Microsoft 365 Copilot — privacy & data policy

Provider: Microsoft. PromptPrivacy score: 90/100. Last verified July 26, 2026.

What happens to your data?

Your data is processed within the Microsoft 365 ecosystem to provide AI responses and is not used to train the underlying AI models. It remains subject to your organization's existing security, privacy, and compliance controls, including data residency and encryption standards.

Does it train on your data?

Prompts, responses, and data accessed through Microsoft Graph are explicitly not used to train foundation LLMs.

Can you opt out?

Yes, users can delete their activity history, and admins can manage connected experiences and feedback settings.

Data retention

Data is stored in alignment with contractual commitments for Microsoft 365 content; admins can set retention policies via Microsoft Purview.

Encryption & security

Customer content is encrypted at rest and in transit using BitLocker, per-file encryption, TLS, and IPsec; also supports Microsoft Purview Information Protection.

Is it safe for work?

Yes, the service is designed for enterprise use with robust compliance, isolation, and administrative controls.

Source policy: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy