GitHub collects your registration details, payment information, profile data, and records how you use the platform including pages visited, features used, your IP address, and device information.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The breadth of collection covers both identity-linked data (name, email, payment) and behavioral data (usage patterns, device fingerprint), meaning GitHub builds a detailed profile of both who you are and how you use the service.
The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.
View change record →New explicit disclosure of comprehensive data collection practices including IP addresses and device information, providing greater transparency about monitoring scope.
View full change record →The policy authorizes collection of identifiers, payment data, device information, IP address, browser type, operating system, and usage activity from all users interacting with GitHub services.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
To stop us collecting your location information, you can update your device settings, stop using the Service, or uninstall our mobile apps.
"We collect information directly from you for registration, payment, and profile purposes. Usage data we collect includes information about how you interact with our services, such as the pages you view, the features you use, and the actions you take. We also collect device and connection information, including IP address, browser type, operating system, and referring URLs.Excerpt from GitHub's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 5 (data minimization and purpose limitation), Article 13 (transparency at point of collection), and CCPA sections requiring disclosure of categories of personal information collected.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The breadth of collection covers both identity-linked data (name, email, payment) and behavioral data (usage patterns, device fingerprint), meaning GitHub builds a detailed profile of both who you are and how you use the service.
The policy authorizes collection of identifiers, payment data, device information, IP address, browser type, operating system, and usage activity from all users interacting with GitHub services.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.