Microsoft Copilot can be used safely for many personal and business tasks, but there is no single
privacy policy called “the Copilot policy.” The consumer companion, Copilot inside Microsoft 365 home apps, work Copilot protected by a Microsoft Entra account, Copilot Studio agents and GitHub Copilot process different context under different terms.
The short answer is:
Microsoft Copilot is reasonably safe for ordinary use when you identify the exact product, choose the correct account, minimize sensitive data and verify important output. It is not confidential by assumption, error-free or authorized to make high-impact decisions on its own.
For features and product names, start with our
complete Microsoft Copilot guide. If you are still setting up the consumer assistant, use our
how-to guide for Microsoft Copilot. Teams deploying custom agents should pair this risk guide with the
Copilot Studio guide. This article focuses on data, access,
security and risk.
First identify which Copilot you are using
The logo is not enough. Account, app and feature determine the rule.
| Copilot experience | Typical account | Model-training position | Conversation or interaction storage |
| Consumer Microsoft Copilot app or website | Personal Microsoft or supported third-party account | Eligible signed-in consumer conversations may be used unless the user opts out; regional and user-category exclusions apply | Conversation activity is stored for 18 months by default; users can delete history |
| Copilot in Microsoft 365 apps for home | Microsoft 365 Personal, Family or Premium owner | Prompts, responses and file contents are not used to train foundation models | Activity can remain visible and can be managed through Microsoft’s privacy dashboard |
| Microsoft 365 Copilot Chat with enterprise data protection | Work or school Microsoft Entra account | Prompts and responses are not used to train foundation models | Prompts and responses are logged in the Microsoft 365 tenant and governed by applicable retention and eDiscovery |
| Microsoft 365 Copilot for work | Licensed work or school account | Prompts, responses and Microsoft Graph data are not used to train foundation models | Stored under the organization’s Microsoft 365 contractual and compliance controls |
| Copilot Studio agent | Organization’s Power Platform environment | Microsoft says Azure OpenAI-based prompt data is not used to train foundation models; external models and connected services need separate review | Conversation transcripts are normally saved to Dataverse, with a default 30-day cleanup job that admins can change or disable |
| GitHub Copilot individual | GitHub Free, Pro, Pro+ or Max | GitHub may use interaction data for model improvement subject to the individual opt-out setting | Varies by feature, provider, logs and agent session; no one retention number covers the entire product |
| GitHub Copilot Business or Enterprise | Organization-managed GitHub account | GitHub says customer data is not used to train AI models | Governed by GitHub product terms, organization settings, repositories, logs and feature-specific handling |
This table is a starting point, not a substitute for a contract. Optional connectors, web search, preview models, external agents and bring-your-own-key providers can add another data processor and another retention rule.
Five different questions hidden inside “safe”
Evaluate Copilot across five dimensions:
- Privacy: Who processes prompts, files and retrieved data, and can they be used for training?
- Security: Can someone access the account, connected systems, code or agent tools?
- Reliability: Can Copilot invent a fact, omit evidence or misunderstand a request?
- Action safety: What can an agent create, send, execute, change or delete?
- Compliance: Does the product, contract and configuration meet the organization’s obligations?
A product can have strong encryption and still give a wrong legal answer. It can avoid training on a prompt and still retain the prompt for history, audit or safety. It can respect Microsoft 365 permissions and still reveal a file that was already overshared.
Does Microsoft Copilot use your conversations for training?
There are four distinct answers.
Consumer Microsoft Copilot
Microsoft says it uses conversation activity from eligible signed-in consumer Copilot users for AI training unless they opt out. This can include text, voice and some image activity after Microsoft’s described de-identification steps.
Uploaded files need a narrower statement. Microsoft’s consumer privacy FAQ says a shared file and conversations about it are treated like other conversation activity subject to the user’s training and personalization choices. A separate
file-upload support page says Microsoft does not use the content of uploaded files for model training. Image-generation documentation separately says uploaded images can be included in conversation activity for training unless the user opts out. The safest reading is to distinguish file content, the surrounding prompt and response, and feature-specific image handling instead of claiming that every upload follows one rule.
Microsoft excludes certain users and countries, and it says unsigned users’ conversations are not used for training. Because rollout and eligibility vary, inspect the current setting rather than guessing from geography.
The control affects future conversation activity. It does not necessarily reverse model-improvement work that already occurred.
