cursorthing 的隐私政策
cursorthing 作者: Nostabyte Interactive
The most up to date revision of this privacy policy can be found here: https://cursorthing.com/privacy
Last updated: July 18, 2026
Cursorthing is a browser extension that lets you see other players' cursors as
you browse the web — and lets them see yours. Explore the internet together,
earn XP, and customize your cursor.
When you sign in with Google or Discord, we receive your email address from
that provider. This is used to identify your account and for support purposes.
We may also use it to send you announcements about Cursorthing features,
updates, or events, or about other projects and events from
Nostabyte Interactive. We will never send third-party marketing or
promotional content unrelated to Cursorthing or Nostabyte Interactive. Your
email address is never visible to or shared with other users.
While the extension is active on a page, we collect your
cursor's x/y coordinates and visibility state at intervals of approximately
100ms. This data is transmitted in real time to other users on the same page
so they can see your cursor.
To place you in the correct "room," the extension generates a fingerprint of
the page URL and sends that to our server — not the URL itself. This
fingerprint cannot be used to discover what URL you were on — though if you
already know a URL, you could confirm whether it matches. Your browsing
activity is not exposed to us.
Anti-cheat and anti-abuse: In some cases — for example, to verify that a
claimed visit is legitimate — our server may issue a challenge requesting the
full URL from your extension. URLs transmitted during a challenge are used
solely for verification and are not stored.
Your cursor appearance settings are stored and shared with other users so
they see your customized cursor. These settings may include visual properties
such as color, style, and other display options.
We store a JWT access token and refresh token in your browser's local
storage. These are used to authenticate your WebSocket connection to our
server. They are never shared with third parties.
We may collect anonymous, aggregated usage statistics to help us understand
how the extension is used and improve the platform. This may include things
like feature interaction counts, error rates, and performance metrics. This
data is not linked to your account or identity and cannot be used to identify
you. We do not currently collect this data, but reserve the right to do so in
the future.
We operate an XP system that rewards you for browsing activity. To track this,
we store on our servers:
- Hashes of website domains and pages you have visited while signed in
(used to determine whether a visit counts as "new" for XP purposes). These are
the same short, truncated hashes described in the Page URL section — we never
store the actual domain name or URL. - Your XP balance and history (XP earned, timestamps of earning events)
This data is linked to your account. Visit hash records are used only for XP
calculations and are not used for advertising or profiling.
- The actual text of URLs or domain names under normal operation — only
fingerprints are sent. Full URLs may be transmitted only if our server issues
an anti-abuse challenge, and are not stored. - Page content, form inputs, or keystrokes
- Precise device or location information
- Any data from pages where the extension is inactive or you are not signed in
| Data | Purpose |
| ---------------------------- | ------------------------------------------------------------------------------------ |
| Email address | Account identification, support, and Cursorthing/Nostabyte Interactive announcements |
| Cursor position + visibility | Real-time display to other users on same page |
| Page URL | Routing you to the correct cursor room |
| Anonymous usage statistics | Improving the platform (not linked to your account) |
| Hashed domain + page values | Determining unique site visits for XP rewards |
| XP balance + history | Operating the rewards system |
| Cursor appearance | Displaying your customized cursor to peers |
| JWT / refresh token | Authenticating your connection |
We do not and will not sell your data to third parties. We do not rent or
share your data with advertisers or third-party analytics services.
All communication between the extension and our server uses secure WebSocket
(WSS) and HTTPS. Data is transmitted to
api.cursorthing.com.Cursor position data is relayed in real time to other authenticated users on
the same page. No cursor data is stored on our servers beyond the active
session.
- Google OAuth (
accounts.google.com) — used for sign-in. Governed by
Google's Privacy Policy. - Discord OAuth (
discord.com) — used for sign-in. Governed by
Discord's Privacy Policy.
We request only the
email scope from both providers. We do not accesscontacts, calendar, messages, or any other account data.
- Cursor position data is not persisted. It is relayed live and discarded.
- Account data (email) is retained as long as your account exists. You can
request deletion at any time. - Visit hash records (hashed domain and page values) are retained as long
as your account exists and are deleted when your account is deleted. - XP balance and history are retained as long as your account exists.
- Auth tokens are stored locally in your browser and cleared when you sign
out.
You can:
- Sign out at any time, which clears all locally stored tokens
- Uninstall the extension to stop all data collection immediately
- Request account deletion by contacting us (see below)
Cursorthing is not directed at children under 13. We do not knowingly collect
data from children under 13.
We may update this policy. Material changes will be noted with an updated date
at the top of this document.
Questions or deletion requests: <me@jacobcoughenour.com>