# Grok Bot privacy and security

Grok Bot uses Cursor auth and privacy settings, requires cloud data storage (Legacy Privacy Mode unsupported), and relies on approvals + shared-computer hygiene rather than per-Bot isolation.

Tags: privacy, security, approvals, compliance

## Account & data

- Auth: Cursor account (org SSO applies).
- Privacy/data-sharing and training opt-out: Cursor account / team settings.
- **Legacy Privacy Mode blocks Grok Bot entirely**.
- Contractual details: https://cursor.com/privacy and https://cursor.com/security.

## Shared-computer boundary (critical)

- One cloud computer per user account, shared by all Bots.
- Files, browser sessions, CLI credentials visible across Bots.
- **Separate Bots are not a security boundary.**
- Deleting a Bot does **not** remove shared-computer files or browser sessions.

## Approvals & Auto-review

- Keep consequential actions behind approval: send, publish, purchase, delete/overwrite, permission changes, production changes, legal terms.
- Auto-review rules: Settings → General → Auto-review (Require Approval beats Always Allow).
- Local computer execution policy defaults to Ask every time.

## Secrets

- Passwords, passkeys, 2FA, CAPTCHAs, payments: human takeover of Agent Computer.
- Never paste secrets in ordinary chat.
- Secure secret-request UI for supported connectors.

## Related

- [[grok-bot]]
- [[grok-bot-community-usage]]

## Sources

- https://docs.x.ai/grok-bot/approvals-security-and-privacy
- https://docs.x.ai/grok-bot/faq
- https://docs.x.ai/grok-bot/teams-and-enterprises
- https://docs.x.ai/grok-bot/computer-and-apps
- https://cursor.com/privacy
- https://cursor.com/security
