Self-hosted agents require Privacy Mode, not Privacy Mode (Legacy). Regular Privacy Mode still enforces zero data retention with all model providers, so your code is not stored or used for training by them. The difference is that regular Privacy Mode allows Cursor to temporarily store code data needed for agent workspaces to function.
Since you’re on a team, your team admin will need to switch the privacy setting: Dashboard > Settings > switch from “Privacy Mode (Legacy)” to “Privacy Mode”. If you are the admin, you can do this yourself.