Microsoft’s
consumer Copilot privacy FAQ explains the training control and exclusions. Training and personalization are separate switches: a user can opt out of training while leaving personalization on.
Copilot in Microsoft 365 apps for home
When a personal Microsoft 365 subscriber uses Copilot inside Word, Excel, PowerPoint, Outlook or OneNote, Microsoft says prompts, responses and file contents are not used to train foundation models.
That is a product-specific promise. It does not mean every conversation in the separate consumer Copilot app inherits the same rule merely because the same Microsoft account is used.
Read Microsoft’s current
home-app data and privacy guide for the exact surface.
Microsoft 365 Copilot and Copilot Chat at work
For organization accounts with enterprise data protection, Microsoft says prompts and responses are not used to train foundation models. Microsoft 365 Copilot’s retrieved Microsoft Graph data is also excluded from foundation-model training.
The protected data can include:
- prompts;
- generated responses;
- email and calendar context;
- Teams and meeting context;
- SharePoint and OneDrive content;
- and other permitted organizational data.
These claims are part of Microsoft’s commercial commitments, not a consumer opt-out setting. See the official
Microsoft 365 Copilot privacy documentation.
Copilot Studio and GitHub Copilot
For Copilot Studio prompt features running on Microsoft-hosted Azure OpenAI Service, Microsoft says customer prompts, grounding data and responses are not used to train or improve the foundation models.
An agent may use an external model, connector, website or custom API. The no-training claim for Microsoft’s model layer does not automatically govern those external services.
GitHub separately says Business and Enterprise customer data is not used to train AI models. Individual Copilot interaction data may be used, subject to the user’s setting.
Training, retention and memory are different
These terms are often collapsed into one misleading sentence.
- Training changes or improves a model using data.
- Retention means data remains stored for a period.
- History is the conversation a user can reopen.
- Memory or personalization means the product keeps or derives information to tailor future interactions.
- Audit logging preserves evidence for administration, compliance or investigation.
- Caching temporarily reuses data to improve service performance.
Turning off training does not delete chat history. Deleting history does not guarantee that every security log, backup, external copy or data already used in model training is immediately reversible. Turning off personalization does not necessarily erase the visible conversation list.
Ask each question separately.
How long does Microsoft Copilot keep conversations?
Consumer Copilot: 18 months by default
Microsoft says consumer Copilot conversation activity is stored for 18 months by default. Users can delete individual conversations or all history.
Uploaded files can also be stored for up to 18 months. Microsoft says file content itself is not used for model training, while the surrounding conversation and some image features can follow the consumer choices described above. Deleting promptly is better than relying on automatic expiry.
Some content can be subject to safety, legal or abuse-review processes. Microsoft also says a limited set of conversations may receive human review, including investigation of suspected Code of Conduct violations.
Microsoft 365 home apps
Activity history can remain visible in supported Microsoft 365 apps and can be exported or deleted from Microsoft’s privacy dashboard. Microsoft does not present the consumer Copilot app’s 18-month sentence as a universal retention term for every Microsoft 365 home interaction.
Microsoft 365 work accounts
Work Copilot prompts and responses can be logged and stored so that users can revisit chats and administrators can apply audit, eDiscovery and retention controls.
Microsoft says Copilot Chat prompts and responses are stored in Exchange within the tenant. The same kinds of retention policies used for Microsoft 365 Copilot can apply, but exact controls depend on the underlying subscription and the organization’s configuration.
There is therefore no truthful universal sentence such as “Microsoft deletes all business Copilot prompts after 30 days.” The tenant’s policy matters.
Copilot Studio
Copilot Studio normally writes agent conversation transcripts and metadata to Dataverse. The default bulk deletion job removes conversation transcript records older than 30 days.
Administrators can:
- prevent new transcripts from being saved;
- restrict viewing and downloading;
- apply environment-group rules;
- change the cleanup schedule;
- and delete existing records.
Turning saving off may affect analytics, and records can continue to appear for up to 24 hours after the setting changes. When SharePoint is used as knowledge, transcript data can include a user’s question and retrieved source content, making transcript governance especially important.
GitHub Copilot
GitHub Copilot does not have one useful retention number across completion, chat, local agents, cloud agents, code review, model providers, repositories and logs.
