Does Microsoft Copilot train on your data? Four answers
· Updated · Written and maintained by Joaquín Trapero, Nonimo
There is no single answer on Copilot data privacy, because there is no single Copilot. Microsoft ships at least four things under that name, they sit under different contracts, and the answer to whether your text is used for training flips between them. On August 18, 2026, it also flipped inside one of them.
That is the whole difficulty with this question. Every page you will read gives one answer confidently, and most of them are quoting a real Microsoft document that happens to be about a different product from the one on your screen.
So this guide sorts them first and answers second, with the date each document carries. If what you actually need to know is whether a paste has already gone wrong, that has its own guide.
| Which Copilot | Signed in with | Trains on your prompts |
|---|---|---|
| Consumer app, older version | Microsoft account | Yes, you can opt out |
| Consumer app, since Aug 18, 2026 | Microsoft account | Stated as no |
| Microsoft Copilot, Copilot Chat | Work or school, Entra | Stated as no |
| GitHub Copilot | GitHub account | Out of scope here |
Microsoft Learn and Microsoft Support pages, read September 19, 2026.
Four products called Copilot, and four different answers
The naming got harder this year rather than easier. Microsoft Learn now carries a note at the top of its Copilot documentation stating that Microsoft 365 Copilot is now named Microsoft Copilot, and that Microsoft 365 Copilot Chat is now named Microsoft Copilot Chat.
The practical effect is that the paid work product and the free consumer product now have the same name, and a search for it returns pages about both. Microsoft adds that there are no changes to security, compliance and privacy for organizations, which is true and beside the point: the difficulty is telling which page you are reading.
There is one test that settles it every time, and it does not involve reading anything. Look at which account is signed in. A personal Microsoft account puts you under the Microsoft Services Agreement and the Microsoft Privacy Statement. A work or school account, meaning Microsoft Entra, puts you under your organization’s Data Protection Addendum. That is the same lever a written AI policy should be pulling.
GitHub Copilot is a different product, and not this one
It shares a brand and nothing else that matters here. GitHub Copilot is a coding assistant with its own documentation, its own settings and its own account model, and people searching for Copilot get its pages mixed in with the rest, which is how a partner ends up reading a developer page and concluding something about Word.
Nothing on this page describes it. If that is the product in your firm, read its own privacy pages rather than assuming any of this carries over, and note that it has its own admin settings in a place your Microsoft 365 administrator may never have opened.
The consumer app split in two on August 18, 2026
This split is why almost every outside article on the subject is wrong for somebody. On that date Microsoft released an updated consumer Copilot app, and rather than editing its support pages it published a second set and left the first in place.
Both sets are live today. Each carries a banner saying which app version it applies to. They answer the training question differently, and both are correct.
What the older page says, and what its opt out does not cover
The page titled Microsoft Copilot privacy controls, which its banner says applies only to the older version of the app, lists four things you control, and training is one of them. You opt out under Privacy, using the settings named Training on conversation activity and Training on voice conversations.
Then comes the sentence worth the whole page. Opting out excludes future conversation activity from training those models, and Microsoft adds that the setting will not exclude your conversations from being used for other general product or system improvements, nor from use for advertising, digital safety, security and compliance purposes.
That is an unusually clear statement of something true of every one of the four major assistants, and of the four it is the only one written next to the switch it qualifies. The same page says conversation history is retained for 18 months by default.
What the newer page says, and how to tell which you have
The page for the app released on August 18, 2026, says the opposite, and briefly. Under a heading about activity history, Microsoft states that prompts, responses and your file contents when using the Microsoft Copilot app are not used to train foundation models.
It adds that optional customer feedback may be used to improve Copilot and is not used to train the foundation models either. There is no training toggle on the new privacy controls page, which now lists six controls: memory, shared experiences, chat history, web search, personalized advertising, and importing browser data.
| Consumer app version | Training | Where it says so |
|---|---|---|
| Older version | Yes, you can opt out | Microsoft Copilot privacy controls |
| Since August 18, 2026 | Stated as not used | Copilot for individuals, activity history |
Microsoft Support, both pages read September 19, 2026, each carrying its own version banner.
Note the exact words on the newer page, because they are narrower than they look. Foundation models is a specific thing. It is not the same as saying your prompts are not used at all, and the Microsoft Privacy Statement, updated September 2026, says what else they are used for.
