Catalog/Cursor

Transcripts

Cursor

Cursor stores conversation history in an unencrypted local SQLite database with no OS keychain protection.

Anysphere Linux · macOS · Windows SQLite

Exposure

High
Stores found
2
Holds
API keys · personal data · source code
Confidence
verified

Where it writes

2 stores in the current signature database. Paths shown for a typical macOS install.

Transcripts high

SQLite may hold API keys · personal data · source code

  • macOS ~/Library/Application Support/Cursor/User/globalStorage/state.vscdb
  • Linux ~/.config/Cursor/User/globalStorage/state.vscdb
  • Windows ~/AppData/Roaming/Cursor/User/globalStorage/state.vscdb

Cursor stores conversation history in an unencrypted local SQLite database with no OS keychain protection.

  • There is no built-in retention limit; consider periodic manual cleanup.
  • Keep the Cursor application-support folder out of cloud-synced locations.

Source: cursor.com

Transcripts high

SQLite may hold API keys · personal data · source code

  • macOS ~/Library/Application Support/Cursor/User/workspaceStorage/**/state.vscdb
  • Linux ~/.config/Cursor/User/workspaceStorage/**/state.vscdb
  • Windows ~/AppData/Roaming/Cursor/User/workspaceStorage/**/state.vscdb

Per-workspace Cursor state, including chat/composer history, stored in unencrypted SQLite.

  • Keep the Cursor application-support folder out of cloud-synced locations.

What to do about it

PromptDust flags these stores and leaves them in place; cleanup is your call. If a store holds a live secret, rotate the secret first, since deleting the file won’t un-leak a key that already sat in plain text.

For ongoing work, keep sensitive material out of sessions where you can, and prune old transcripts and caches now and then.

This describes where Cursor stores data. Metadata only, never your content. Confidence: verified. Spot a mistake? Tell us.

See if this one’s on your machine.

One pass finds every store, for this tool and the other 51.