Key Facts
Can Sourcegraph Cody guarantee absolute security of data transmitted over the Internet?
Sourcegraph Cody cannot guarantee absolute security of data transmitted over the Internet.
Does Sourcegraph Cody permit limited data elements to remain accessible to an organization's administrators after a deletion request?
Sourcegraph Cody permits limited data elements to remain accessible to an organization's administrators as necessary to maintain the organizational workspace, even after a deletion request.
What may remain accessible to an organization's administrators even after a deletion request?
Sourcegraph Cody permits limited data elements to remain accessible to an organization's administrators as necessary to maintain the organizational workspace, even after a deletion request.
Does Sourcegraph Cody use personal data for decisions based solely on automated processing that produce legal effects or similarly significantly affect a user?
Sourcegraph Cody does not use personal data for decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect a user.
What will Sourcegraph Cody do if notified that a child under the age of 18 has provided personal data?
Sourcegraph Cody will investigate and, if appropriate, delete personal data if notified that a child under the age of 18 has provided personal data.
How long does Sourcegraph Cody retain limited data elements necessary to maintain the integrity of the organizational workspace?
Sourcegraph Cody retains limited data elements necessary to maintain the integrity of the organizational workspace for as long as the organization maintains an active workspace.
What does Sourcegraph Cody not sell or share personal data for?
Sourcegraph Cody does not sell or share personal data for cross-context behavioral advertising as defined under applicable privacy laws.
What does Sourcegraph Cody not intentionally collect?
Sourcegraph Cody does not intentionally collect government-issued identification numbers, health information, or other sensitive personal data as defined under applicable law.
What does Sourcegraph Cody rely on for transfers of personal data originating from the EEA, UK, or Switzerland?
Sourcegraph Cody relies on Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office for transfers of personal data originating from the EEA, UK, or Switzerland.
Does Sourcegraph Cody rely on Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office?
Sourcegraph Cody relies on Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office for transfers of personal data originating from the EEA, UK, or Switzerland.
Summary
This document explains how Sourcegraph Cody handles your personal data: it collects metadata about your AI interactions (such as prompt titles and interaction patterns), keeps your data for as long as your service relationship is active, and does not sell it for targeted advertising. If you ask for your data to be deleted, some data may still remain accessible to your organization's administrators for as long as your organization uses the service.
Analysis
This privacy policy establishes Sourcegraph Cody's data collection, retention, sharing, and automated-processing practices for users of the Cody service. It prohibits the sale or sharing of personal data for cross-context behavioral advertising, automated decision-making that produces legal or similarly significant effects on users, and intentional collection or extraction of sensitive personal data or personal data from User Content—though each prohibition is qualified by the word 'intentionally,' leaving inadvertent collection outside its scope. Personal data is retained on an open-ended basis tied to contractual obligations, with certain data elements persisting indefinitely for organizational workspace integrity even after individual deletion requests. Cross-border transfers of personal data originating from the EEA, UK, or Switzerland are conducted under Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office.
What this means for you
As an individual user, your personal data is collected in the form of AI usage metadata—including prompt titles, prompt categories, and interaction patterns—and is retained for as long as Sourcegraph Cody needs it to deliver the service. A deletion request does not guarantee full removal: limited data elements remain accessible to organizational administrators for as long as the organization maintains an active workspace. Sourcegraph Cody does not make solely automated decisions that legally or similarly significantly affect you. Sourcegraph Cody cannot guarantee the security of data transmitted over the Internet, and once you enable a third-party integration, Sourcegraph Cody does not control how that third party handles your data. If you believe a child under 18 has submitted personal data, you can notify Sourcegraph Cody to trigger an investigation and potential deletion.
2 important changes detected
3 versions captured · Last updated: July 2026
What changed
Sourcegraph Cody updated contact email addresses across its Privacy Policy in an update detected on July 28, 2026. The policy previously directed users to privacy@sourcegraph.com or other email addresses for different requests; the updated policy now routes most privacy-related requests to support@sourcegraph.com, security concerns to security@sourcegraph.com, and some requests to privacy@sourcegraph.com. This consolidates the contact points for exercising data subject rights, appealing denied requests, and reporting account compromises.
Why this matters
The updated policy redirects privacy-related contact requests to different email addresses. Most privacy rights requests, California privacy requests, and state privacy law requests now route to support@sourcegraph.com instead of privacy@sourcegraph.com; security concerns route to security@sourcegraph.com; and child data requests route to privacy@sourcegraph.com. No changes were made to what rights users have or how requests are handled, only where to send them.
View full change record →
What changed
Sourcegraph updated its Privacy Policy on June 16, 2026 with substantial restructuring and expanded definitions. The policy previously stated it did not apply to customer data processed under business agreements; the updated version now explicitly distinguishes between data Sourcegraph collects as a controller (covered by the policy) and user content processed on behalf of customers (covered by separate customer agreements). The policy added a detailed index, expanded definitions of data types (Account Information, Activity Data, Analytics Data), and clarified the scope of coverage for website visitors, service users, and communication recipients.
Why this matters
The updated policy clarifies that Sourcegraph's Privacy Policy covers personal data it collects directly when individuals visit the website, use services, or receive communications. The policy explicitly states it does not cover user content (such as code) processed through services on behalf of customers, which is instead governed by separate customer agreements. The restructuring adds detailed definitions of data categories and creates a navigable index, but does not appear to materially change what data is collected or how it is used.
View full change record →
Archival ProvenanceSource & Archival Record
Last Captured
July 28, 2026 01:22 UTC
Capture Method
Automated scheduled archival capture
Document ID
CA-D-000799
Version ID
CA-V-005324
SHA-256
3fc04ba4ecee5813c81fe513139ca6b284044ada331f19d5c4b6871366f0855b
✓ Snapshot stored
✓ Text extracted
✓ Change verified
✓ Hash verified