Provision record
GitHub · GitHub Copilot Product Terms · View original document ↗

Prompt Data Handling and Retention

Medium severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The terms state that Prompts (code and contextual data sent to GitHub) are encrypted in transit, deleted after Suggestions are generated, and not used for any other purpose by default. Retention occurs only under three enumerated conditions: CLI or non-editor tool usage, private language model fine-tuning requests, and alternative data handling configurations such as third-party extension enablement.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the default data lifecycle for Prompt data and defines the conditions under which retention is triggered. Enterprise organizations with source code confidentiality requirements or data minimization obligations under GDPR or similar frameworks should map their active Copilot configurations against the three retention conditions specified in Section 6(B).

Consumer impact (what this means for users)

Under these terms, Prompt data including submitted code and chat input is deleted by default after Suggestions are returned. The agreement states that retention applies when users access Copilot through CLI tools, enable private language model fine-tuning, or configure third-party extension integrations, meaning the applicable data handling treatment depends on which product features are active.

Cross-platform context

See how other platforms handle Prompt Data Handling and Retention and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.

Excerpt from GitHub's Copilot Product Terms

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR data minimization and storage limitation principles, as well as CCPA obligations regarding the processing of personal information, to the extent that Prompt data constitutes or contains personal data.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
GitHub Copilot Product Terms
Entity
GitHub
Document last updated
May 11, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074179
Document ID
CA-D-00776
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
84c17d24d27ade5447d26fe46e6147312edfe991c45fa6a641e9ab5d665ed29c
Analysis generated
July 12, 2026 14:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Copilot Product Terms
Record ID: CA-P-074179
Captured: 2026-07-12 14:12:12 UTC
SHA-256: 84c17d24d27ade54…
URL: https://conductatlas.com/platform/github/github-copilot-product-terms/provision/CA-P-074179/prompt-data-handling-and-retention/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does GitHub's Prompt Data Handling and Retention clause do?

This provision establishes the default data lifecycle for Prompt data and defines the conditions under which retention is triggered. Enterprise organizations with source code confidentiality requirements or data minimization obligations under GDPR or similar frameworks should map their active Copilot configurations against the three retention conditions specified in Section 6(B).

How does this clause affect you?

Under these terms, Prompt data including submitted code and chat input is deleted by default after Suggestions are returned. The agreement states that retention applies when users access Copilot through CLI tools, enable private language model fine-tuning, or configure third-party extension integrations, meaning the applicable data handling treatment depends on which product features are active.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.