GitHub
GitHub uses your code, inputs and AI outputs to develop and train AI/ML models by default, with no self-serve opt-out stated in its privacy statement.
No opt-out found in this policy
Graded on the plan most users are on. Other plans appear in the matrix below.
"We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models."
- 01 May 2026
- 12 Aug 2026
- Individual accounts (all plans)
- global
- FBC97EB3…F69F
Scope of this finding: The policy defines collected "User Content and Files" as "code, inputs, AI outputs, text, documents, images, or feedback," with no public/private repo distinction — but Copilot itself is never named in or near the training clause; it appears twice elsewhere only as an example feature. This capture also replaced the prior version's detailed private-repository access protections with a pointer to "Section E (Private Repositories)" of the GitHub Terms of Service, a document this monitor hasn't archived — so how GitHub's access rights to private repo code interact with this clause isn't independently confirmed. Outside the EU/UK, no self-serve opt-out is stated for this use.
This clause is real, but it doesn't resolve the training question — see the finding below.
"In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller."
- 01 May 2026
- 12 Aug 2026
- Organization-provided accounts (Enterprise/Business)
- global
- FBC97EB3…F69F
Why this is still UNCLEAR: When a school or employer supplies your GitHub account, the privacy statement says that organization becomes the Data Controller and GitHub acts as a Data Processor under a Data Protection Agreement negotiated with that organization. The same paragraph adds a wrinkle: GitHub remains Data Controller "solely for specific processing activities" defined in that agreement, and "for those limited purposes, this Statement governs" — so part of org-account processing may fall under the very clause quoted on the Individual accounts tier, but the document never says whether AI/ML training is one of those "limited purposes" or one of the DPA-governed ones. We also checked GitHub's own publicly-linked standard Data Protection Agreement (the document this policy points readers to); it authorizes GitHub to provide, update, and troubleshoot the service and explicitly rules out using organization data for profiling, advertising, or data brokering, but it does not mention AI or machine learning model training in either direction — genuinely silent, not merely unread.
What each plan can refuse
The same questions asked of every plan we could identify. Every cell is sourced from a quoted clause or a documented search — see the evidence above.
- None offered
- Not stated
- 81 / 100
- Unknown
- Not established
- Not stated
- —
- Not established
Everything we read
Vendor response
GitHub has not disputed, clarified, or announced a change to any clause quoted above. If that changes, it will be published here verbatim.
Report a wrong clause