- Review the agent's plan and its diff before merging, and let Bugbot check the pull request
- Create a team at cursor.com/team/new-team, choose a billing cycle, then invite colleagues by link or email
- Add the Slack application or the iOS app to follow and steer agents away from the desktop
- Configure rules, skills, hooks and MCP servers once the basics are in place, starting from cursor.com/docs/get-started/quickstart
Pros & Cons
Pros
- A permanently free tier that needs no credit card, so the tool can be assessed at zero cost
- Open model choice across competing providers rather than a single locked-in engine
- All three desktop operating systems covered, plus a CLI, a web workspace and an iOS app
- Privacy Mode available on every plan including the free one, backed by zero data retention agreements with all model providers
- SOC 2 Type II attestation and at-least-annual third-party penetration testing, with reports available through the trust portal
- Subprocessors published and re-reviewed annually, and no infrastructure or subprocessor based in China
- Eleven documented integrations plus SDKs and an API for programmatic use, including headless in CI
Cons
- No on-premises or private VPC deployment: Cursor runs only on its own AWS infrastructure
- No Android application, the native mobile app being iOS only
- Pro+ and Ultra prices are not readable on the pricing page without JavaScript, so only twenty US dollars per month and forty US dollars per user per month can be confirmed
- Usage beyond the included allowance is billed on demand in arrears, so the monthly bill is not capped by default
- Every request travels through Cursor's backend even when you bring your own API key
- No data processing agreement is published and no EU Article 27 representative is named
- Data is hosted in the United States, with no European data residency option announced on the site
Pricing & Plans
Cursor offers a permanent free plan, named Hobby, which requires no credit card and provides a limited number of agent requests together with access to Composer. The cheapest paid entry point is the individual Pro plan at USD 20 per month. Team pricing starts at USD 40 per user per month, and Enterprise is quoted on request. All prices are stated exclusive of applicable taxes, and model usage beyond the included allowance is billed on demand, in arrears, at public API list prices.
- free - no credit card required
- limited agent requests
- access to Composer
- USD 20 per month - extended agent limits
- generous Grok and Composer limits
- access to frontier models
- MCPs
- skills and hooks
- cloud agents
- Bugbot on usage-based billing
- everything in Pro with three times the Pro agent limits
- everything in Pro with twenty times the Pro agent limits and priority access to new features
- USD 40 per user per month - centralised billing and administration
- team marketplace for internal rules
- skills and plugins
- agentic code review with Bugbot
- cloud agents and automations with shared team context
- usage analytics
- team-wide Privacy Mode
- SAML or OIDC SSO
- everything in Standard with five times the Standard agent limits
- custom pricing - pooled usage
- invoice or purchase order billing
- SCIM seat management
- repository
- model and MCP access controls
- auto-run
- browser and network controls
- audit logs and service accounts
Data, GDPR & hosting
A consolidated view of how Cursor handles your data.
GDPR overview
The enterprise page states plainly that Cursor is compliant with the requirements of GDPR and CCPA. The privacy policy, effective 6 October 2025, enumerates the usual rights, namely the right to know, access and portability, deletion, correction, objection, restriction and withdrawal of consent, with hi@cursor.com as the single address both for exercising them and for appealing a refusal. Anysphere states that it neither sells nor shares personal data for targeted advertising and takes no solely automated decisions with legal effect. Transfers from the EEA and the United Kingdom go to United States servers under what the policy calls an adequate level of protection. Two gaps deserve naming: no Article 27 representative in the European Union is designated anywhere on the site, and no data processing agreement is published or announced. Subprocessors, by contrast, are listed publicly and reviewed annually.
Who owns the data?
Anysphere separates Inputs, the content you submit, from Suggestions, the responses generated from them, and treats both as your material rather than company property. You keep the right to access, port, correct, delete or export your personal data, to object to or restrict processing, and to withdraw consent, all through hi@cursor.com. Two caveats matter in practice. Where Anysphere acts as a processor for a commercial customer, that customer's contract governs the data instead of the public privacy policy. And when your account belongs to an organisation, its administrators may access and manage your use of the service, and receive account-related information about you.
