GitHub General Privacy Statement - GitHub Docs
https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement • 304 KB fetched
Open original page
GitHub General Privacy Statement - GitHub Docs Skip to main content
GitHub Docs Version: Free, Pro, & Team
Search or ask Copilot Search or ask Copilot
Select language: current language is English
Search or ask Copilot Search or ask Copilot
Open menu
Collapse sidebar Expand sidebar
Scroll breadcrumbs left
* Home
* Site policy
* Privacy Policies
* GitHub General Privacy Statement
Scroll breadcrumbs right
Site policy
*
*
* GitHub Terms
* GitHub Terms of Service
* GitHub Corporate Terms of Service
* GitHub Terms for Additional Products and Features
* GitHub Community Guidelines
* GitHub Community Code of Conduct
* GitHub Pre-release License Terms
* GitHub DPA-Covered Previews
* GitHub Sponsors Additional Terms
* GitHub Registered Developer Agreement
* GitHub Marketplace Terms of Service
* GitHub Marketplace Developer Agreement
* GitHub Research Program Terms
* GitHub Open Source Applications Terms and Conditions
* GitHub Event Terms
* GitHub Event Code of Conduct
* GitHub Educational Use Agreement
* GitHub Copilot Extension Developer Policy
* GitHub Secret Scanning Partner Program Agreement
* Acceptable Use Policies
* GitHub Acceptable Use Policies
* Active Malware or Exploits
* Bullying and Harassment
* Disrupting the Experience of Other Users
* Doxxing and Invasion of Privacy
* Hate Speech and Discrimination
* Impersonation
* Disinformation Policy
* Sexually Obscene Content
* Threats of Violence and Gratuitously Violent Content
* Terrorism and Violent Extremism Content
* CSAM Policy
* NCII
* Synthetic Media and AI Tools
* GitHub Appeal and Reinstatement
* Privacy Policies
* GitHub General Privacy Statement
* GitHub Subprocessors
* GitHub Cookies
* GitHub Global Data Privacy Notice for Candidates
* Other Site Policies
* GitHub and Trade Controls
* GitHub Deceased User Policy
* GitHub Logo Policy
* GitHub Government Takedown Policy
* GitHub Username Policy
* Guidelines for Legal Requests of User Data
* GitHub Account Recovery Policy
* Content Removal Policies
* Submitting content removal requests
* DMCA Takedown Policy
* GitHub Private Information Removal Policy
* GitHub Trademark Policy
* Guide to Submitting a DMCA Counter Notice
* Guide to Submitting a DMCA Takedown Notice
* Security Policies
* Coordinated Disclosure of Security Vulnerabilities
* GitHub Bug Bounty Program Legal Safe Harbor
* GitHub SIRT description RFC 2350
* GitHub Company Policies
* GitHub Statement Against Modern Slavery and Child Labor
* GitHub Anti-Bribery Statement
* GitHub GPL Cooperation Commitment
* GitHub Gifts and Entertainment Policy
GitHub General Privacy Statement
Copy as Markdown
In this article
* GitHub Privacy Statement
* Personal Data We Collect
* Processing Purposes: How We Use Your Personal Data
* Sharing of Personal Data
* Private repositories: GitHub Access
* Lawful Bases for Processing Personal Data (Applicable to EEA and UK End Users)
* Your Privacy Rights
* International data transfers
* Data Privacy Framework (DPF)
* Security and Retention
* Security
* Contact Us
* Information for Minors
* Changes to Our Privacy Statement
* Translations
* Our use of cookies and tracking technologies
* US State Specific Information
GitHub Privacy Statement
Effective date: April 27, 2026
Welcome to the GitHub Privacy Statement. This is where we describe how we handle your “Personal Data”, which is information that is directly linked or can be linked to you. It applies to the Personal Data that GitHub, Inc. or GitHub B.V., processes as the “Data Controller” when you interact with websites, applications, and services that display this Statement (collectively, “Services”). This Statement does not apply to services or products that do not display this Statement, such as Previews, where relevant.
End User Notice: Organization-Provided GitHub Accounts
When a school or employer supplies your GitHub account, they assume the role of Data Controller for most Personal Data used in our Services. This enables them to:
* Manage and administer your GitHub account, including adjusting privacy settings.
* Access and utilize your Personal Data, which includes details on how you use the Services, as well as your content and files.
