Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
Sourcegraph Cody's privacy and usage terms establish that you own your prompts and outputs, and Sourcegraph will not use your code to train AI models. If a third party claims your use of Cody infringes their intellectual property, Sourcegraph will cover that claim, with no cap on that coverage if you use a signed Order Form and the current version with Sourcegraph's provided filters. However, if you use your own LLM relationship with Cody, some of Sourcegraph's data and retention commitments may not apply to you.
This document establishes the substantive data, intellectual property, and liability framework governing customer use of Sourcegraph Cody. It allocates ownership of all inputs and outputs to the customer, restricts Sourcegraph's use of Customer Content solely to service delivery, and commits Sourcegraph Partner LLMs to zero retention of inputs, outputs, and embeddings beyond the time required to generate a response. Sourcegraph Cody provides IP indemnification for third-party infringement claims, which is uncapped for customers who have signed an Order Form and use the current version with provided filters, while liability for confidentiality or data security breaches is capped at five times the customer's annual license fees. Data isolation guarantees are strongest for enterprise customers who self-host with their own LLM API key, and Sourcegraph's training and retention commitments may not apply when a customer brings their own LLM relationship.
As an individual user, your prompts and outputs belong to you, and Sourcegraph Cody will not use your code to improve its products or train models. If your organization enables the embeddings feature, a copy of your repository contents is shared with a third-party LLM provider, though that provider retains nothing beyond the time needed to generate a response. If you are an enterprise user who self-hosts Cody with your own LLM API key, Sourcegraph Cody does not collect or access your prompts or responses at all. If your organization uses its own LLM relationship, you should verify which of Sourcegraph's data commitments still apply to your deployment, as some may not.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Sourcegraph Cody has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle 5x Annual Fee Cap for Confidentiality Breach and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.