142 Total
46 High severity
84 Medium severity
12 Low severity

Key Facts

Does Microsoft use information submitted to Copilot Health to develop or train generative AI models?
Microsoft does not use information submitted to Copilot Health to develop or train generative AI models, nor for advertising or marketing purposes.
Does Microsoft use information submitted to Copilot Health for advertising or marketing purposes?
Microsoft does not use information submitted to Copilot Health to develop or train generative AI models, nor for advertising or marketing purposes.
Does Microsoft prohibit using K-12 student personal data for advertising?
Microsoft prohibits using or sharing K-12 student personal data for advertising or similar commercial purposes, including personalized advertising directed at students.
Does Microsoft prohibit sharing K-12 student personal data for personalized advertising directed at students?
Microsoft prohibits using or sharing K-12 student personal data for advertising or similar commercial purposes, including personalized advertising directed at students.
Does Microsoft collect users' browsing history?
Microsoft collects users' browsing history.
What content does Microsoft collect?
Microsoft collects the content of files and communications, including emails, chats, calls, meetings, photos, and documents that users create or share using Microsoft products.
Does Microsoft collect the content of files and communications that users create or share using Microsoft products?
Microsoft collects the content of files and communications, including emails, chats, calls, meetings, photos, and documents that users create or share using Microsoft products.
Does Microsoft collect location data from users' devices?
Microsoft collects location data from users' devices, which may be precise (e.g., GPS, cell tower, or Wi-Fi hotspot) or imprecise (e.g., inferred from an IP address).
May location data collected by Microsoft be precise or imprecise?
Microsoft collects location data from users' devices, which may be precise (e.g., GPS, cell tower, or Wi-Fi hotspot) or imprecise (e.g., inferred from an IP address).
When does Microsoft disclose personal data to law enforcement?
Microsoft discloses personal data to law enforcement and other parties when it has a good faith belief that disclosure is necessary to comply with applicable law or respond to valid legal process.
Stay ahead of the changes
Track Microsoft and get the diff the day its terms change.
Summary

This document explains what data Microsoft collects about you—including your location, browsing history, and the content of your emails, chats, and files—and how Microsoft uses that data, including to show you ads on Microsoft and other companies' sites and to train its AI systems. Your employer controls your work account and can access everything you create or store through it. A few categories of data have special protections: what you share with Copilot Health won't be used for ads or AI training, and personalized ads won't be shown to users whose accounts indicate they are under 18.

Analysis

The Microsoft Privacy Statement establishes the terms under which Microsoft collects, uses, shares, and retains personal data across its products and services. It sets out broad data collection practices encompassing browsing history, precise and imprecise location data, and the full content of user communications and files including emails, chats, calls, photos, and documents. The statement permits Microsoft to use collected data for advertising on both Microsoft and third-party properties through automated profiling processes, and to use user data to develop, train, and fine-tune AI models including large language models. It carves out explicit restrictions for specific contexts: health data submitted to Copilot Health is excluded from AI training and advertising use; K-12 student personal data is excluded from advertising and commercial use; personalized advertising is withheld from users whose Microsoft accounts identify them as under 18; and Windows Recall data is stored locally on-device and not transmitted without affirmative user action. The statement also vests employing organizations with control over, and the right to access and process, data created by users operating under work accounts.

What this means for you

As an individual user, Microsoft collects your location, browsing history, and the actual content of your communications and files, and uses that data to serve targeted ads across Microsoft and third-party sites and to build AI systems. If you use a work account, your employer—not you—controls and can access that data. What you share through Copilot Health is protected from AI training and advertising use. Windows Recall stores its continuous record of on-screen activity only on your device and does not transmit it unless you take action to do so. If you play Xbox games or use network-connected apps, the publisher of that game or app can access your user identifier, gamertag, country, age range, and gameplay data.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

9 important changes detected

11 versions captured · Last updated: August 2026

What changed Microsoft updated its Privacy Statement in an update detected on August 1, 2026, making changes primarily to document structure, formatting, and specific product disclosures. The document now includes a table of contents and updated navigation structure. The substantive change adds explicit language stating that Microsoft may share age group information with Microsoft apps, services, and third-party apps to apply safeguards and tailor experiences. Additionally, new language describes the Screenshot feature in Sticky Notes, clarifying that users can capture, view, edit, and annotate content from other apps within the note application.
Why this matters The updated terms explicitly state that Microsoft may share age group information with Microsoft apps, services, and third-party apps to apply appropriate safeguards, tailor experiences, and comply with applicable laws and regulations. This clarifies an existing practice rather than establishing a new one, and the stated purpose is to apply protective measures for minors. The document also adds technical detail about the Sticky Notes screenshot feature, explaining that captured content can be viewed, edited, and annotated within the application.
View full change record →
What changed Microsoft's privacy policy table of contents was updated on June 30, 2026, with a single sentence modification. The specific textual change involved updating a reference in the document navigation, replacing 'Window' with 'MSN Windows Mixed Real' in the product-specific details section. This appears to be a minor organizational or product categorization update with no material change to privacy rights, data practices, or user obligations.
Why this matters No material change to consumer privacy rights, data collection practices, or user obligations is evident from this update. The revision affects the organizational structure of Microsoft's privacy policy documentation rather than substantive privacy terms. No specific consumer actions are required.
View full change record →

June 28, 2026 low

Microsoft's Privacy Statement table of contents was reorganized on June 28, 2026. Several product and feature references were relocated or renamed within the document structure: 'Microsoft Family' became 'Microsoft Family …

View change record →
June 26, 2026 medium

Microsoft substantially reorganized and rewrote its privacy statement on June 26, 2026. The company removed detailed explanations of specific third-party data sources it previously disclosed (data brokers, public social media …

View change record →
April 19, 2026 medium

Microsoft modified its data retention policy language on April 19, 2026. Previously, the policy described specific retention criteria including whether customers expected data to be retained until they removed it, …

View change record →
April 8, 2026 low

Microsoft's Privacy Statement was updated on April 8, 2026, with 2 sentences added, 11 sentences removed, and 10 sentences modified. The document previously contained specific language across these sections that …

View change record →
April 1, 2026 medium

Microsoft revised its data retention policy language on April 1, 2026. Previously, the policy outlined specific retention criteria including whether customers expected data retention until deletion, whether automated deletion controls …

View change record →
March 13, 2026 medium

Microsoft updated its Privacy Statement in March 2026 with two substantive changes: removal of language describing additional rights for European Economic Area users, and addition of language authorizing contact via …

View change record →
March 5, 2026 medium

Microsoft removed a sentence from its privacy statement that described consent-based marketing contact via auto-dialer and prerecorded voice technology potentially generated using AI. The updated document no longer explicitly discloses …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

142 provisions
12 featured
20 clause types
46 high severity
Data Collection 39 13 high
Show all 39 data collection provisions
Restricted or Prohibited Content/Industries 2 2 high
Monetization Rules 1 1 high
Stay ahead of the changes

Monitoring

Microsoft has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Children under 13 require parental consent for Microsoft account and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 1, 2026 00:10 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000001
Version ID CA-V-005414
SHA-256 038c77f4e0e0960bdacc607fc616e0fe9c09d77f584fa91f8e3c4c3050fea6dd
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans