Sourcegraph Cody · Sourcegraph Cody Usage and Privacy · View original document ↗

Third-Party Data Sharing and Embeddings

High severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Sourcegraph Cody recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Sourcegraph Cody Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Your code queries are sent to third-party AI providers. If your administrator enables the embeddings feature, a full copy of your code repository is also sent to a third-party AI provider.

This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that enabling the embeddings feature triggers transmission of full repository contents to a third-party provider, which is an operationally significant data sharing event that may not be apparent to individual users and is controlled at the administrator level.

Consumer impact (what this means for users)

Under this provision, both individual code queries and, if embeddings are enabled by an administrator, entire repository contents are transmitted to third-party LLM providers. The scope of this data sharing is stated to be limited to service provision, but the activation of embeddings represents a broader data transfer than routine query processing.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Skillshare Medium

We may share your information with third-party vendors and service providers that perform services on our behalf, such as payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance. We may also share your information with third-party advertising p...

Bumble Medium

We may also share your personal information with third parties that assist us in providing our services, or where we are under an obligation to report to. But rest assured: we will only ever share your personal information in the limited circumstances described in this Policy.

See all platforms with this clause type →

Monitoring

Sourcegraph Cody has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Yes. Cody sends LLM Prompts to a third-party LLM provider. In addition, when an administrator turns on the feature to generate embeddings for a repository, a copy of the repository contents will be shared with a third-party LLM provider for the sole purpose of providing you the service.

— Excerpt from Sourcegraph Cody's Sourcegraph Cody Usage and Privacy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Transmission of full repository contents to third-party providers engages GDPR data transfer requirements, including requirements for data processing agreements and, for cross-border transfers, appropriate transfer mechanisms. CCPA service provider rules require that shared data be used only for the specified purpose. The provision states the sole purpose is service provision, which should be reflected in applicable DPAs. If repositories contain personal data, data subject notification obligations may be relevant. GOVERNANCE EXPOSURE: High. The embeddings feature involves transmission of entire codebases to a third-party provider, which is a materially broader data sharing event than individual query processing. This may include proprietary algorithms, credentials, personal data of employees or customers embedded in code, or regulated information. Administrator-level control over this feature means individual users may not be aware of the extent of data sharing. JURISDICTION FLAGS: EU and EEA organizations must ensure that full repository transfers to third-party LLM providers are covered by valid data processing agreements and, where applicable, Standard Contractual Clauses or other GDPR transfer mechanisms. California organizations should assess whether repository contents include personal information subject to CCPA. Organizations in regulated industries such as financial services or healthcare should assess whether repository contents include regulated data before enabling embeddings. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should document which third-party LLM providers receive repository data when embeddings are enabled and ensure those providers are covered by appropriate DPAs. The document does not name the specific third-party LLM providers, which may require supplementary disclosure requests. Administrator training on the data sharing implications of enabling embeddings is advisable. COMPLIANCE CONSIDERATIONS: Organizations should classify repository contents before enabling embeddings and conduct a data protection impact assessment covering the full repository transfer. Access controls for the embeddings feature should be reviewed to ensure only appropriately authorized administrators can enable it. Data maps should be updated to reflect this third-party transfer pathway.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over data sharing practices and representations about the scope of third-party data transfers in commercial software services.
    File a complaint →
  • State AG
    State attorneys general in California and other states with comprehensive privacy laws have authority over third-party data transfers that may involve personal information under CCPA and similar statutes.
    File a complaint →

Applicable regulations

Connecticut Data Privacy Act Amendments
US-CT
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Sourcegraph Cody Usage and Privacy
Entity
Sourcegraph Cody
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011943
Document ID
CA-D-00817
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b8ff7d30f484b2079ef67f58f5a212ce1a3c8e732db00a2420391e9f5a6bdb14
Analysis generated
May 12, 2026 16:26 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Sourcegraph Cody
Document: Sourcegraph Cody Usage and Privacy
Record ID: CA-P-011943
Captured: 2026-05-12 16:26:00 UTC
SHA-256: b8ff7d30f484b207…
URL: https://conductatlas.com/platform/sourcegraph-cody/sourcegraph-cody-usage-and-privacy/third-party-data-sharing-and-embeddings/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Sourcegraph Cody's Third-Party Data Sharing and Embeddings clause do?

This provision discloses that enabling the embeddings feature triggers transmission of full repository contents to a third-party provider, which is an operationally significant data sharing event that may not be apparent to individual users and is controlled at the administrator level.

How does this clause affect you?

Under this provision, both individual code queries and, if embeddings are enabled by an administrator, entire repository contents are transmitted to third-party LLM providers. The scope of this data sharing is stated to be limited to service provision, but the activation of embeddings represents a broader data transfer than routine query processing.

Is ConductAtlas affiliated with Sourcegraph Cody?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.