When an AI tool wants to be your system of record
How to tell a tool that reads your data from one that stores the only copy, and what to check before you let a vendor hold it.
on this page · 0 / 0 checked
A tool you already pay for sends you a note about a new feature. From now on it can store the thing itself, not just work on it: your repositories, your documents, your automations, your client list. Setup is one toggle, it costs nothing extra because it is bundled into your plan, and when you flip it nothing appears to happen. That is the moment worth slowing down for, and it is the one almost nobody slows down for, because the change is invisible on the day you make it and expensive only later.
This guide is about that decision and nothing else. Not whether the tool is good, not whether the vendor will survive, but the narrower question of where the only copy of your work lives and what it would take to get it back. The distinction it turns on is old and boring and it keeps deciding outcomes: some software reads your data, and some software becomes the place your data is. If you are running a business on someone else’s infrastructure by choice, with a platform team and a contract, this is too small for you. It is written for a one-person business or a team under about twenty, where the person who would run the migration is you, on a weekend.
Two kinds of tool, and only one of them can strand you
The first kind reads your data and gives it back changed. A chat assistant you paste a document into is this. So is a coding tool that edits files in a folder your machine already has, and an automation that moves rows between two apps you separately control. If the vendor disappeared overnight you would lose convenience, habits and some tuning. You would not lose the material.
The second kind holds the data. It is the store, the address other systems point at, the thing a write lands in first. Lose access and you have not lost a feature, you have lost the asset. A tool can move from the first category to the second without changing its name or its price, and the move usually arrives described as an integration rather than a relocation.
Cursor’s Origin is a clean example of both sides existing inside one product. Origin began rolling out in early beta on 17 August 2026, to all paid plan users except enterprise orgs whose admins opt out [1]. It offers two modes, and the difference between them is the whole subject of this guide. For repositories you sync from GitHub, Cursor states that “GitHub stays the source of truth: pushes keep going to GitHub, and Origin mirrors the result” [1]. For repositories hosted on Origin itself, the same page states that “Origin is the source of truth” and that “Pushes land on Origin, and GitHub is not in the path” [1]. On synced repositories, pull request comments travel both ways, and a reply on GitHub shows up in Cursor within seconds [1]. That is what makes the two modes feel alike in daily use, even though only one of them can strand you.
Nothing about that is dishonest. It is documented on the vendor’s own changelog in plain words. But the two options sit next to each other in the same interface, they look the same once you are working, and only one of them leaves a full copy of your history somewhere you already control. The general form of the question, for any tool in any category, is: when I make a change, which system does it land in first, and could I rebuild today’s state from something I hold if that system stopped answering.
The bundled store is free because the switching cost is the product
A store bundled into a subscription is not a gift, it is a change in the shape of what you would be giving up. Leaving a model or an editor is a settings change and an afternoon of irritation. Cursor Pro is $20 per month and Teams Standard is $40 per user per month [2], and a subscription is a line item you can stop paying. Leaving a service that holds your repositories, your revision history and your review threads is a project with a date on it, and you will schedule it around client work, which means you will not schedule it.
That asymmetry is the point of the bundle, and it is not unique to any one vendor. The vendor is not buying your usage this month. It is buying the cost of your departure in two years.
None of which makes the bundle a bad deal. A tighter stack genuinely does remove friction, and for a solo operator, friction is the main tax. The mistake is not saying yes. The mistake is saying yes without pricing the exit, because the exit is the thing you are actually paying with. So price it before you commit, in the only unit that matters to a small team, which is your own hours.
projects × hours each × your rate. Count verification and reconnecting integrations, not just the copy. Computed in the page; nothing is sent anywhere.
Run the export before you need it, and read what it leaves behind
Most vendors have an export button, and its existence is what stops people from asking the next question, which is what the export actually contains. The gaps are specific, and they are written down, so you can look them up before you commit rather than after.
