If you connect Cody to your own AI provider instead of Sourcegraph's partners, Sourcegraph's promises about data retention, training restrictions, and data handling no longer apply.
This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Customers using a bring-your-own-LLM configuration lose all of Sourcegraph's data protection commitments regarding Zero Retention and training restrictions, and must rely entirely on their own agreements with their LLM provider.
This provision creates a two-tier data protection posture: customers using Sourcegraph Partner LLMs receive Zero Retention and no-training commitments, while customers using their own LLM configurations do not. The practical scope of data protection for bring-your-own-LLM customers depends entirely on their direct LLM provider agreements.
How other platforms handle this
We also require these service providers to protect your personal information to at least the same standards that we do.
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud
"The following Sourcegraph commitments may not apply if you use your own LLM relationship in conjunction with Cody: Any representations regarding data used to train the LLM; Any representations regarding data retention (including Zero Retention), data collection, or data use by the LLM.Excerpt from Sourcegraph Cody's Usage and Privacy
REGULATORY LANDSCAPE: For organizations in the EU and EEA, the carve-out means that GDPR data processing commitments for LLM interactions may be absent when a customer uses their own LLM.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Customers using a bring-your-own-LLM configuration lose all of Sourcegraph's data protection commitments regarding Zero Retention and training restrictions, and must rely entirely on their own agreements with their LLM provider.
This provision creates a two-tier data protection posture: customers using Sourcegraph Partner LLMs receive Zero Retention and no-training commitments, while customers using their own LLM configurations do not. The practical scope of data protection for bring-your-own-LLM customers depends entirely on their direct LLM provider agreements.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.