GitHub’s
model-hosting documentation describes provider-specific arrangements. It currently lists zero-data-retention arrangements for generally available OpenAI and Anthropic model features, but also names exceptions. Claude Fable 5 retains prompts and outputs for safety processing, and some beta or preview Anthropic features are outside GitHub’s general Anthropic ZDR coverage.
Repository content, branches, commits, pull requests, agent logs, Actions logs and user-created session persistence have their own lifecycles. “The model provider has ZDR” does not delete the pull request Copilot created.
Are Copilot conversations private?
They are not public by default, but “private” has limits.
Consumer conversations can be processed for product operation, personalization, training when eligible and enabled, and safety review. Work conversations can be visible through authorized administrative, audit, legal and eDiscovery processes. Copilot Studio makers with the appropriate roles can access agent transcripts. GitHub agent work can be visible in commits, pull requests and session logs.
Do not assume a chat creates:
- attorney-client privilege;
- medical confidentiality;
- protection of a journalistic source;
- a trade-secret safe harbor;
- an export-control exception;
- or permission under a nondisclosure agreement.
Those outcomes depend on law, contract, policy and configuration.
Before sharing protected information, identify:
- the product and account;
- the contractual terms;
- training settings;
- retention and deletion;
- authorized human and admin access;
- location and subprocessors;
- connected services;
- and whether the task can use redacted or synthetic data.
Microsoft 365 permissions: protection and hidden risk
Microsoft 365 Copilot only surfaces organizational data the current user has permission to view. That is a meaningful control.
It is not an automatic cure for poor permissions.
If a broad “Everyone” group can already access an old salary spreadsheet, Copilot may make that existing oversharing easier to discover. The model has not broken access control; it has removed the friction that previously hid the mistake.
Before rollout:
- inventory SharePoint and OneDrive sharing;
- remove stale links and broad groups;
- apply sensitivity labels;
- define site owners;
- restrict external sharing;
- review guest access;
- and test representative users.
Microsoft explicitly emphasizes permission hygiene in its
Microsoft 365 Copilot privacy documentation.
For product and administration details, read our
Microsoft 365 Copilot guide.
Web search is a separate data path
Microsoft 365 Copilot and Copilot Chat can create short web queries from a prompt and send them to Bing. Microsoft says user and tenant identifiers are removed, queries are not shared with advertisers and are not used to train foundation LLMs.
However, Bing operates separately from the Microsoft 365 service boundary under different data-handling terms. The EU Data Boundary and a HIPAA business associate agreement do not automatically cover web queries.
This matters when a prompt contains a sensitive project codename, unpublished acquisition target or patient detail. A generated web query may be shorter than the prompt, but sensitive words can still be sensitive.
Disable or govern web grounding where the use case does not justify it, and train users not to include protected information in a query intended for the public web.
Anthropic models have a separate residency boundary
Microsoft 365 Copilot, Researcher, Copilot Studio and Microsoft 365 apps can expose selected Anthropic models when the tenant permits them. That choice does not preserve every Microsoft-only data-location commitment.
- standard supported Anthropic use is covered by Microsoft’s enterprise framework, Product Terms, Data Protection Addendum and enterprise data protection when Anthropic operates as Microsoft’s subprocessor;
- Anthropic models in these Microsoft offerings are currently excluded from the EU Data Boundary and, where applicable, in-country processing commitments;
- EU, EFTA and UK tenants have Anthropic models disabled by default and must opt in;
- administrators can restrict provider access by user or group;
- some preview models with data retention use separate Anthropic commercial and data-processing terms, with Anthropic acting as an independent processor rather than a Microsoft subprocessor;
- those retention previews remain default-off even when standard Anthropic models are enabled.
Microsoft currently identifies Claude Fable 5 and Claude Mythos 5 as examples of preview models requiring retention. It says Anthropic stores most inputs and outputs for up to 30 days, with longer retention possible when trust-and-safety systems identify a potential policy violation. Anthropic says retained data is not used for model training without express permission.
For a tenant with strict residency, sovereign-cloud or regulated-processing requirements, “enterprise data protection” is therefore not the last question. Check the selected provider, model label, admin setting, processing region and applicable terms. Keep retention-preview models disabled unless the workload and contract have been explicitly approved.
Files, images, voice, Vision and browsing
Consumer Copilot can process more than typed text. A user may upload documents or images, speak, use Vision, open webpages or synchronize selected browsing data.