Take the friendliest possible case: moving a repository from one GitHub product to another, using GitHub’s own migration tool. It carries Git source with commit history, pull requests, issues, milestones, wikis excluding attachments, Actions workflows, commit comments, active webhooks, repository topics and releases up to 10 GiB per repository [4]. It does not carry Git LFS objects and large binaries, Actions secrets, variables, environments, runners, artifacts or workflow run history, packages in GitHub Packages, the new projects experience, rulesets, code scanning results, Dependabot alerts, repository-level discussions, the edit history of issue and pull request comments, fork relationships, repository stars and watchers, webhook secrets, or user access to the repository [4]. That is the first-party tool, moving between two products from the same company. Assume any cross-vendor path is worse.
The same pattern holds outside code. Notion exports to PDF, HTML, or Markdown and CSV, and its own help page notes that you cannot export a Form view of a database, that when exporting a database “you can only choose between the current view and the default view”, that “Exporting all views at once isn’t supported”, and that pages the exporter does not have access to are left out [6]. Zapier’s Zap import and export is available on Team and Enterprise accounts only, and “Import and export only support the JSON file format” [7]. Import is not available during a free Zapier trial, and unless you are the account owner or a super admin you can only export the Zap workflows you own [7]. After importing, you still have to turn the workflows on and test your app connections yourself [7]. That last case is worth naming precisely: the file the export produces is a file the same vendor’s importer reads. It is a backup, not a door.
So the check is not “is there an export”. It is: run the export today, on your real data, open what comes out on a machine that has none of the vendor’s software installed, and see what you are actually holding. Do it during the trial, while you can still walk away for free.
The source-of-truth question, answered in writing
Three questions settle it, and all three have answers you can write down in a file rather than carry as an impression.
Where does a write land first. Not where does it end up, where does it land. If the answer is the vendor, you have a system of record. If the answer is somewhere you control and the vendor mirrors it, you have a cache, and a cache going down is an outage rather than a loss.
What could you rebuild from tomorrow morning without the vendor’s cooperation. A cloned repository on your laptop is an answer. A monthly export you have never opened is a weaker answer. An account login is not an answer at all, because it is exactly the thing an outage, a billing failure or a suspended account takes away.
What does the vendor’s own documentation say about the specific product, rather than the company. This distinction catches people out. Cursor’s data-use page describes privacy mode, states that with it enabled “Customer Data will not be used for training by Cursor”, says Cursor “maintains zero data retention (ZDR) agreements with all providers”, and explains that file contents are temporarily cached on Cursor’s servers, “encrypted using unique client-generated keys”, and “never permanently stored” [3]. Those statements are about code sent through AI features. Hosting a repository is a different activity with different retention implications, and that page does not mention hosted repositories or Origin at all [3]. That is not an accusation, it is a gap you should notice, because a policy that covers one product does not automatically cover a newer one.
Reliability is the wrong reason to move, in either direction
The usual argument for adopting a new store is that the incumbent went down. Origin’s beta arrived on the same day GitHub suffered a worldwide outage that degraded the site for over six hours with a nearly 20% error rate, and the same report cited an analysis by LeadDev counting 257 GitHub outages over the previous year [8]. That is a real event with a real cost, and it explains the timing of a great deal of coverage.
It is also close to useless as a decision input. An incumbent with a decade of public incident history looks worse than a service too new to have one, and the comparison rewards youth rather than reliability. The service that has never had an outage has usually never had a Tuesday with your traffic on it either. Meanwhile the failure that will actually hurt you is not a six-hour outage at either vendor, it is a silent divergence between two copies you assumed were identical, discovered a month later.
The right response to an outage at your host is not to change hosts. It is to check whether the outage cost you access or cost you data, because those are different problems with different fixes. Access problems are solved by having a local clone and a way to work offline. Data problems are solved by not having a single copy in the first place. Changing vendors solves neither, and resets whatever operational knowledge you had.
