GitHub · GitHub Copilot Product Terms · View original document ↗

Prompt Data Handling and Retention

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time GitHub changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity GitHub recorded 7 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for GitHub Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The terms state that Prompts (code and contextual data sent to GitHub) are encrypted in transit, deleted after Suggestions are generated, and not used for any other purpose by default. Retention occurs only under three enumerated conditions: CLI or non-editor tool usage, private language model fine-tuning requests, and alternative data handling configurations such as third-party extension enablement.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the default data lifecycle for Prompt data and defines the conditions under which retention is triggered. Enterprise organizations with source code confidentiality requirements or data minimization obligations under GDPR or similar frameworks should map their active Copilot configurations against the three retention conditions specified in Section 6(B).

Consumer impact (what this means for users)

Under these terms, Prompt data including submitted code and chat input is deleted by default after Suggestions are returned. The agreement states that retention applies when users access Copilot through CLI tools, enable private language model fine-tuning, or configure third-party extension integrations, meaning the applicable data handling treatment depends on which product features are active.

Cross-platform context

See how other platforms handle Prompt Data Handling and Retention and similar clauses.

Compare across platforms →

Monitoring

GitHub has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.

Excerpt from GitHub's Copilot Product Terms

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR data minimization and storage limitation principles, as well as CCPA obligations regarding the processing of personal information, to the extent that Prompt data constitutes or contains personal data. The FTC Act's prohibition on unfair or deceptive practices is relevant to the accuracy of the retention disclosures made here. The document directs readers to the GitHub Data Protection Agreement at gh.io/dpa for further detail, which would govern processor obligations under GDPR Article 28 if applicable. (2) GOVERNANCE EXPOSURE: Medium. The default deletion commitment is operationally significant for organizations subject to data minimization obligations. However, the three retention conditions in Section 6(B) create configuration-dependent data handling outcomes that may not be uniformly visible to enterprise administrators or end users, creating a disclosure gap risk in regulated environments. (3) JURISDICTION FLAGS: EU/EEA organizations face heightened exposure under GDPR, particularly regarding lawful basis for Prompt processing and whether the retention conditions satisfy transparency requirements under Article 13/14. California-based organizations should evaluate whether Prompt data containing personal information triggers CCPA disclosure or deletion rights. Where source code constitutes trade secret or confidential business information, retention conditions may also engage contractual confidentiality obligations. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify that the GitHub Data Protection Agreement at gh.io/dpa contains adequate GDPR Article 28 processor commitments and addresses sub-processor disclosure for any third-party extensions that trigger the retention condition in Section 6(B)(iii). The document does not identify specific sub-processors, and vendor assessments should address this gap. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a data mapping exercise to document Prompt data flows under each of the three retention conditions. Internal policies governing which Copilot configurations employees may activate should be reviewed to ensure alignment with organizational data minimization commitments. Where the organization operates under GDPR, a review of the legal basis for Prompt processing and whether retention conditions are adequately disclosed in employee or user-facing privacy notices may be warranted.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data handling practices, relevant to whether the Prompt retention disclosures in Section 6 are accurate and adequately communicated to users
    File a complaint →

Provision details

Document information
Document
GitHub Copilot Product Terms
Entity
GitHub
Document last updated
May 11, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074179
Document ID
CA-D-00776
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
84c17d24d27ade5447d26fe46e6147312edfe991c45fa6a641e9ab5d665ed29c
Analysis generated
July 12, 2026 14:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Copilot Product Terms
Record ID: CA-P-074179
Captured: 2026-07-12 14:12:12 UTC
SHA-256: 84c17d24d27ade54…
URL: https://conductatlas.com/platform/github/github-copilot-product-terms/provision/CA-P-074179/prompt-data-handling-and-retention/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does GitHub's Prompt Data Handling and Retention clause do?

This provision establishes the default data lifecycle for Prompt data and defines the conditions under which retention is triggered. Enterprise organizations with source code confidentiality requirements or data minimization obligations under GDPR or similar frameworks should map their active Copilot configurations against the three retention conditions specified in Section 6(B).

How does this clause affect you?

Under these terms, Prompt data including submitted code and chat input is deleted by default after Suggestions are returned. The agreement states that retention applies when users access Copilot through CLI tools, enable private language model fine-tuning, or configure third-party extension integrations, meaning the applicable data handling treatment depends on which product features are active.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.