GitHub · GitHub Privacy Statement · View original document ↗

Data Retention

Medium severity Medium confidence Explicitdocumentlanguage Common · 135 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for GitHub Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

GitHub keeps your personal data for as long as it needs to for service delivery, legal compliance, dispute resolution, and contract enforcement, with specific timeframes varying by data type.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy does not specify retention periods for individual data categories, stating instead that retention is based on necessity and legal obligation; this means users cannot determine from this document alone how long specific types of data will be held.

Interpretive note: Specific retention periods for individual data categories are not disclosed in the policy text, making it unclear how long particular types of personal data are held in practice.

Recent Activity

This document changed recently

High Apr 28, 2026

The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.

View change record →

Consumer impact (what this means for users)

The policy authorizes retention of personal data across all collected categories for an unspecified duration tied to operational necessity and legal requirements; specific retention periods are not disclosed in this document.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a data deletion request via https://support.github.com/contact/privacy to request that GitHub delete your personal data not subject to legal retention requirements.

How other platforms handle this

Grindr Medium

We retain personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. The specific retention periods depend on the type of information and the purposes for which it is processed.

Threads Medium

We keep information for as long as we need it to provide our products, comply with legal obligations, or for other legitimate purposes, such as to maintain safety, security, and integrity.

Hinge Medium

After your account is deleted, we keep data about interactions you've had on our service to prevent abuse, ban evaders and others in an effort to protect and ensure the safety and security of our service and our members.

See all platforms with this clause type →

Monitoring

GitHub has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
GitHub retains personal data for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer needed, GitHub will delete or anonymize it. Specific retention periods vary by data type and applicable legal requirements.

— Excerpt from GitHub's GitHub Privacy Statement

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: Data retention practices implicate GDPR Article 5(1)(e) (storage limitation), which requires personal data to be kept no longer than necessary for the purposes for which it is processed. CCPA also requires reasonable retention periods. The Irish DPC and California Privacy Protection Agency are the primary enforcement authorities. Retention policies that are broadly stated without specific periods may face scrutiny under storage limitation requirements. (2) GOVERNANCE EXPOSURE: Medium. The absence of specific retention periods in the policy creates a compliance disclosure gap; while internal retention schedules may exist, they are not surfaced to users in this document, limiting users' ability to exercise rights based on retention status. (3) JURISDICTION FLAGS: EU/EEA users have the strongest standing to challenge indefinite or overly broad retention under GDPR storage limitation principles. California residents can request deletion under CCPA, but GitHub's retention for legal obligation purposes may limit the scope of deletion available. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should request GitHub's data retention schedule as part of procurement due diligence and confirm that retention periods for enterprise user data align with the enterprise's own data governance policies and legal hold obligations. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should request GitHub's internal retention schedule, verify that deletion requests result in timely purging of data not subject to legal hold exceptions, and assess whether GitHub's anonymization practices meet the standard for true anonymization under applicable law.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data retention practices and can investigate whether retention policies are adequately disclosed to consumers.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
GitHub Privacy Statement
Entity
GitHub
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-003601
Document ID
CA-D-00254
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d21b58443ca0b4402240dbd06996ada072c72ed842fcccc6b13acab2d7bc6c4d
Analysis generated
May 10, 2026 09:46 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Privacy Statement
Record ID: CA-P-003601
Captured: 2026-05-10 09:46:36 UTC
SHA-256: d21b58443ca0b440…
URL: https://conductatlas.com/platform/github/github-privacy-statement/data-retention/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does GitHub's Data Retention clause do?

The policy does not specify retention periods for individual data categories, stating instead that retention is based on necessity and legal obligation; this means users cannot determine from this document alone how long specific types of data will be held.

How does this clause affect you?

The policy authorizes retention of personal data across all collected categories for an unspecified duration tied to operational necessity and legal requirements; specific retention periods are not disclosed in this document.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 135 platforms. See the full comparison.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.