What the law gives you, and what it does not
If you or your vendor are in the EU, there is a legal floor under all of this, and it is worth knowing because it is better than most contracts. The EU Data Act was published in the Official Journal on 22 December 2023 and applies since 12 September 2025 [5]. Its switching rules require that providers of platform and software as a service “make open interfaces available and, at a minimum, export data in a commonly used and machine-readable format” [5]. What counts as portable is defined rather than assumed: the data key for switching “comprises input and output data, including metadata, generated by the customer’s use of the service, excluding data protected by intellectual property rights or constituting a trade secret” [5]. On money the regulation is blunt. It “will also entirely remove switching charges, including charges for data egress, from 12 January 2027”, and during the transitional window before that date providers may still charge the costs they incur on switching and egress [5].
Read that as a floor and not a plan. It gives you a right to leave and, from 2027, a right to leave without paying for the exit, which is genuine leverage. It does not give you a working copy of your data at 9am on the morning the account stops opening, it does not make the export lossless, and the carve-out for trade secrets and intellectual property means it is not a promise that everything comes out. Treat it as the backstop that stops a bad situation from becoming permanent, and treat your own export as the thing that stops the bad situation from starting.
A staged way to say yes
Say yes in stages, and give each stage a date. Stage one is mirror only, where the new tool syncs a copy and the old store keeps receiving your writes. Cursor’s synced mode is exactly this, and Cursor documents it as such [1]. Nothing is at risk, and you learn the only thing that matters, which is whether sync stays clean when you are not watching.
Stage two is a real dependency on something small. Pick one project you could lose without a phone call, make the new tool authoritative for that project only, and run it for a full billing cycle including at least one period where you are away from your desk. Watch for divergence rather than downtime.
Stage three is the export drill, which is the step everyone skips. Once, on a calendar reminder, export everything, open it without the vendor’s app, and try to answer one real question from the export alone. If you cannot, you are not in stage three yet, whatever the toggle says.
Only then consider moving anything you would be sad to lose, and even then keep a mirror pointing the other way for as long as the vendor allows it. The cost of holding a redundant copy is a few dollars and a small amount of tidiness. The cost of finding out you had one copy is measured in weeks.
What still goes wrong
The honest failure of this approach is that it makes you slower than people who just say yes, and some of the time they are right. Depth on one platform is how small teams get good at anything, and a policy of permanent reversibility means never committing hard enough to get the benefit. If you are deliberately building your working life around one vendor’s workflow, that is a legitimate choice, and this guide’s caution will cost you real speed. Know which one you are doing before you start.
The second problem is that the checks above verify a moment, not a trajectory. An export that is complete today can quietly lose fidelity when a feature is added, and a product where you are the source of truth today can change that in a release note you do not read. Origin is in early beta [1], and a product in beta is the least stable thing you can point a policy at. The current state of any of them, including everything cited here, is a snapshot on the date in this page’s header. Re-run the export drill on a schedule rather than trusting the result of the one you ran during a trial.
Third, none of this addresses the case where the vendor is fine and you are the problem: an expired card, a mistyped domain at renewal, an account tied to an email address you no longer control. Those failures take away access with no incident page to point at and no vendor to escalate to, which is precisely why the copy you hold yourself is the part of this guide that matters most.
- 01Cursor — Origin: code hosting built for agents (changelog)cursor.com
- 02Cursor — Pricingcursor.com
- 03Cursor — How your data is usedcursor.com
- 04GitHub Docs — About migrations between GitHub products with GitHub Enterprise Importerdocs.github.com
- 05European Commission — Data Act explaineddigital-strategy.ec.europa.eu
- 06Notion — Export your contentnotion.com
- 07Zapier — Import and export Zap workflows in your Team or Enterprise accounthelp.zapier.com
- 08TechCrunch — Cursor capitalizes on GitHub frustration, launches rival hosting platformtechcrunch.com