9 Total
2 High severity
7 Medium severity
0 Low severity

Key Facts

Does GitHub use Copilot Business or Enterprise data to train AI models?
GitHub does not use Copilot Business or Enterprise data to train AI models.
What is Prompts as a defined data category?
GitHub collects Prompts as a defined data category, consisting of chat or code inputs along with context that are sent to Copilot's AI to generate suggestions.
What does Prompts consist of?
GitHub collects Prompts as a defined data category, consisting of chat or code inputs along with context that are sent to Copilot's AI to generate suggestions.
What infrastructure and encryption does GitHub Copilot use?
GitHub Copilot uses Azure infrastructure and encryption to support its service.
What does GitHub collect from users?
GitHub collects Feedback Data from users, comprising real-time reactions, optional comments, and feedback from support tickets.
What comprises Feedback Data?
GitHub collects Feedback Data from users, comprising real-time reactions, optional comments, and feedback from support tickets.
Does GitHub apply the same consistent governance controls and assurance model to Copilot regardless of the use case?
GitHub applies the same consistent governance controls and assurance model to Copilot regardless of the use case.
What does GitHub Copilot include?
GitHub Copilot includes an AI-based vulnerability prevention system that blocks insecure coding patterns in real-time.
What does the AI-based vulnerability prevention system block?
GitHub Copilot includes an AI-based vulnerability prevention system that blocks insecure coding patterns in real-time.
What does GitHub Copilot generate?
GitHub Copilot generates Suggestions — AI-produced code lines or chat responses — based on user prompts.
Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Summary

This document describes what data GitHub collects when you use Copilot Business or Enterprise — including your code inputs, chat messages, and how you interact with suggestions — and what GitHub does with it. Importantly, GitHub does not use your Business or Enterprise data to train its AI models. The service runs on Azure infrastructure and applies the same security and governance standards regardless of how Copilot is used.

Analysis

This document establishes GitHub's data practices for the Copilot Business and Enterprise tiers, defining the categories of data GitHub collects, how that data is used, and the limitations that apply. GitHub collects Prompts (user chat and code inputs with context), Suggestions (AI-generated outputs), User Engagement Data (pseudonymous interaction records including accepted or dismissed completions, error messages, and system logs), and Feedback Data (real-time reactions, optional comments, and support ticket feedback). A core restriction established by the document is that GitHub does not use Copilot Business or Enterprise data to train its AI models. The service operates on Azure infrastructure with encryption, applies a consistent governance and assurance model across all Copilot use cases, and includes an AI-based vulnerability prevention system that intervenes on user-generated code patterns in real-time.

What this means for you

When using Copilot Business or Enterprise, your code inputs, chat messages, and surrounding context are collected as Prompts and sent to Copilot's AI to generate suggestions. GitHub also records pseudonymous behavioral data about how you interact with those suggestions, such as whether you accept or dismiss them, along with error messages and system logs. Your feedback — reactions, comments, and support ticket content — is also collected. GitHub does not use any of this Business or Enterprise data to train its AI models. An AI-based system actively intervenes on your code in real-time to block insecure patterns as you work.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

4 important changes detected

6 versions captured · Last updated: July 2026

What changed GitHub added 'Opens in new tab' link annotations to several URLs and references in their GitHub Copilot Trust Center, detected on July 21, 2026. The change adds visual indicators that external links will open in a new browser tab. This is a formatting and navigation enhancement with no material change to privacy, security, or data handling practices.
Why this matters This change has no material impact on consumer rights, data handling, or the terms governing GitHub Copilot Business. The updated language adds HTML annotations indicating that certain links open in new browser tabs, a standard web accessibility and usability practice. No new obligations, restrictions, or permissions are introduced.
View full change record →
What changed GitHub updated its Copilot Business Privacy Statement on June 24, 2026 by reorganizing and expanding the FAQ section. The document previously listed certification resources and began a FAQ section with limited questions visible. The updated version removes some certification file links and restructures the FAQ to explicitly surface questions about third-party testing, personal data processing, and AI model training, along with detailed descriptions of data categories processed (suggestions, feedback data, prompts, and user engagement data). This reorganization makes privacy-relevant questions and data processing information more directly accessible within the statement.
Why this matters The updated privacy statement makes information about Copilot data processing more transparent by organizing key questions in the FAQ section. The statement now explicitly discloses what personal data is processed (suggestions, feedback data, prompts, and user engagement data), addresses third-party testing and certifications, and directly states whether business and enterprise data is used to train AI models. Users can review these disclosures in the reorganized FAQ without searching through longer policy text.
View full change record →

June 21, 2026 low

GitHub updated its GitHub Copilot Business Privacy Statement on June 21, 2026 by adding a date range to one of its compliance certifications. The SOC 3 Report reference now specifies …

View change record →
May 13, 2026 low

GitHub updated its Copilot Business Privacy Statement on May 13, 2026 by adding compliance documentation to its public resources section. The document now includes PCI DSS v4.0.1 compliance matrices and …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

9 provisions
9 featured
5 clause types
2 high severity
AI / Automated Decision-Making 1
Disclosure and Transparency Requirements 1
Stay ahead of the changes

Monitoring

GitHub has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle No training on Business or Enterprise data and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured August 7, 2026 00:41 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000775
Version ID CA-V-005572
SHA-256 f09e29426803dd127beb377bd63599e684ebf0e0844aff10876b393a30d92571
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans