Microsoft
Copilot
Verified: 2026-06-22 Changed: 2026-06-23
D64 Pts
Privacy Grade Breakdown
Scores are calculated based on default weights. Visit the Methodology page for the formulas.
Default Training
F0/100
Opt-Out Ease
A+100/100
Data Retention
B-80/100
Deletion Rights
A+100/100
Third-Party Sharing
B85/100
Human Review
B-80/100

Policy Details & Nuances

Default Model Training
Yes

Consumer Copilot (free and Pro) uses conversations for training by default. Enterprise and school accounts with commercial data protection (EDP) are excluded from training.

Opt-Out Mechanism
Yes

In consumer Copilot settings, go to Privacy > Model Training and toggle off 'Model Training for Text/Voice'.

Data Retention & Deletion

Retention Period

Consumer conversations are kept in account history for 18 months. If history is disabled, Microsoft retains data for 30 days for abuse monitoring, then deletes it.

Deletion on Request

Yes

You can delete individual conversations or your entire conversation history at any time through the Copilot UI or the Microsoft Privacy Dashboard.

Third-Party Data Sharing

Shared with service providers and Microsoft affiliates. Query and conversation data is shared with OpenAI under strict confidentiality terms, but OpenAI cannot train on Microsoft user data.

Human Review of Chats
Yes

Some conversations are subject to human review for product improvement and digital safety. Conversations flagged as Code of Conduct violations may also be reviewed. Opt-out of human review is not available.

Context & Variations

Regional Variations

EEA/UK users have access to GDPR privacy dashboards and enhanced telemetry opt-out options.

Children's Data Policy

Requires a Microsoft account, which restricts users under 13 (or regional age limit) without explicit parental verification.

Enterprise vs. Consumer
Yes

Copilot for Microsoft 365 and Copilot with Enterprise Data Protection (EDP) enforce no model training, no human review of chats, and all data is encrypted at rest and in transit.