Should you access a GitHub Service through an account provided by an organization, such as your employer or school, the organization becomes the Data Controller, and this Privacy Statement's direct applicability to you changes. Even so, GitHub remains dedicated to preserving your privacy rights. In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller. For further details regarding their privacy practices, please refer to the privacy statement of the organization providing your account.
In cases where your organization grants access to GitHub products, GitHub acts as the Data Controller solely for specific processing activities. These activities are clearly defined in a contractual agreement with your organization, known as a Data Protection Agreement. You can review our standard Data Protection Agreement at GitHub Data Protection Agreement . For those limited purposes, this Statement governs the handling of your Personal Data. For all other aspects of GitHub product usage, your organization's policies apply.
Third Party Access and Data Protection
When you use third-party extensions, integrations, or follow references and links within our Services, the privacy policies of these third parties apply to any Personal Data you provide or consent to share with them. Their privacy statements will govern how this data is processed.
Personal Data We Collect
Personal Data is collected from you directly, automatically from your device, and also from third parties. The Personal Data GitHub processes when you use the Services depends on variables like how you interact with our Services (such as through web interfaces, desktop or mobile applications), the features you use (such as pull requests, Codespaces, or GitHub Copilot) and your method of accessing the Services (your preferred IDE). Below, we detail the information we collect through each of these channels:
From You
* Account Data: We collect certain information when you open an account such as your GitHub handle, name, email address, password, payment information and transaction information.
* User Content and Files: When you use our Services, we collect Personal Data included as part of the information you provide such as code, inputs, AI outputs, text, documents, images, or feedback.
* Demographic information: In some cases, you provide us with ethnicity, gender, or similar demographic details.
* Feedback Data: This consists of information you submit through surveys, reviews, or interactive features.
* Payment Information: For paid subscriptions, we collect details like name, billing address, and payment specifics.
* Profile Information: We collect information to create a user profile, which may include a photo, additional email addresses, job title, or biography.
* Sales and Marketing Data: This includes information provided for promotional communications, such as name, email address, and company name.
* Support Data: When you seek customer support, we collect details like code, text, or multimedia files.
Automatically
* Buttons, Tools, and Content from Other Companies: Our Services may contain links or buttons that lead to third-party services like Twitter or LinkedIn. Use of these features may result in data collection. Engaging with these buttons, tools, or content may automatically send certain browser information to these companies. Please review the privacy statements of these companies for more information.
* Essential Cookies and Similar Tracking Technologies: We use cookies and similar technologies to provide essential functionality like storing settings and recognizing you while using our Services.
* Non-essential Cookies: Depending on your jurisdiction, we may use online analytics products that use cookies to help us analyze how de-identified users use our Services and to enhance your experience when you use the Services. We may also employ third-party Cookies to gather data for interest-based advertising. In some jurisdictions, we only use non-essential cookies after obtaining your consent. See this section for more details and control options.
* Email Marketing Interactions: Our emails may have web beacons that offer information on your device type, email client, email reception, opens, and link clicks.
* Geolocation Information: Depending on the Service's functionality, we collect regional geolocation data.
* Service Usage Information: We collect data about your interactions with the Services, such as IP address, device information, session details, date and time of requests, device type and ID, operating system and application version, information related to your contributions to repositories, and performance of specific features or Services.
* Website Usage Data: We automatically log data about your Website interactions, including the referring site, date and time of visit, pages viewed, and links clicked.
From Third Parties
* Information from Other Users of the Services: Other users may share information about you when they submit issues and comments. We may also receive information about you if you are identified as a representative or administrator on your company's account.
* Publicly Available Sources: We may acquire information about you from publicly available sources.
* Services you linked to your GitHub account: When you or your administrator integrate third-party apps or services with our Services, we receive information based on your settings with those services. This can include details like your name and email from services like Google for authentication. The information we receive depends on the third-party's settings and privacy policies. Always review these to understand what data is shared with our Services.
* Vendors, Partners, and Affiliates: We may receive information about you from third parties, like vendors, resellers, partners, or affiliates for the purposes outlined in this statement.
Processing Purposes: How We Use Your Personal Data
The Personal Data we process depends on your interaction and access methods with our Services, including the interfaces (web, desktop, mobile apps), features used (pull requests, Codespaces, GitHub Copilot), and your preferred access tools (like your IDE). This section details all the potential ways GitHub may process your Personal Data:
* Business Operations: We use Personal Data for activities like billing, accounting, and compensation. This includes creating aggregated statistical data for internal reporting, financial reporting, revenue planning, capacity planning, and forecast modeling (including product strategy).
