GitHub keeps your personal data for as long as it needs to for service delivery, legal compliance, dispute resolution, and contract enforcement, with specific timeframes varying by data type.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy does not specify retention periods for individual data categories, stating instead that retention is based on necessity and legal obligation; this means users cannot determine from this document alone how long specific types of data will be held.
Interpretive note: Specific retention periods for individual data categories are not disclosed in the policy text, making it unclear how long particular types of personal data are held in practice.
The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.
View change record →Added explicit commitment to "delete or anonymize" data when no longer needed, providing stronger transparency about data lifecycle management.
View full change record →The policy authorizes retention of personal data across all collected categories for an unspecified duration tied to operational necessity and legal requirements; specific retention periods are not disclosed in this document.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"GitHub retains personal data for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer needed, GitHub will delete or anonymize it. Specific retention periods vary by data type and applicable legal requirements.Excerpt from GitHub's Privacy Statement
(1) REGULATORY LANDSCAPE: Data retention practices implicate GDPR Article 5(1)(e) (storage limitation), which requires personal data to be kept no longer than necessary for the purposes for which it is processed.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy does not specify retention periods for individual data categories, stating instead that retention is based on necessity and legal obligation; this means users cannot determine from this document alone how long specific types of data will be held.
The policy authorizes retention of personal data across all collected categories for an unspecified duration tied to operational necessity and legal requirements; specific retention periods are not disclosed in this document.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.