Provision record
GitHub · GitHub Copilot Business Privacy Statement · View original document ↗

Data Categories Processed by Copilot

Medium severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The document identifies four categories of data processed by Copilot: AI-generated suggestions, user feedback including reactions and support ticket feedback, user prompts and associated context, and pseudonymous engagement data including accepted/dismissed completions, error messages, system logs, and product usage metrics.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Change history

added Jul 21, 2026

Introduces granular transparency regarding specific data types processed by Copilot, enabling customers to understand their data exposure in operational terms.

View full change record →

Consumer impact (what this means for users)

The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact GitHub Support to submit a data subject access or deletion request covering prompt and engagement data associated with your Copilot account.

Cross-platform context

See how other platforms handle Data Categories Processed by Copilot and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Data used Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts. Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets. Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions. User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.

Excerpt from GitHub's Copilot Business Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The disclosure of four data categories, including prompt content and pseudonymous identifiers, engages GDPR data subject rights obligations and the requirement to maintain a Record of Processing Activities under Article 30.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
GitHub Copilot Business Privacy Statement
Entity
GitHub
Document last updated
May 11, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015174
Document ID
CA-D-00775
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
26511138518c56fd5be42d6fd5b0a779f11a61a1ff0bdb996a06d1a2c8e02876
Analysis generated
July 9, 2026 07:21 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Copilot Business Privacy Statement
Record ID: CA-P-015174
Captured: 2026-07-09 07:21:59 UTC
SHA-256: 26511138518c56fd…
URL: https://conductatlas.com/platform/github/github-copilot-business-privacy-statement/provision/CA-P-015174/data-categories-processed-by-copilot/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does GitHub's Data Categories Processed by Copilot clause do?

This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot.

How does this clause affect you?

The agreement discloses that Copilot processes prompt content including code and context inputs, which may include source code, intellectual property, or sensitive business information submitted by users during coding sessions. Pseudonymous engagement data, including system logs and product usage metrics, is also collected from user interactions.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.