1 min lesson
Data flow
Use "Compare AI request transit, stored index embeddings and metadata, and remote Cloud Agent repository execution" to describe the practical rule.
Step 1 of 3
Compare AI request transit, stored index embeddings and metadata, and remote Cloud Agent repository execution
An AI request sends the prompt and selected code context through Cursor and the chosen model path, while indexing uploads small code chunks to compute embeddings and stores embeddings plus metadata. A Cloud Agent sends repository data and task context into a remote execution environment, while local files remain on the device until a feature selects or uploads them.
Learn more
Advanced table
Data flow
- Data flow
- AI request
- What leaves the device
- The prompt and selected code context are sent through Cursor and the chosen model path
- What the review must verify
- Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition., provider terms, retention, region and access controls
- Data flow
- Codebase indexing
- What leaves the device
- Small code chunks are uploaded to compute embeddings
- What the review must verify
- Plaintext handling plus storage and deletion of embeddings and metadata
- Data flow
- Cloud Agent
- What leaves the device
- Repository data and task context enter a remote execution environment
- What the review must verify
- Repository retention, environment isolation, credentials, egress and deletion
- Data flow
- Local editor state
- What leaves the device
- Files remain local until a feature selects or uploads their content
- What the review must verify
- Which user action or policy starts each outbound flow
| Data flow | What leaves the device | What the review must verify |
|---|---|---|
| AI request | The prompt and selected code context are sent through Cursor and the chosen model path | Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition., provider terms, retention, region and access controls |
| Codebase indexing | Small code chunks are uploaded to compute embeddings | Plaintext handling plus storage and deletion of embeddings and metadata |
| Cloud Agent | Repository data and task context enter a remote execution environment | Repository retention, environment isolation, credentials, egress and deletion |
| Local editor state | Files remain local until a feature selects or uploads their content | Which user action or policy starts each outbound flow |
Cursor documentation says codebase indexing stores embeddings and metadata after plaintext chunks are processed. Those records are derived from the repository and need an owner, access policy, retention rule and deletion path. Do not describe the indexing path as if nothing is stored.
Learn more
Optional practice
Test yourself on Data flow
QWhy must an enterprise data map include codebase indexing even when the service does not retain plaintext files?