Consumer Copilot, advertising, and one setting that is not the ads setting
The Microsoft Privacy Statement puts the other use in one clause: Microsoft Copilot uses prompts and related data to provide and improve services, including relevant advertising. That is the consumer product, and it is current.
The support pages fill in how. If you use Copilot without a Microsoft 365 subscription you may see advertising, and personalized ads might use your chat history, saved memories and other Microsoft data you have chosen to share. Turn personalization off and you still see ads, chosen from the most recent content of your current conversation rather than from your history.
There is a second control called One shared experience, and it is easy to mistake for the ads control. With it on, your activity in Bing, Edge and MSN personalizes Copilot, and your Copilot chats personalize Bing and MSN in return. Microsoft notes explicitly that this setting does not control whether you see personalized ads, which is a separate choice.
| Control | What it governs | What it does not |
|---|---|---|
| Personalization and memory | What Copilot remembers about you | Whether you see ads |
| One shared experience | Bing, Edge and MSN both ways | Whether you see ads |
| Allow ads personalization | Whether ads use your history | Whether ads appear |
Microsoft, Copilot for individuals: your privacy controls and choices, read September 19, 2026.
Three controls, and the column on the right is the one to read, because two of the three sound like they turn advertising off and neither does. Turning all three off leaves ads in place, chosen from whatever is on screen right now.
One consumer offering is carved out in the other direction, and the contrast is instructive. For Copilot Health, Microsoft states that the information you submit is not used to develop or train generative AI models and is not used for advertising or marketing. Writing that about one product tells you what the default is for the rest.
The import from Edge, which only Americans are offered
Buried in the consumer privacy controls page is a feature with a geographic restriction, and no other fact on this page is as specific to the United States. You can import your Microsoft Edge browsing data into the Copilot app: cookies, history, payment info, passwords and autofill data.
Microsoft states that this setting is currently available only to individuals whose Microsoft account is based in the United States, and adds that it is also available when signed in with a work, school or organizational account.
Whatever the merits, an American professional is offered a path from a saved password store into an AI assistant that takes one click, and a British or German one is not. Your insurer’s application will not ask about it, and it is worth knowing that it exists and that it is offered to you specifically.
A work account changes the product, not just the plan
This is where a small firm gets the largest improvement for the least money, and often for nothing at all, because the license is already paid for.
Enterprise data protection, and what it covers
Microsoft’s term for the protections on a work account is enterprise data protection. Its page defines it as the controls and commitments under the Data Protection Addendum and Product Terms that apply to customer data, with Microsoft acting as a data processor rather than as a controller.
The four commitments it lists are worth restating in plain English. Data is encrypted at rest and in transit, with isolation between tenants. Microsoft will not use your data except as you instruct. Your identity model, permissions, sensitivity labels and retention policies apply to Copilot. And prompts, responses and data accessed through Microsoft Graph are not used to train foundation models.
| Work product | Grounded in | Included with |
|---|---|---|
| Microsoft Copilot | Your Microsoft Graph data and the web | A paid license |
| Copilot Chat | The web, plus content you bring in | Commercial Microsoft 365 |
Microsoft Learn, enterprise data protection and Copilot Chat privacy pages, read September 19, 2026.
There is a genuine extra worth crediting here, because it goes further than the others. Microsoft states that while abuse monitoring including human review of content is available in Azure OpenAI, Copilot services have opted out of it. That is a different posture from Google’s human review of a subset of Gemini chats.
Copilot Chat, and the protection that comes with it at no extra cost
Copilot Chat is the part most firms of five to fifty people have never looked at. Microsoft states that enterprise data protection is available in it at no extra cost, and that the interface shows a green shield next to the New Chat button when it applies.
It is grounded in web data rather than in your files, so it is not the same product as the licensed Copilot that reads your mail and documents. Users can bring organizational content into it deliberately, by pasting, uploading, using the file picker, or by using it inside Outlook. Uploaded files are stored in the user’s own OneDrive for Business as part of the same protections.
For a firm whose people are currently pasting client text into a free consumer chatbot, moving them to Copilot Chat buys a business contract, an audit trail and a clear no on training, for the price of one announcement at a staff meeting. No other improvement on this page costs less.
Copilot data privacy is about more than training
Everything above turns on a confusion worth naming, because it is the one that gets client files pasted into chatbots by people who believed they had checked the box that mattered.
Prompts and responses are not used to train foundation models is a promise about one use. It says your words will not be folded into a future model. It does not say nobody can read them, that nothing is kept, or that they never left your office.
