Microsoft Copilot — privacy & data policy
Provider: Microsoft. PromptPrivacy score: 44/100. Last verified August 26, 2026.
What happens to your data?
Microsoft collects your prompts, chat interactions, account details, and uploaded files to operate and personalize its services. This data may be used to train and refine AI models and is subject to automated and human review. Information is stored in global data centers and may be shared with affiliates, service providers, and advertising partners.
Does it train on your data?
Microsoft uses customer data, including text, queries, and interactions, to develop, train, and fine-tune AI models and large language models (LLMs). Training and product improvement may involve both automated processing and manual human review of data and outputs.
Can you opt out?
Users can delete their Copilot activity history, manage privacy settings via the privacy dashboard, and opt out of personalized advertising. However, the provided policy text does not specify an explicit self-serve toggle to opt out of AI model training for consumer accounts.
Data retention
Microsoft retains personal data for as long as necessary to provide products, fulfill transactions, resolve disputes, secure systems, and meet legal and contractual obligations. Actual retention timelines vary based on the context and sensitivity of the data.
Encryption & security
Microsoft states that it uses encryption when transmitting highly confidential data (such as credit card numbers or passwords) over the internet and maintains physical and procedural safeguards at its data centers.
Is it safe for work?
Consumer Microsoft accounts should be used with caution for sensitive business data because inputs and interactions may be used for AI model training and manual human review. For business use, organizations should utilize enterprise work or school accounts (Microsoft 365 Copilot / Entra ID) governed by organizational administration.
Source policy: https://privacy.microsoft.com/en-us/privacystatement