Sourcegraph states it does not intentionally collect sensitive categories of personal data such as health, biometric, or racial information, and that submitting such data violates the terms of service.
This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a policy-level commitment not to collect sensitive data categories, but the qualifier 'intentionally' means that if such data is inadvertently submitted through code repositories or prompts, the policy does not guarantee it will not be processed.
Interpretive note: The 'not intentionally' qualifier creates ambiguity regarding whether inadvertent collection of sensitive data through AI prompts or repository content triggers the same protections, which may vary by jurisdiction.
Sourcegraph states it does not intentionally collect sensitive personal data, but users who submit code or prompts containing embedded sensitive data (such as health records or biometric identifiers) should be aware that the 'not intentionally' qualifier means inadvertent processing is not explicitly excluded.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
You can contact us in order to (1) update or correct your personally identifiable information, (2) change your preferences with respect to communications and other information you receive from us, or (3) delete the personally identifiable information maintained about you...
Access information about you consistent with legal requirements. In addition, you may have the right in some cases to receive or have your electronic information transferred to another party.
"Sourcegraph does not intentionally collect 'Sensitive Personal Information,' such as personal data revealing racial, ethnicity, political and religious beliefs, trade union membership, or genetic, biometric, health, or sexual data. Providing Sensitive Personal Information violates our Terms of Use.Excerpt from Sourcegraph Cody's Sourcegraph Privacy Policy
1) REGULATORY LANDSCAPE: Sensitive personal data categories are subject to heightened protection under GDPR Article 9, which generally requires explicit consent or a specific exemption for processing.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a policy-level commitment not to collect sensitive data categories, but the qualifier 'intentionally' means that if such data is inadvertently submitted through code repositories or prompts, the policy does not guarantee it will not be processed.
Sourcegraph states it does not intentionally collect sensitive personal data, but users who submit code or prompts containing embedded sensitive data (such as health records or biometric identifiers) should be aware that the 'not intentionally' qualifier means inadvertent processing is not explicitly excluded.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.