Change record
CA-C-001456 Top 5%
GitHub Privacy Statement
Entity
Date detected
April 28, 2026
Effective date
April 27, 2026
Severity
Direction
Negative
Taxonomy
Ai training rights
Changes
+3 sentences added · −2 sentences removed · 8 sentences modified

Impact Summary

High Negative for users
Affected users
All users EU users UK users

GitHub updated its Privacy Statement on April 28, 2026 to explicitly authorize collection and use of AI outputs from user-provided content, and to broaden the scope of personal data sharing with affiliates to include product development and AI/machine learning training. The statement also removed specific language describing the conditions under which GitHub personnel may access private repositories and replaced it with a reference to the Terms of Service. These changes expand the stated purposes for data use and affiliate sharing without adding explicit opt-out mechanisms.

1 new obligation 1 obligation expanded 1 protection removed

Data controllers using GitHub: If your organization processes user data on GitHub, you must now acknowledge that GitHub will use some of that data to train and improve AI technologies.

All users: GitHub now states it collects AI-generated outputs alongside code and text you provide, expanding what data it considers collected from your use.

All users: Details about when GitHub staff can access your private repositories are no longer in the privacy policy; you must refer to the Terms of Service for those specifics.

Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.

Historical Context

This is the 2nd significant Ai Training Rights change GitHub has made since ConductAtlas began monitoring.

Across all monitored documents, GitHub has made 3 significant changes.

Key Clauses Affected

AI outputs in collected data

The policy now explicitly includes AI outputs alongside user-provided code and content as collected personal data, expanding the scope of what GitHub considers data collection.

Affiliate data sharing for AI/ML

The policy now explicitly authorizes sharing personal data with Microsoft and other GitHub affiliates for product development and AI/ML model training, removing the prior limitation that affiliate use must be consistent with the privacy statement.

Private repository access conditions

The policy removes the explicit list of conditions under which GitHub may access private repositories and directs users to the Terms of Service instead, reducing privacy-policy-level transparency about these access practices.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
ad856e2f671fd7f64342016df39012ee8fe0b0e642759d355a7eb7e0f0f08cab
March 19, 2026 15:02 UTC
✓ Verified
Current Version
b36cbcc068012375c4a0d88eb7699d8a007a4c8b93ea435d81210244c50bf16d
April 28, 2026 06:21 UTC
✓ Verified
Change Detected
April 28, 2026 06:21 UTC
Analysis Methodology
Citation Record
Entity: GitHub
Document: GitHub Privacy Statement
Record ID: CA-C-001456
Captured: 2026-04-28 06:21:11 UTC
URL: https://conductatlas.com/change/2026-04-28-github-github-privacy-statement-1456/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

This change expands stated data processing purposes to explicitly include AI/ML model training and improvement, and broadens affiliate data sharing authority to include these purposes. Organizations subject to GDPR, CCPA, or similar privacy regimes should …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001456.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
GitHub Privacy Statement
Entity
GitHub
Captured
April 28, 2026
Source URL
https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
Other changes to GitHub Privacy Statement
Next change Jul 11, 2026
GitHub's privacy policy header was updated on July 11, 2026, with a minor structural change to the navigation breadcrumb. The …
Low Neutral
View full version history →
More from GitHub
Jul 21, 2026 Low
GitHub Copilot Business Privacy Statement

GitHub added 'Opens in new tab' link annotations to several URLs and references in their GitHub Copilot Trust Center, detected …

Jul 16, 2026 Low
GitHub Privacy Statement

GitHub's Privacy Statement was detected with a formatting change on July 16, 2026. The table of contents header 'Site policy …

Jul 16, 2026 Low
GitHub Terms of Service

GitHub removed navigation and structural language from the header of its Terms of Service document, detected in an update on …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track GitHub policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All GitHub changes →