Reuse rights
The terms do not transfer ownership of what you write or of what the agent produces for you: you may reuse your code and the generated output in your own projects without asking permission. What changes is what Cursor may do with it. With Privacy Mode enabled, customer data is not used for training by Cursor or by its model providers, which are bound by zero data retention agreements; models that fall outside those agreements are flagged as such or require an administrator to opt in. With Privacy Mode disabled, Cursor may store and use codebase data, prompts, editor actions and code snippets to improve its AI features and train its models. In both cases requests travel through Cursor's backend, even when you supply your own API key, and indexing uploads code in small chunks so that embeddings can be computed.
Data retention & training
Hosting summary
Anysphere processes personal data on servers located in several jurisdictions, including the United States. The privacy policy states that data belonging to users in the European Economic Area and the United Kingdom may be transferred to Anysphere's United States servers and to other countries outside those areas, under what it calls an adequate level of data protection and legally valid transfer mechanisms. The enterprise page is more specific about the platform: Cursor currently operates on SOC 2 Type II compliant AWS infrastructure, and on-premises deployment is not offered. The security page adds that Cursor maintains no infrastructure in China and engages no subprocessor headquartered there. Data is encrypted with AES-256 at rest and TLS 1.2 or above in transit, and file contents cached to reduce latency are encrypted with client-generated keys that exist on Cursor's servers only for the duration of a request. The list of subprocessors is published on the trust portal and re-reviewed annually. No European data residency option is announced anywhere on the site.
Things to keep in mind
Risks and trade-offs to weigh before adopting Cursor.
- Privacy Mode is not on by default: until it is enabled, code, prompts and editor actions may be stored and used to train models
- Even with Privacy Mode on, a prompt that trips an abuse classifier can be retained for investigation by Cursor or by a model provider
- Bringing your own API key does not keep requests off Cursor's backend, and codebase indexing uploads code in chunks to compute embeddings
- On-demand usage is billed in arrears and can trigger intermediate charges once a rolling spend threshold is crossed; set limits before handing agents long-running work
- Delegating whole features carries a genuine skill-erosion risk for junior developers who never read the diff: the agent's output still needs a reviewer who understands it
- Fees are non-refundable except where the law requires otherwise, and the terms impose AAA arbitration while capping Anysphere's liability
- Subscriptions bought outside cursor.com may be suspended, and the service is restricted to users aged eighteen or over
Setup & Integrations
Technical difficulty
Low for an individual. Download the installer for macOS, Windows or Linux, or install the CLI with a single shell command, then sign in; the free tier asks for no card. The real prerequisite is professional rather than technical, since the product edits an existing repository and you need to be able to review a diff. Team setup remains self-service, but SAML or OIDC single sign-on, SCIM provisioning and access controls over repositories, models and MCP servers require an administrator and an identity provider. Rules, hooks and MCP servers are optional refinements added later.
Deployment
Apps stores
Integrations
Supported languages
Behind Cursor
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Is there a free plan?
How much does the first paid plan cost?
Which platforms does Cursor run on?
Is my code used to train models?
Who can turn Privacy Mode on?
What security certifications does Cursor hold?
Can Cursor be deployed on premises or in a private VPC?
Does Cursor provide an API?
Can I buy Cursor through a reseller?
What is the minimum age to use Cursor?
Should you pick Cursor?
Cursor has moved well beyond autocompletion. What Anysphere sells today is an agent that reads a repository, plans, edits, runs the terminal, reviews pull requests and, in its cloud form, works unattended for hours inside its own virtual machine. The breadth is unusual: desktop on three operating systems, a CLI that runs headless in continuous integration, a web workspace, an iOS app, eleven documented integrations and SDKs in TypeScript and Python.
The privacy posture is better documented than most. Privacy Mode is available on every plan, the free one included, an administrator can enforce it, and Anysphere states it holds zero data retention agreements with all of its model providers. A SOC 2 Type II report and a penetration test summary are available through the trust portal, subprocessors are published and re-reviewed yearly, and encryption is specified as AES-256 at rest and TLS 1.2 or above in transit.
The gaps are real. There is no on-premises or VPC option, data sits on United States infrastructure with no announced European residency, no data processing agreement is published, and no Article 27 representative is named for the European Union. Cost is the other item to watch: the included allowance is generous, but usage beyond it is billed on demand in arrears, so the monthly figure is not capped unless an administrator sets limits.
For an individual developer the decision costs nothing, since the Hobby tier is permanently free and asks for no card. For a team, the real questions are whether United States hosting is acceptable, whether the absence of a published DPA blocks procurement, and whether agent spending can be governed. On everything else, what the site documents holds up.
- Choosing a selection results in a full page refresh.
- Opens in a new window.