Each added modality increases context and exposure:
- an image can contain faces, addresses and metadata;
- a document can include hidden comments or customer records;
- screen vision can reveal notifications and unrelated windows;
- voice can capture bystanders;
- browser context can expose tabs, cookies or history;
- and personalization can preserve inferred preferences.
Microsoft says Copilot on Windows does not automatically scan and upload a user’s files merely because it displays recent items. A file is sent when the user selects or shares it with Copilot.
Before sharing:
- close unrelated content;
- remove hidden metadata and comments;
- redact identifiers;
- verify the active account;
- and check whether the feature has its own privacy notice.
Connectors, tools and agents
A connector can introduce another service, identity and permission scope. An agent can turn retrieved text into action.
Risks include:
- an overbroad OAuth grant;
- a maker-owned connection exposing more than the end user should see;
- prompt injection inside email or a document;
- an external service with different retention;
- a tool accepting unvalidated model output;
- and an action executed without meaningful confirmation.
Apply:
- least privilege;
- user-level authorization;
- connector allowlists;
- domain restrictions;
- typed inputs;
- deterministic validation;
- transaction limits;
- idempotency;
- human approval;
- and audit logs.
For Copilot Studio, Power Platform data policies can govern connectors, knowledge, HTTP, triggers and channels. Its transcripts can also be disabled or restricted by environment.
An agent’s output should be treated as a proposal. The application decides whether the current identity may perform the action.
Prompt injection
Prompt injection occurs when untrusted content contains instructions aimed at the AI. For example, a webpage might tell an agent to ignore its task and send data to another tool.
Microsoft uses filters and defenses, but no model-level instruction makes tool-using AI immune.
Reduce the risk:
- separate trusted instructions from retrieved content;
- treat documents, emails and websites as data;
- limit tools and data available in one session;
- block unapproved domains;
- require confirmation for external communication;
- validate destinations and parameters;
- and do not let a model authorize itself.
The higher the agent’s permissions, the more important deterministic controls become.
Is GitHub Copilot safe for private code?
It can be appropriate for private repositories under the correct plan and organization policy.
GitHub says:
- Business and Enterprise customer data is not used to train AI models;
- individual plan interaction data may be used subject to opt-out;
- models can be hosted by several providers under provider-specific arrangements;
- and Copilot output can still be incorrect, insecure or similar to public code.
The main coding risks are:
- secrets included in prompt context;
- insecure generated code;
- unsafe shell commands;
- malicious instructions in repository content;
- overpowered MCP servers;
- public-code and license issues;
- and merging an AI-authored pull request without independent review.
Use a private repository, but also use branch protection, code review, tests, secret scanning, dependency review, code scanning and narrowly scoped credentials. A private repository protects visibility; it does not prove generated code is safe.
Our
complete GitHub Copilot guide covers the workflow in depth.
Can Microsoft Copilot hallucinate?
Yes. Copilot can generate a confident statement that is unsupported, outdated or fabricated. Grounding and citations reduce risk but do not eliminate it.
Use an evidence workflow:
- ask for sources;
- open the source;
- check that it supports the exact claim;
- distinguish source fact from Copilot inference;
- confirm dates, units and jurisdiction;
- verify calculations independently;
- and obtain qualified human review for consequential work.
A real link can be attached to a false interpretation. Citation presence is not citation accuracy.
Do not use Copilot as the sole decision-maker for:
- diagnosis or treatment;
- legal rights or strategy;
- credit or insurance;
- employment decisions;
- critical infrastructure;
- physical safety;
- or emergency response.
Security starts with the account
For a personal account:
- use a unique password;
- enable multifactor authentication;
- secure the recovery email and device;
- review active sessions;
- check training and personalization settings;
- remove unnecessary connected apps;
- and delete sensitive history promptly.
For an organization:
- use Entra identity and conditional access;
- apply least-privilege administrator roles;
- automate joiner, mover and leaver processes;
- restrict unmanaged devices where appropriate;
- govern external sharing;
- configure retention and eDiscovery;
- log and monitor agent actions;
- maintain an incident-response path;
- and prevent protected work in personal consumer accounts.
A no-training promise does not help if an attacker takes over the account.