Copilot makes the point better than the other three products do, because on a work account the answers pull in opposite directions. Training: no, clearly and contractually. Kept: yes, deliberately, in a store your organization controls. Readable: yes, by your own administrators, on purpose. The same design that gives a firm the best training answer among the four major assistants also gives it the most thorough record of what everybody typed.
What still happens when nothing trains
| What still happens | Where Microsoft says so |
|---|---|
| Prompts and responses logged in Exchange | Copilot Chat privacy and protections |
| Admins can search and export them | Data, privacy and security for Copilot |
| Retention policies decide how long | Learn about retention for Copilot |
| Web queries leave the service boundary | Enterprise data protection |
Microsoft Learn, pages last updated August 18, 2026, and read September 19, 2026.
The first two rows are the reason the work account is better, not a criticism of it: a firm that can audit and retain its own AI usage is a firm that can answer a client’s questionnaire. But they are the opposite of data privacy in the sense most Copilot users have in mind, and nobody tells the users.
Your prompts are logged in Exchange, and that word matters here
Microsoft’s Copilot Chat documentation says it in a single line in the flow description: before the response goes back to the user, both the prompt and the response are logged and stored in Exchange for auditing and eDiscovery.
Exchange is where your email lives. Putting Copilot prompts in the same store means they inherit the same machinery, and in the United States that machinery has a name with consequences attached.
| Who reaches it | With what | Scope |
|---|---|---|
| The user | My Account portal | Their own activity history |
| An admin | Content search or Purview | The tenant |
| Your own organization | Retention policies in Purview | How long everything is kept |
Microsoft Learn, Data, Privacy and Security for Microsoft Copilot, last updated August 18, 2026.
That is a better arrangement than the alternative, and a client security questionnaire is easier to answer because of it. It is also a complete record of what everyone in the firm asked an AI assistant, which is a thing that did not exist two years ago.
What an admin can read, and with which tool
Microsoft states that admins can view and manage stored Copilot interaction data using Content search or Microsoft Purview, and can use Purview to set retention policies for Copilot chat interactions. For Teams chats with Copilot, the Teams Export APIs reach the same data.
Users can delete their own Copilot activity history through the My Account portal. That removes their view of it; it does not override a retention policy the organization has set, which is how every other record in the tenant already behaves.
Discovery, and why this is sharper in the United States
In a country with no federal data protection regulator, the realistic risk for a professional firm is not a letter from one. It is a subpoena, a client audit, or opposing counsel’s request for documents, and eDiscovery is the word that connects all three. In local government the same logic runs through open records law instead, where a resident request reaches the prompt itself.
A Copilot prompt sitting in Exchange under a retention policy is a business record like any other. If the prompt contained a client matter, it is a discoverable business record containing a client matter. That is the version of this question worth taking to your managing partner, and it is not answered anywhere on a vendor comparison page.
Whether a prompt with the client’s name masked stays privileged is a separate question, and the answer turns on who received it, not on what was taken out.
HIPAA: the agreement stops at the web search box
Microsoft states that Copilot and Copilot Chat support HIPAA compliance for properly configured implementations. That wording puts the configuration on the customer, as every vendor’s HIPAA language does when read closely. Then comes a footnote that changes how a medical practice should use the product, and it is one sentence long.
HIPAA compliance does not apply to web search queries, because those are not covered by the Data Protection Addendum or the business associate agreement. The same footnote structure covers the EU Data Boundary, which likewise does not apply to web queries. For a medical practice, that leaves one part of the answer the footnote cannot touch: what staff take out at the workstation, before Copilot sees the text.
The mechanism behind it is documented and reasonable. When Copilot decides a web search would improve an answer, it generates a query of a few words from your prompt and sends it to the Bing search service over a secure connection, with user and tenant identifiers removed. Microsoft states those queries are not shared with advertisers and are not used to train its foundation models.
| Part of the interaction | Under the addendum and agreement |
|---|---|
| Prompts and responses | Covered |
| Microsoft Graph data | Covered |
| Generated web search queries | Not covered |
Microsoft Learn, enterprise data protection, footnotes, last updated August 18, 2026.
But Bing operates separately from Microsoft 365, under the Microsoft Services Agreement rather than the addendum, with Microsoft acting as an independent data controller. Our guide to client data and breach duties covers the same exclusion from the breach angle; what belongs here is the operational consequence. If protected health information is in scope, the question for your administrator is whether web grounding is on.
Which model sees your prompt, and where it is processed
Two questions that used to have obvious answers and no longer do. Both are answered in Microsoft’s documentation, and both have moved in the last year.
