Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document describes what data GitHub collects when you use Copilot Business or Enterprise — including your code inputs, chat messages, and how you interact with suggestions — and what GitHub does with it. Importantly, GitHub does not use your Business or Enterprise data to train its AI models. The service runs on Azure infrastructure and applies the same security and governance standards regardless of how Copilot is used.
This document establishes GitHub's data practices for the Copilot Business and Enterprise tiers, defining the categories of data GitHub collects, how that data is used, and the limitations that apply. GitHub collects Prompts (user chat and code inputs with context), Suggestions (AI-generated outputs), User Engagement Data (pseudonymous interaction records including accepted or dismissed completions, error messages, and system logs), and Feedback Data (real-time reactions, optional comments, and support ticket feedback). A core restriction established by the document is that GitHub does not use Copilot Business or Enterprise data to train its AI models. The service operates on Azure infrastructure with encryption, applies a consistent governance and assurance model across all Copilot use cases, and includes an AI-based vulnerability prevention system that intervenes on user-generated code patterns in real-time.
When using Copilot Business or Enterprise, your code inputs, chat messages, and surrounding context are collected as Prompts and sent to Copilot's AI to generate suggestions. GitHub also records pseudonymous behavioral data about how you interact with those suggestions, such as whether you accept or dismiss them, along with error messages and system logs. Your feedback — reactions, comments, and support ticket content — is also collected. GitHub does not use any of this Business or Enterprise data to train its AI models. An AI-based system actively intervenes on your code in real-time to block insecure patterns as you work.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
4 important changes detected
6 versions captured · Last updated: July 2026
GitHub updated its GitHub Copilot Business Privacy Statement on June 21, 2026 by adding a date range to one of its compliance certifications. The SOC 3 Report reference now specifies …
View change record →GitHub updated its Copilot Business Privacy Statement on May 13, 2026 by adding compliance documentation to its public resources section. The document now includes PCI DSS v4.0.1 compliance matrices and …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
GitHub has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle No training on Business or Enterprise data and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.