A practical traffic-light policy
Green: ordinary use
- public information;
- brainstorming;
- rewriting non-sensitive text;
- learning and practice;
- summarizing a document you are authorized to process;
- and low-risk code examples.
Verify factual output.
Amber: approved account and review required
- internal documents;
- unpublished plans;
- customer-support drafts;
- production source code;
- contracts;
- financial analysis;
- personal data;
- and actions in business systems.
Use the organization-approved product, minimize data and require a qualified human review.
Red: do not paste into an ordinary Copilot session
- passwords and API keys;
- raw payment-card data;
- unrestricted customer databases;
- classified material;
- protected source identities;
- highly sensitive medical records;
- material non-public information;
- and data forbidden by contract or law.
A legitimate regulated use belongs in a specially approved architecture with the correct contract and controls.
Business rollout checklist
Before enabling Copilot broadly:
- inventory each Copilot product and account type;
- prohibit protected work in consumer accounts;
- classify use cases by data and action risk;
- verify contracts, regions and subprocessors;
- configure training and feedback settings;
- repair Microsoft 365 permissions;
- define sensitivity labels and retention;
- govern web search and connectors;
- approve models and previews;
- apply DLP and Power Platform environment strategy;
- review Copilot Studio transcript access;
- restrict GitHub model, agent and MCP policies;
- protect identities and service credentials;
- test prompt injection and data leakage;
- require confirmation for consequential actions;
- preserve human review;
- monitor usage, safety and cost;
- and reassess after major product changes.
The review must cover the full data path. The strongest Microsoft setting cannot govern a third-party connector that sends content elsewhere.
Frequently asked questions
Is Microsoft Copilot safe to use?
Yes, for many ordinary tasks when you use the correct account, avoid unnecessary sensitive data and verify important output. It is not safe by default for every confidential, regulated or autonomous use case.
Does Microsoft Copilot use my conversations for training?
Eligible consumer Copilot conversations may be used unless the signed-in user opts out. Copilot in Microsoft 365 home apps and Entra-protected Microsoft 365 Copilot work experiences are excluded from foundation-model training under Microsoft’s stated policies.
How do I stop consumer Copilot from training on my chats?
Open Copilot’s privacy controls while signed in and disable model training for conversation activity. The setting applies to future conversations and is separate from personalization.
How long does Microsoft Copilot save chats?
Consumer Copilot stores conversation activity for 18 months by default. Microsoft 365 work and Copilot Studio retention depends on tenant and environment controls; Copilot Studio has a default 30-day transcript cleanup job that administrators can change.
Can I delete Microsoft Copilot history?
Consumer users can delete individual conversations or all history. Microsoft 365 home activity can be managed through the Microsoft privacy dashboard. In organizations, retention, legal hold, audit and administrator policy can affect deletion.
Can my employer see Microsoft 365 Copilot chats?
Authorized administrators can use Microsoft 365 audit, retention and eDiscovery capabilities for work prompts and responses. Treat a work Copilot conversation as organizational data, not a private personal diary.
Does Microsoft 365 Copilot bypass SharePoint permissions?
Microsoft says it retrieves only organizational content the user is allowed to view. It can, however, make previously overshared content easier to discover, so permission cleanup remains essential.
Are Copilot Studio conversations stored?
They are normally saved as Dataverse transcripts and metadata. Administrators can restrict access, change retention or stop new transcripts from being saved, with potential analytics consequences.
Is GitHub Copilot safe for proprietary code?
It can be under an approved Business or Enterprise deployment with appropriate repository, model, agent and security controls. Review all output, protect secrets and preserve human code review.
Is Microsoft Copilot compliant with GDPR or HIPAA?
Microsoft offers commercial commitments and controls that can support compliant deployments. Compliance depends on the exact product, contract, configuration, data, web search, connectors and customer responsibilities. A logo or license alone does not make a workflow compliant.
Bottom line
Microsoft provides meaningful privacy and enterprise controls, but “Copilot” covers several products. Consumer Copilot can use eligible conversations for training and keeps history for 18 months by default; Microsoft 365 home apps exclude prompts and files from foundation-model training; work Copilot provides enterprise data protection; Copilot Studio adds Dataverse transcripts and agent permissions; GitHub Copilot has plan- and provider-specific rules.
Identify the surface before making a privacy claim. Then minimize data, secure the account, repair permissions, govern connectors and agents, and keep humans responsible for important facts and actions.