* Communication: We use Personal Data to inform you about new Services, features, offers, promotions, and other pertinent information. This also includes sending confirmations, invoices, technical notices, updates, security alerts, and administrative messages.
* Inference: We generate new information from other data we collect to derive likely preferences or other characteristics. For instance, we infer your general geographic location based on your IP address.
* Personalization: We use Personal Data to customize the Service to your preferences, to evaluate the effectiveness of enterprise business ads and promotional communications, and to ensure a seamless and consistent user experience.
* Safety and Security: To promote safety, integrity, and security across our Services, we process Personal Data, using both automated and, at times, manual techniques for abuse detection, prevention, and violations of terms of service.
* Service Provision: We use Personal Data to deliver and update our Services as configured and used by You, and to make ongoing personalized experiences and recommendations.
* Troubleshooting: We use Personal Data to identify and resolve technical issues.
* Ongoing Service Performance: Personal Data helps us keep the Services up to date and performant, and meet user productivity, reliability, efficacy, quality, privacy, accessibility and security needs.
* Product Development and Improvement: We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
* Complying with and resolving legal obligations: including responding to Data Subject Requests for Personal Data processed by GitHub as Controller (for example website data), tax requirements, agreements and disputes.
* Delivering Professional Services: We use Personal Data to deliver training, consulting or implementation (“Professional Services”). This includes providing technical support, professional planning, advice, guidance, data migration, deployment, and solution/software development services.
* Improving Professional Services: Enhancing delivery, efficacy, quality, and security of Professional Services and the underlying product(s) based on issues identified while providing Professional Services, including fixing software defects, and otherwise keeping the Professional Services up to date and performant.
When carrying out these activities, GitHub practices data minimization and uses the minimum amount of Personal Information required.
Sharing of Personal Data
We may share Personal Data with the following recipients:
* Abuse and Fraud Prevention Entities: We may disclose Personal Data based on a good faith belief it is needed to prevent fraud, abuse, or attacks on our Services, or to protect the safety of GitHub and our users.
* Affiliates: Personal Data may be shared with GitHub affiliates, including Microsoft, to facilitate customer service, marketing and advertising, order fulfillment, billing, technical support, legal and compliance obligations, product development and improvement (including training and improving artificial intelligence and machine learning technologies), and for other purposes described in their respective privacy statements. When we share data with affiliates, they will process it in accordance with applicable law and their privacy commitments.
* GitHub Organization Accounts: If an organization adds you to their GitHub account, we might share Personal Data with that organization to fulfill the commercial relationship. In such a case, your use of the Services is protected by a data protection agreement and terms between your organization and GitHub
* Competent Authorities: We may disclose Personal Data to authorized law enforcement, regulators, courts, or other public authorities in response to lawful requests or to protect our rights and safety. Please refer to our Guidelines for Legal Requests of User Data for more information.
* Corporate Transaction Entities: we might disclose Personal Data within the limits of the law and in accordance with this Privacy Statement for strategic business transactions such as sales or a merger.
* Partners and Resellers: We cooperate with third-parties that offer sales, consulting, support, and technical services for our Services. We may share your data with these partners and resellers where allowed, and with your consent when required.
* Subprocessors and Service Providers: We may use vendors to provide services on our behalf, including hosting, marketing, advertising, social, analytics, support ticketing, credit card processing, or security services. They are bound by contractual obligations to ensure the security, privacy, and confidentiality of your information. Please visit https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors to see our list of Subprocessors.
* Visual Studio Code (GitHub Codespaces): GitHub Codespaces and github.dev offer Visual Studio Code in a web browser, where some telemetry is collected by default. Details on telemetry collection are on the VS Code website . To opt out, go to File > Preferences > Settings in the top left menu of VS Code. Opting out will sync this preference across all future web sessions in GitHub Codespaces and github.dev.
* Other Third-party Applications: Upon your instruction, we may share Personal Data with third-party applications available on our Marketplace. You are responsible for the data you instruct us to share with these applications.
* Other Users and the Public: Depending on your account settings, we may share Personal Data with other users of the Services and the public. You control what information is made public. To adjust your settings, visit User Settings in your profile. Please be aware that any information you share in a collaborative context may become publicly accessible.
