Knowledge · Is this AI tool safe · 8 minutes

Does Copilot collect your data? Consumer, Microsoft 365, GitHub

What happens to data in Copilot: model training, retention, where it is processed and how to turn it off. Three products, three rule sets, October 2026.

Last updated: October 5, 2026

Does Copilot collect data? Short version: it depends which Copilot

Copilot is a brand, not one product. Three of them matter for data: consumer Microsoft Copilot (copilot.com and the app, signed in with a personal Microsoft account), Copilot for organizations (signed in with a Microsoft Entra ID work account, formerly Microsoft 365 Copilot) and GitHub Copilot for developers.

Watch the names. According to Microsoft Learn (as of September 2026), Microsoft 365 Copilot is now called Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. So one name now covers both the personal and the business version. What separates them is the account you sign in with, not the app name.

Every version processes what you type, otherwise it could not answer. The real questions are whether it is stored, for how long, who can see it and whether it is used to train models. Each version answers differently. The wider rules for pasting data into chatbots are in our article on whether you can paste data into ChatGPT.

Does Copilot use your data to train AI models?

Consumer Copilot (personal account). According to the "Privacy FAQ for Microsoft Copilot", Microsoft may use conversations to train its generative models. Excluded from training are: users signed in with a work Entra ID account, users of Copilot inside Microsoft 365 apps on Personal and Family plans, signed-out users, users under 18, users who opted out, and users in Brazil, China (excluding Hong Kong), Israel, Nigeria, South Korea and Vietnam. Before training, Microsoft says it removes names, phone numbers, email addresses, account identifiers and similar data.

The same FAQ states that conversations are stored for 18 months by default and that some of them go through automated and human review. You cannot opt out of review done for safety purposes.

Copilot on a work account. According to "Data, Privacy, and Security for Microsoft Copilot", prompts, responses and data pulled from Microsoft Graph (mail, files, chats) are not used to train foundation models. Chat history is stored like other Microsoft 365 content, and the admin sets its retention in Microsoft Purview. Microsoft also says business Copilot has opted out of the human-review abuse monitoring available in Azure OpenAI.

GitHub Copilot. On 25 March 2026 GitHub announced that from 24 April 2026 interaction data on the Free, Pro and Pro+ plans (including code you type, context around the cursor, file names, repository structure, accepted suggestions) may be used to train models unless the user opts out. This includes code from private repositories while you work with Copilot. The data may be shared with affiliates, including Microsoft. Business and Enterprise plans are not affected by this change.

Where is Copilot data processed and under what legal basis?

Personal account: the Microsoft Privacy Statement (September 2026 version) applies. For transfers outside the EU, Microsoft relies on the EU-U.S. Data Privacy Framework and standard contractual clauses approved by the European Commission. There is no processing agreement with your company here, because the contracting party is a private person.

Work account: Copilot and Copilot Chat are covered by the Data Protection Addendum (DPA) and the Product Terms, with Microsoft acting as a data processor. Microsoft calls this set of commitments Enterprise Data Protection, shown in the app by a green shield. For EU customers Copilot is an EU Data Boundary service, meaning EU traffic is meant to stay inside the EU data boundary.

There are two exceptions worth knowing. First, Anthropic models offered in Copilot as a subprocessor are, according to Microsoft, excluded from the EU Data Boundary. Second, in spring 2026 Microsoft introduced "flex routing" for EU and EFTA customers: during peak demand, model processing of prompts may happen in the United States, Canada or Australia. Data at rest is meant to stay inside the EU Data Boundary, except for limited pseudonymized data. According to Microsoft Learn (as of 29 September 2026) flex routing is on by default for tenants created after 25 March 2026, and admins of older tenants are advised to check their setting.

GitHub Copilot Business and Enterprise: GitHub says data on these plans is protected by its data protection agreement and cannot be used for training without the customer's explicit authorization. The processing location for an individual Free or Pro account is not described in these materials.

How to turn off data collection in Copilot, step by step

Consumer Copilot in the browser (copilot.com): click your profile icon, then your profile name, choose Privacy and turn off "Training on conversation activity" and "Training on voice conversations". In the Windows or macOS app: profile icon, Settings, Privacy, the same two switches. On a phone: menu, profile icon, Account, Privacy. Opting out covers future conversations. Memory is in the same profile under Memory, "Personalization and memory".

Copilot on a work account (admin): 1. Make sure staff sign in with Entra ID and see the green shield. 2. In the Microsoft 365 admin center go to Copilot, Settings, View all, "Flex routing during peak load periods" and choose "Do not allow flex routing" if data must stay in the EU. 3. In the same place review "AI providers operating as Microsoft subprocessors". 4. Set retention for Copilot chats in Microsoft Purview. 5. Block sign-in with personal Microsoft accounts on company devices if your policy requires it.