Anthropic and OpenAI as subprocessors
Microsoft states that it offers AI models from other companies inside Copilot, naming Anthropic and OpenAI models, and that an administrator decides whether to use them, and that additional terms may apply. It also deploys models it hosts and operates itself, under the same commitments, where it says no data leaves Microsoft.
| Model provider | Who decides it is used | Documented where |
|---|---|---|
| Microsoft hosted models | Microsoft, under its own terms | Microsoft Learn |
| Anthropic models | Your administrator | Anthropic models in Microsoft Online Services |
| OpenAI models | Your administrator | OpenAI as a subprocessor |
Microsoft Learn, Data, Privacy and Security for Microsoft Copilot, last updated August 18, 2026.
So the answer to which company processes my prompt is now a tenant setting rather than a fact about the product, and the last two rows carry additional terms of their own. For a firm that answered a client questionnaire last year by naming Microsoft alone, that is worth rechecking, and it is precisely what the subprocessor question on those forms is for.
Data residency for a customer outside the EU
Microsoft states that Copilot calls to the model are routed to the closest data centers in the region, and can go to other regions when capacity is short. For European users, additional safeguards keep traffic inside the EU Data Boundary, with Anthropic models currently excluded from it.
Then the sentence that applies to you: customers outside the EU may have their queries processed in the US, the EU, or other regions. An American firm’s prompts may be processed in Europe, which is the exact inversion of the anxiety that dominates writing on this subject, and which no US statute currently addresses.
How to check what your firm actually has, in four questions
None of this needs a consultant. Four questions, answerable in one conversation with whoever administers your tenant.
Are people signed in with a personal Microsoft account?
YesThat is consumer Copilot, under the Microsoft Services Agreement, and the app version decides the training answer: the older app trains unless you opt out, and the one released on August 18, 2026, states that prompts are not used to train foundation models.
NoAn Entra work or school account is a different product with a different contract, your organization's Data Protection Addendum. Go to the next question.
Is Copilot Chat turned on, and do people know it exists?
YesLook for the green shield next to the New Chat button: it shows that enterprise data protection applies.
NoIt comes with commercial Microsoft 365 licenses and carries enterprise data protection at no extra cost. Move people onto it.
Is web grounding on, and do you handle protected health information?
YesThe business associate agreement does not cover the web search queries Copilot generates.
NoGo to the next question.
Has anyone set a retention policy for Copilot interactions in Purview?
YesWrite down the period. The records sit in Exchange, where your admins can search them.
NoThe default is whatever nobody set, and the records sit in Exchange anyway.
Four answers, and the firm knows which Copilot it actually has.
Write the answers down with today’s date. An undated note is worth very little to a client asking what you had in place six months ago, and the firms who deploy this for you will ask the same four questions anyway.
What a tool can do here, and what no tool can do, including ours
Software of this kind can mask identifiers before text is sent, because identifiers sit in predictable places and some carry check digits that can be verified arithmetically. It can show what it changed so a person can overrule it, and it can leave a record that the control was on, which is what an auditor asks for.
It cannot decide that a document is too sensitive to send. It cannot see that a paragraph identifies a client through facts rather than names. And it cannot make you compliant, because compliance is not a property that software has.
What our engine does and does not do in the United States
An SSN, an EIN or a Medicare beneficiary identifier is masked before sending when it carries a label the engine recognizes, and what replaces it is a general REFERENCE tag. An email address is replaced without asking, because its format leaves no doubt, and so is a card number with a valid check digit. Every change is shown and reversible.
Nonimo runs on the computer itself, on Mac and Windows, and IT sets the policy step for the whole firm rather than for each user. What it replaces, it replaces reversibly, keeping the mapping encrypted on the user’s own computer. That is pseudonymization rather than anonymization, and it is how our pages for organizations describe it too.
For what the app keeps on your disk, see Nonimo’s security page.
If you buy nothing at all, do these five things
- Find out which app version your people are on. It decides which of Microsoft’s two live consumer pages applies, and they disagree.
- Ask whether Copilot Chat is available on your licenses, and move people onto it. The contract is different and enterprise data protection comes at no extra cost.
- Ask about web grounding before you ask about anything else. It is the one part the business associate agreement does not reach.
- Set a retention policy for Copilot interactions. They are sitting in Exchange whether or not anyone chose a period.
- Write the never list. Five lines naming the document types that may never be pasted, on any account, in any app.