Private repositories: GitHub Access
If your GitHub account has private repositories, our ability and rights to access private repository information is set forth in Section E (Private Repositories) of the GitHub Terms of Service.
Lawful Bases for Processing Personal Data (Applicable to EEA and UK End Users)
GitHub processes Personal Data in compliance with the GDPR, ensuring a lawful basis for each processing activity. The basis varies depending on the data type and the context, including how you access the services. Our processing activities typically fall under these lawful bases:
* Contractual Necessity: Processing is required to fulfill our contractual duties to you, in accordance with the GitHub Terms of Service.
* Legal O
Links found on this page
- Skip to main content [direct]
- GitHub Docs [direct]
- Site policy [direct]
- Privacy Policies [direct]
- GitHub Terms of Service [direct]
- GitHub Corporate Terms of Service [direct]
- GitHub Terms for Additional Products and Features [direct]
- GitHub Community Guidelines [direct]
- GitHub Community Code of Conduct [direct]
- GitHub Pre-release License Terms [direct]
- GitHub DPA-Covered Previews [direct]
- GitHub Sponsors Additional Terms [direct]
- GitHub Registered Developer Agreement [direct]
- GitHub Marketplace Terms of Service [direct]
- GitHub Marketplace Developer Agreement [direct]
- GitHub Research Program Terms [direct]
- GitHub Open Source Applications Terms and Conditions [direct]
- GitHub Event Terms [direct]
- GitHub Event Code of Conduct [direct]
- GitHub Educational Use Agreement [direct]
- GitHub Copilot Extension Developer Policy [direct]
- GitHub Secret Scanning Partner Program Agreement [direct]
- GitHub Acceptable Use Policies [direct]
- Active Malware or Exploits [direct]
- Bullying and Harassment [direct]
- Disrupting the Experience of Other Users [direct]
- Doxxing and Invasion of Privacy [direct]
- Hate Speech and Discrimination [direct]
- Impersonation [direct]
- Disinformation Policy [direct]
- Sexually Obscene Content [direct]
- Threats of Violence and Gratuitously Violent Content [direct]
- Terrorism and Violent Extremism Content [direct]
- CSAM Policy [direct]
- NCII [direct]
- Synthetic Media and AI Tools [direct]
- GitHub Appeal and Reinstatement [direct]
- GitHub Subprocessors [direct]
- GitHub Cookies [direct]
- GitHub Global Data Privacy Notice for Candidates [direct]
- GitHub and Trade Controls [direct]
- GitHub Deceased User Policy [direct]
- GitHub Logo Policy [direct]
- GitHub Government Takedown Policy [direct]
- GitHub Username Policy [direct]
- Guidelines for Legal Requests of User Data [direct]
- GitHub Account Recovery Policy [direct]
- Submitting content removal requests [direct]
- DMCA Takedown Policy [direct]
- GitHub Private Information Removal Policy [direct]
- GitHub Trademark Policy [direct]
- Guide to Submitting a DMCA Counter Notice [direct]
- Guide to Submitting a DMCA Takedown Notice [direct]
- Coordinated Disclosure of Security Vulnerabilities [direct]
- GitHub Bug Bounty Program Legal Safe Harbor [direct]
- GitHub SIRT description RFC 2350 [direct]
- GitHub Statement Against Modern Slavery and Child Labor [direct]
- GitHub Anti-Bribery Statement [direct]
- GitHub GPL Cooperation Commitment [direct]
- GitHub Gifts and Entertainment Policy [direct]
- GitHub Data Protection Agreement [direct]
- VS Code website [direct]
- Commission Implementing Decision 2021/914 [direct]
- European Commission website [direct]
- https://www.dataprivacyframework.gov/ [direct]
- https://go.adr.org/dpf_irm.html [direct]
- https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction [direct]
- notify us [direct]
- Déclaration de confidentialité de GitHub (PDF) [direct]
- https://docs.github.com/ [direct]
- Do Not Track [direct]
- Privacy Badger [direct]
- uBlock Origin [direct]
- Global Privacy Control — Take Control Of Your Privacy [direct]
- NAI [direct]
- DAA [direct]
- Digital Advertising Alliance of Canada [direct]
- European Digital Advertising Alliance [direct]
- Private Information Removal request [direct]
- GitHub support [direct]