GitHub Copilot Free, Pro, Pro+ (according to GitHub Docs also Max): click your profile picture, choose Copilot settings, and set "Allow GitHub to use my data for AI model training" to Disabled. If you had already turned off data collection for product improvements, GitHub says that choice has been kept.

Before you paste a config file or a chunk of logs into Copilot, you can check in your browser whether it contains a key or token. Nothing is sent anywhere.

Known incidents and regulator positions

CVE-2025-32711, named EchoLeak by researchers (published 11 June 2025). Microsoft described it as AI command injection in M365 Copilot that lets an unauthorized attacker disclose information over a network. CVSS 3.1 score: 9.3, critical. The CVE record marks the fix as official. It is an example of prompt injection: malicious content in a document or email that Copilot reads changes how it behaves.

SURF, the Dutch IT cooperative for higher education, published a data protection impact assessment (DPIA) of Microsoft 365 Copilot in December 2024 and advised against using it for the time being. After an update in September 2025 and a second update on 27 May 2026, SURF says two risks remain at medium level: an opaque filter that stops AI from judging employees, and retention of pseudonymized diagnostic data for up to 18 months. Flex routing was added as a new low risk. SURF's advice: use it cautiously and assess each use case separately.

We found no public decision or position by the Polish data protection authority (UODO) specifically on Copilot (as of October 2026).

Copilot at work: when it makes sense and when it does not

It makes sense when staff sign in with work accounts, the company has a DPA with Microsoft and permissions in SharePoint, OneDrive and Teams are in order. Copilot only shows what the user can at least read. If the payroll folder is shared with the whole company, Copilot will surface it to anyone who asks. Review permissions first, buy licenses second.

It does not make sense when people use personal accounts for company work. Those chats then follow consumer rules, including training and 18 months of retention, and the company has no visibility. That is a typical case of shadow AI. The same goes for GitHub Copilot Free or Pro on company code: unless the switch is off, code may end up in training.

Write the rules into your company AI use policy: which accounts, which data, who approves new tools. For comparison, see how the same questions look for ChatGPT, Gemini and DeepSeek.

What we do not know

The current consumer Copilot FAQ does not list the European Economic Area among the training exclusions. We found no clear Microsoft statement on whether conversations of users in Poland or elsewhere in the EU are used for training today. Check the switch in your profile instead of assuming.

Microsoft does not say how often or for how long flex routing actually kicks in. It only says peak periods are typically limited in duration.

GitHub's March 2026 announcement does not state how long interaction data from individual plans is kept for training. It is also unknown whether data already used for training can later be removed from a finished model.

In short

  • Copilot is three different products. What happens to data depends on the account (personal or Entra ID) and the plan, not the app name.
  • On a personal account, chats may be used for training and are kept for 18 months by default. Training can be switched off under Privacy.
  • On a work account the DPA applies and foundation models are not trained on your data, but Copilot sees everything the employee can access. Fix permissions before rollout.
  • EU admins should make a deliberate choice on flex routing and on AI providers acting as subprocessors.
  • On GitHub Copilot Free, Pro and Pro+, interaction data may be used for training by default since 24 April 2026. For company code use Business or Enterprise, or turn the switch off.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Does Copilot save my conversations?

Yes. Consumer Copilot stores conversations for 18 months by default and you can delete them. On a work account conversations are stored in Microsoft 365 and the admin sets retention.

Does Microsoft 365 Copilot train AI on company data?

According to Microsoft, no: prompts, responses and Microsoft Graph data are not used to train foundation models. This applies when you sign in with an Entra ID account covered by Enterprise Data Protection.

Does GitHub Copilot use my code for training?

According to GitHub, on Free, Pro and Pro+ plans yes since 24 April 2026, unless you turn it off in Copilot settings. On Business and Enterprise plans GitHub says no, not without the customer's explicit authorization.

Does Copilot data stay in the EU?

For EU work accounts Copilot is an EU Data Boundary service, with exceptions: Anthropic models sit outside that boundary, and with flex routing on, processing may happen in the US, Canada or Australia.

Is Copilot a GDPR problem for personal data?

It depends on the version. With a work account Microsoft acts as a processor under the DPA. With a personal account used for company work there is no processing agreement, so pasting customer data is hard to justify.

Sources

  1. Microsoft: Privacy FAQ for Microsoft Copilot
  2. Microsoft: Microsoft Copilot privacy controls
  3. Microsoft Learn: Data, Privacy, and Security for Microsoft Copilot
  4. Microsoft Learn: Flex routing (EU and EFTA)
  5. GitHub Blog: Updates to GitHub Copilot interaction data usage policy (25 March 2026)
  6. GitHub Docs: Managing GitHub Copilot policies as an individual subscriber
  7. CVE.org: CVE-2025-32711 (M365 Copilot)
  8. SURF: Privacy risks Microsoft 365 Copilot remain orange despite improvements (27 May 2026)

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also