A firm that does all five is in better shape than one that bought software and did none of them. If a technical control later looks worth it, our license terms say plainly what ours is and is not.
Two things you will read elsewhere that are wrong today
We checked both claims below against the current documents on September 19, 2026.
The first is that Copilot trains on your conversations by default and you have to opt out. That is what Microsoft’s own page says, and it applies to the consumer app released before August 18, 2026. Pages dated July and August of this year state it flatly, without the version banner Microsoft puts on its own page, which makes them wrong for anyone on the current app.
The second is the reverse error, and it is more common among IT pages: that Copilot never trains on anything, because enterprise data protection says so. Enterprise data protection applies to work accounts. It says nothing about a partner using the free app on a personal account at home, which is where most of the pasting actually happens.
Both mistakes come from quoting a true Microsoft sentence about the wrong product. It is the predictable cost of four things sharing one name, and it is why the first question on this page is which account is signed in, the same first question as for the other three assistants.
Sources
Checked September 19, 2026. Every link below returned a live page on that date.
- Microsoft Learn, Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat, last updated August 18, 2026. The renaming note, the four commitments, the foundation model statement, and the footnote excluding web search queries from HIPAA and from the EU Data Boundary.
- Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, last updated August 18, 2026. Interaction data stored and searchable by admins, deletion through My Account, Anthropic and OpenAI as subprocessors, opting out of abuse monitoring, and processing regions outside the EU.
- Microsoft Learn, Microsoft Copilot Chat privacy and protections. Enterprise data protection at no extra cost, the green shield, logging in Exchange for auditing and eDiscovery, and how generated web queries are built.
- Microsoft, Copilot privacy controls. The older consumer app: the training settings, the history kept for 18 months, and the sentence on what opting out does not cover.
- Microsoft, Copilot for individuals: your activity history. The newer consumer app: prompts, responses and file contents not used to train foundation models.
- Microsoft, Copilot for individuals: your privacy controls and choices. The six controls, personalized and generic ads, one shared experience, and the Edge import limited to accounts based in the US.
- Microsoft Privacy Statement, updated September 2026. Consumer Copilot using prompts and related data including for relevant advertising, and the Copilot Health exception.
The same questions for the other three assistants: does ChatGPT share or sell your data, does Claude train on your data, and what Gemini does with your data.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Does Microsoft Copilot train on your data?
It depends which Copilot, because Copilot data privacy follows the account you sign in with. On a work or school account Microsoft states that prompts, responses and Microsoft Graph data are not used to train foundation models. On a personal account the answer changed with the app version released on August 18, 2026.
Does the free Copilot use my conversations for training?
The page for the older consumer app describes model training that you can opt out of. The page for the app released on August 18, 2026, states that prompts, responses and file contents are not used to train foundation models.
Does Copilot show ads based on my chats?
On consumer accounts, yes if personalization is on. Microsoft states that personalized ads might use your chat history and saved memories, and that generic ads are selected from the most recent content of your current conversation.
What is enterprise data protection in Copilot?
It is the set of contractual commitments under the Data Protection Addendum and Product Terms that apply when you sign in with a work account. Microsoft acts as processor, and prompts and responses get the same terms as Exchange and SharePoint.
Is Copilot Chat free?
Microsoft states that enterprise data protection is available in Copilot Chat at no extra cost, and that the interface shows a green shield when it applies. Copilot Chat is grounded in web data rather than in your organization's files.
Can my employer read my Copilot prompts?
On a work account, yes. Microsoft states that prompts and responses are logged and stored in Exchange for auditing and eDiscovery, and that admins can view them with Content search or Microsoft Purview.
Is Microsoft Copilot HIPAA compliant?
Microsoft states it supports HIPAA compliance for properly configured implementations, and adds one exclusion: HIPAA compliance does not apply to web search queries, because those are not covered by the addendum or the business associate agreement.
Which AI model does Copilot use?
Several, and your administrator can choose. Microsoft documents Anthropic and OpenAI models as subprocessors in Copilot experiences, alongside models it hosts and operates itself, each with its own documentation page.
Where are my Copilot prompts processed?
Microsoft states that calls go to the closest data centers in the region and can use other regions at busy times, and that customers outside the EU may have queries processed in the US, EU or other regions.
Does GitHub Copilot follow the same rules?
No. GitHub Copilot is a separate product for developers with its own documentation and its own settings, and nothing on this page describes it. Check its own privacy pages rather than assuming the answers here carry over.