24 Total
12 High severity
11 Medium severity
1 Low severity

Key Facts

What liability limit does Sourcegraph Cody apply to breaches of confidentiality or data security in connection with the customer's use of Cody?
Sourcegraph Cody applies a liability limit of five times the customer's annual license fees to breaches of confidentiality or data security in connection with the customer's use of Cody.
What prevails over the terms governing a customer's order form in the event of a conflict?
Sourcegraph Cody's Terms of Use prevail over the terms governing a customer's order form in the event of a conflict.
For what purposes does Sourcegraph Cody use Customer Content?
Sourcegraph Cody uses Customer Content solely to provide the service and not for product improvement purposes.
Who owns all inputs to and outputs generated by a customer's use of Sourcegraph Cody?
As between the parties, the customer owns all inputs to and outputs generated by their use of Sourcegraph Cody.
Will Sourcegraph Cody indemnify customers against claims alleging that their use of Cody or any Cody outputs infringes third-party intellectual property rights?
Sourcegraph Cody will indemnify customers against claims alleging that their use of Cody or any Cody outputs infringes third-party intellectual property rights, in accordance with the indemnification terms in the customer's agreement.
Does Sourcegraph Cody collect or have access to User Prompts or Responses for customers with an enterprise license who bring their own LLM API key for a self-hosted deployment?
Sourcegraph Cody does not collect or have access to User Prompts or Responses for customers with an enterprise license who bring their own LLM API key for a self-hosted deployment.
Do Sourcegraph and Sourcegraph Partner LLMs use code from Cody Enterprise or Cody Pro teams to train models?
Sourcegraph and Sourcegraph Partner LLMs do not use code from Cody Enterprise or Cody Pro teams to train models.
What does Sourcegraph Cody prohibit customers from using Cody for?
Sourcegraph Cody prohibits customers from using Cody for unlawful purposes or in violation of Sourcegraph's Acceptable Use Policy.
For what purpose does Sourcegraph Cody share a copy of the repository contents with a third-party LLM provider when an administrator enables the embeddings feature for a repository?
When an administrator enables the embeddings feature for a repository, Sourcegraph Cody shares a copy of the repository contents with a third-party LLM provider for the sole purpose of providing the service.
Do Sourcegraph Cody's commitments regarding data used to train the LLM and data retention apply if the customer uses their own LLM relationship in conjunction with Cody?
Sourcegraph Cody's commitments regarding data used to train the LLM and data retention may not apply if the customer uses their own LLM relationship in conjunction with Cody.
Stay ahead of the changes
Track Sourcegraph Cody and get the diff the day its terms change.
Summary

Sourcegraph Cody's privacy and usage terms establish that you own your prompts and outputs, and Sourcegraph will not use your code to train AI models. If a third party claims your use of Cody infringes their intellectual property, Sourcegraph will cover that claim, with no cap on that coverage if you use a signed Order Form and the current version with Sourcegraph's provided filters. However, if you use your own LLM relationship with Cody, some of Sourcegraph's data and retention commitments may not apply to you.

Analysis

This document establishes the substantive data, intellectual property, and liability framework governing customer use of Sourcegraph Cody. It allocates ownership of all inputs and outputs to the customer, restricts Sourcegraph's use of Customer Content solely to service delivery, and commits Sourcegraph Partner LLMs to zero retention of inputs, outputs, and embeddings beyond the time required to generate a response. Sourcegraph Cody provides IP indemnification for third-party infringement claims, which is uncapped for customers who have signed an Order Form and use the current version with provided filters, while liability for confidentiality or data security breaches is capped at five times the customer's annual license fees. Data isolation guarantees are strongest for enterprise customers who self-host with their own LLM API key, and Sourcegraph's training and retention commitments may not apply when a customer brings their own LLM relationship.

What this means for you

As an individual user, your prompts and outputs belong to you, and Sourcegraph Cody will not use your code to improve its products or train models. If your organization enables the embeddings feature, a copy of your repository contents is shared with a third-party LLM provider, though that provider retains nothing beyond the time needed to generate a response. If you are an enterprise user who self-hosts Cody with your own LLM API key, Sourcegraph Cody does not collect or access your prompts or responses at all. If your organization uses its own LLM relationship, you should verify which of Sourcegraph's data commitments still apply to your deployment, as some may not.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

24 provisions
12 featured
10 clause types
12 high severity
Intellectual Property 2 1 high
Acceptable Use Restrictions 1 1 high
Data Retention 1 1 high
General Contract Terms 1 1 high
Stay ahead of the changes

Monitoring

Sourcegraph Cody has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle 5x Annual Fee Cap for Confidentiality Breach and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 12, 2026 06:09 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000817
Version ID CA-V-002503
SHA-256 b585243b4c0c3ac3a145eb74f178b27a3d36b51c358275f84eb50809e242bf66
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans