GitHub Copilot (Individual) — privacy & data policy

Provider: GitHub/Microsoft. PromptPrivacy score: 36/100. Last verified August 26, 2026.

What happens to your data?

Your code, inputs, prompts, and outputs are gathered alongside account and device telemetry. This data is used to provide the service, shared with Microsoft affiliates and third-party vendors, and used to train AI models. Data is stored for the lifetime of your active account.

Does it train on your data?

GitHub processes user data—including code, inputs, AI outputs, documents, and feedback—to improve services and explicitly train machine learning and artificial intelligence models across GitHub and Microsoft affiliates.

Can you opt out?

You can opt out of non-essential cookies and marketing tracking, or email GitHub to exercise data subject objection and deletion rights. The general policy does not provide a direct self-service toggle for opting individual Copilot prompts out of model training.

Data retention

Personal data is kept for as long as your account remains active and as required to meet legal obligations, resolve disputes, and maintain service agreements. Specific retention windows for individual telemetry and model interactions are not detailed.

Encryption & security

Not specified in detail. The policy notes that administrative, technical, and physical safeguards are maintained, but specific encryption standards (e.g., TLS, AES-256) or certifications (SOC 2, ISO 27001) are not enumerated in the text.

Is it safe for work?

Caution is advised for proprietary work under the Individual plan, as user inputs and code can be utilized for AI and machine learning model training and product improvement. Organizations should use GitHub Enterprise accounts with a formal Data Protection Agreement to protect confidential code.

Source policy: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement