I've been testing all three of these AI coding assistants. The marketing is all about features, but the real cost is in the data. I read the privacy policies so you don't have to. Here's the breakdown from a buyer's perspective.
* **Continue (local-first model):** Their policy is the shortest. Your code, prompts, and data stay on your machine unless you explicitly opt into their cloud. They collect minimal usage data (like feature clicks) for improvement. This is the clear winner for control.
* **Cursor:** Operates in a "cloud mode" by default. Your code snippets and prompts are sent to their servers (and then to OpenAI/Microsoft). They state this is for providing the service. You can use a local model, but the default setup means your data leaves your machine.
* **GitHub Copilot:** Microsoft's policy applies. Telemetry collection is extensive—code snippets, engagement data, and more. It's used for service improvement and training. You're feeding the Microsoft machine.
Bottom line: If data privacy is a primary concern, Continue's architecture is fundamentally different. The others are cloud services that require you to trust their data handling. Always check if your company's legal team has approved these tools.
Just the facts.
Trust but verify.
Interesting that you're taking the privacy policies at face value. The shortest policy isn't always the most protective, it's often just the one from the smallest company with the least lawyers.
You mention Continue's data stays local *unless you opt into their cloud*. That's a huge caveat. How is that opt-in presented? Is it a dark pattern during setup, a tempting feature you'll eventually need, or a checkbox buried in settings? The devil is in that default, and in how hard they make it to stay purely local.
And let's not give Copilot a pass on the "training" angle. Saying it's used for service improvement is the standard corporate fig leaf. The real question is whether that training creates a derivative product that competes with your own codebase. Their terms are notoriously fuzzy on that point.
If it's free, you're the product. If it's expensive, you're still the product.
That's a really good point about the opt-in being a potential trap. I hadn't thought about how they might nudge you towards the cloud later. I'm still learning about all this.
You're right, the "service improvement" wording is everywhere. But how do you even check if a company is actually following their own policy? Is it just a matter of trust until someone finds out they're doing more?
rookie