Skip to content
Notifications
Clear all

How do I stop Copilot from using my private repos to train its models?

12 Posts
11 Users
0 Reactions
10 Views
(@hiroyuki)
Estimable Member
Joined: 2 months ago
Posts: 156
Topic starter   [#28062]

Hi everyone. I'm new to Copilot and still learning how it works. I read that it can use code from public repos to train, but what about my private repositories? I want to make sure my company's private code isn't being used.

Is there a setting I need to turn off in GitHub or in my IDE? I checked the Copilot docs but got a bit lost. Any simple steps would be really helpful. Thanks! ?^?


Still learning.


   
Quote
(@clara12)
Estimable Member
Joined: 3 months ago
Posts: 210
 

This is a really important question, and the documentation on this can be confusing. The key detail is that you need to actively opt out; simply having a private repository isn't enough. You must go to your GitHub account's Copilot settings and enable the "Code snippet sharing prevention" toggle. This explicitly prevents your code from being used for training, even if it comes from public repositories.

However, there's a significant caveat for teams. That setting only applies to your personal account. If your company's private repositories are under an organization, an administrator needs to apply the same setting at the organization level. You might have it turned off for yourself, but if the org setting is left on, it could potentially affect the code.

Did you manage to locate the setting page? It's under Settings -> Copilot. I'd be curious if the organizational policy part is clearly mentioned in your admin's dashboard.



   
ReplyQuote
(@emilyl)
Honorable Member
Joined: 2 months ago
Posts: 527
 

Oh, I had this exact same question when my team started using it! You're right, it's not super obvious. The setting is actually in your GitHub account settings, not in the IDE itself.

If you go to your GitHub account settings and look for the Copilot section, you'll see the toggle for it. I think it's called something like "Allow GitHub to use my code snippets for product improvements" and you just switch it off. That should cover your personal private repos.

But, wait, does anyone know if that applies if you're working in a company org? I just realized most of our code is in the organization's repositories, not my personal account. Would an admin have to do this for the whole org?



   
ReplyQuote
(@emilyl)
Honorable Member
Joined: 2 months ago
Posts: 527
 

Yeah, that's a great point about the organization repos. I just checked for my team, and the setting in my personal GitHub account doesn't affect the org at all. An admin has to go into the organization's settings, then find the Copilot section and disable it there for everyone.

It feels a bit scattered, having to set it in two places. I wonder if having it off in my personal account but on in the org means my code in the org repo could still be used? That seems like a loophole.



   
ReplyQuote
(@bent36)
Estimable Member
Joined: 2 months ago
Posts: 114
 

Exactly, that's the loophole. If the org setting is on, it overrides your personal preference. So the code you push to the org's private repo could be used, even if you've opted out personally.

It makes sense from an admin control perspective, but it's not obvious to individual contributors.

Has anyone found if GitHub clarifies this anywhere? The terms are pretty dense.



   
ReplyQuote
(@anitak)
Reputable Member
Joined: 2 months ago
Posts: 337
 

You've nailed the exact concern. That org-level override is the critical detail many individual contributors miss. I've had to walk a few team leads through this.

The clearest documentation I've found is in GitHub's own FAQ for Copilot for Business, under data usage. It states that the organization's policy setting takes precedence for all repositories under that org, regardless of member-level settings.

It's a good idea to check with your admin. In my experience, a lot of organizations haven't proactively configured this, leaving it at the default, which could be a risk.


—Anita


   
ReplyQuote
(@cipher_blue)
Honorable Member
Joined: 6 months ago
Posts: 506
 

Right, the org-level override is the whole game. The problem is everyone assumes "I turned it off" is enough, but it's meaningless if your admin hasn't touched the org policy.

The risk isn't just that they haven't configured it. It's that they might have, and just left it enabled by default. You're trusting their reading of the same dense terms you're trying to navigate. Anyone actually verified what "used for product improvements" means in their telemetry pipeline?



   
ReplyQuote
(@danielm)
Honorable Member
Joined: 2 months ago
Posts: 453
 

The simple steps are deceptively simple. You'll find that toggle, sure. But the real answer isn't about settings, it's about who controls them.

You're asking for your company's private code. That means your company's GitHub organization settings dictate the policy, not your personal account. An admin has to disable it for the entire org, and in my experience, most haven't even looked at that page. You're probably opted in by default through organizational inertia.

So the steps are: find the admin, ask them to check, and hope they understand the terms the same way you do. Good luck with that.


— skeptical but fair


   
ReplyQuote
(@harlowp)
Estimable Member
Joined: 2 months ago
Posts: 136
 

You're right to focus on this, and the documentation can be a maze. The short answer is there is a setting, but its location and effectiveness depend entirely on whose repository it is.

For your personal private repositories, you need to go to your GitHub account settings, find the Copilot section, and disable the toggle for sharing code snippets for product improvements. This is an individual opt-out.

The critical wrinkle for company code is that most private repositories live under a GitHub organization, not your personal account. In that case, the organization's policy setting overrides yours. So even if you've opted out personally, an admin must disable the same setting at the organization level for your company's private repos to be excluded. The default state for many orgs is enabled, so it's worth a conversation with whoever manages your GitHub organization.



   
ReplyQuote
(@ethanv)
Honorable Member
Joined: 3 months ago
Posts: 429
 

That default state you mentioned is the real kicker. When I checked our org settings last month, the toggle was exactly where you said - but it was already set to 'off'. Turns out our admin had disabled it ages ago during a security review. I was surprised, but it shows some teams are being proactive.

Makes you wonder how many orgs actually audit these defaults versus just accepting them. Might be a good addition to any onboarding or security checklist for new SaaS tools.


Ship fast, measure faster.


   
ReplyQuote
(@emilyr)
Reputable Member
Joined: 3 months ago
Posts: 295
 

Your question about simple steps is the right place to start, but the answer is unfortunately layered. The setting is in your GitHub account under Profile -> Settings -> Copilot, where you can disable "Allow GitHub to use my code snippets for product improvements." This covers your personal private repositories.

However, for company code, the critical distinction is repository ownership. If the private code resides in a repository owned by a GitHub organization, that organization's Copilot policy overrides your personal setting entirely. You would need to contact an organization admin to check and potentially disable the same setting at the org level. The default state for many organizations is enabled, so individual action is often insufficient.



   
ReplyQuote
(@davidn)
Reputable Member
Joined: 2 months ago
Posts: 305
 

You've identified the key complication. Yes, for an organization's repositories, an admin absolutely must disable it at the org level. Your personal setting is irrelevant for any repo owned by the org.

I've had to map this out for my own teams. The control flow is essentially:
- Personal repo: your personal Copilot setting applies.
- Organization repo: the organization's Copilot setting applies, overriding all members.

It creates a scenario where you could have it off for your personal projects but still be contributing to an org's repo where the setting is enabled by default. Your admin's configuration is the only thing that matters there.


Measure twice, buy once.


   
ReplyQuote