Microsoft Copilot on a personal account
Microsoft states that except for certain categories of users or users who have opted out, it uses data from Bing, MSN, Copilot and ad interactions for AI training. Conversation activity is stored for 18 months by default and can be deleted at any time. Some conversations are subject to both automated and human review. A signed in user can opt out.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AVD-2026-0012
- Kind
- Consumer tier
- Jurisdiction
- United States
- Last verified
- Added
- Microsoft states that except for certain categories of users or users who have opted out, it uses data from Bing, MSN, Copilot and ad interactions for AI training.
- Conversation activity is stored for 18 months by default, and uploaded files for no longer than 18 months.
- Some Copilot conversations are subject to both automated and human review.
- Signed out users, users under 18, Entra ID accounts and users in six named countries are excluded from training.
Dimension by dimension
10 dimensions, each one stated, silent or open
Used for training by default, Retention period, Deletion on request, Storage region and residency, Subprocessor list published, Human review of content, Opt out available, DPA available, Persistent memory across sessions, Last change to the terms. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Used for training by defaultStated
- Yes by default for signed in consumers. Microsoft uses data from Bing, MSN, Copilot and ad interactions for AI training except for named categories and users who opted out.Microsoft, privacy FAQ for Microsoft Copilot, primary source, 15 September 2026.
- Retention periodStated
- Conversation activity is stored for 18 months by default, and uploaded files for no longer than 18 months.Microsoft, privacy FAQ for Microsoft Copilot, primary source, 15 September 2026.
- Deletion on requestStated
- You can delete individual conversations or your entire conversation history at any time, and erasure rights run through the Microsoft privacy dashboard.Microsoft, privacy FAQ for Microsoft Copilot, primary source, 15 September 2026.
- Storage region and residencyStated
- The consumer Copilot pages print no storage region. The privacy statement says data may be stored and processed in your region, the United States and other jurisdictions.Microsoft privacy statement, primary source, 15 September 2026.
- Subprocessor list publishedSilent
- No subprocessor list or named processor appears on either consumer Copilot page.Microsoft, Copilot privacy controls, primary source, 15 September 2026.
- Human review of contentStated
- Yes. Some Copilot conversations are subject to both automated and human review, for product improvement and digital safety.Microsoft, privacy FAQ for Microsoft Copilot, primary source, 15 September 2026.
- Opt out availableStated
- Yes for a signed in user, in the app under memory and personalisation or under account privacy training options, and personalisation can stay on independently.Microsoft, Copilot privacy controls, primary source, 15 September 2026.
- DPA availableSilent
- No data processing addendum exists for the consumer tier and none is referenced on either page.Microsoft, Copilot privacy controls, primary source, 15 September 2026.
- Persistent memory across sessionsStated
- Yes. With personalisation enabled Copilot remembers key details you share, such as your name, interests and goals, and memory can be switched off and cleared.Microsoft, privacy FAQ for Microsoft Copilot, primary source, 15 September 2026.
- Last change to the termsStated
- The consumer Copilot support pages print no effective date, only an app availability notice of 18 August 2026. The Microsoft privacy statement prints Last Updated September 2026.Microsoft privacy statement, primary source, 15 September 2026.
Figures
Every number, with who measured it and when
- 18 months
Default storage of conversation activity
Microsoft, privacy FAQ for Microsoft Copilot, primary source, as of .
What it changes
For a buyer or a workplace AI policy
Note who is already excluded before you write a rule. Signed out users, under eighteens, work accounts and six named countries are outside training already, so the population your policy actually needs to reach is signed in adults on personal accounts in the remaining markets. For them the opt out is per person and per device, which means a policy that relies on it needs a way to check it, not just a sentence telling staff to set it.
Sources
What this record was verified against
- Microsoft, privacy FAQ for Microsoft CopilotPrimary · 15 September 2026
- Microsoft, Copilot privacy controlsPrimary · 15 September 2026
- Microsoft privacy statementPrimary · 15 September 2026
Related
Records that sit beside this one
Microsoft 365 Copilot, now named Microsoft Copilot
United States · verified 15 September 2026
Prompts, responses and data accessed through Microsoft Graph are not used to train foundation large language models.
Azure OpenAI Service and models sold by Azure in Microsoft Foundry
United States · verified 15 September 2026
The models are stateless, no prompts or completions are stored in the model, and prompts and completions are not used to train, retrain or improve the base models.
ChatGPT Free, Plus and Pro
United States · verified 15 September 2026
Training is on by default on the consumer plans. The help centre says OpenAI may use content from services for individuals to train its models.
Amazon Bedrock
United States · verified 15 September 2026
Amazon Bedrock uses a zero data retention security model, so by default it does not store model inputs or outputs.
GitHub Copilot Business and Enterprise
United States · verified 15 September 2026
GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models.
Cursor and its privacy mode
United States · verified 15 September 2026
The terms of service state that Cursor will not use content to train any AI models unless you have explicitly agreed.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AVD-2026-0012 is permanent and is never reused.
- In a sentence
- According to the GAGE AI Vendor Data Ledger (as of 15 September 2026), microsoft copilot on a personal account.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Microsoft Copilot on a personal account. AI Vendor Data Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0012-microsoft-copilot-consumer
- MLA
- "Microsoft Copilot on a personal account." AI Vendor Data Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0012-microsoft-copilot-consumer.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Microsoft Copilot on a personal account." AI Vendor Data Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0012-microsoft-copilot-consumer.
- Permalink
- https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0012-microsoft-copilot-consumer
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any terms change a vendor announces.
Back to the full ledger, or every record for United States and every consumer tier record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.