Microsoft Copilot
Microsoft · Chat assistant · US · copilot.microsoft.com
services/microsoft-copilot.yamlVendor data-handling terms
This entry covers copilot.microsoft.com with a personal Microsoft account or no account. Work-account use with enterprise data protection is the Microsoft 365 Copilot entry.
“As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.”
“Microsoft retains personal data for as long as necessary to provide the products and services you use and to fulfill the transactions you request.”
“Personal data collected by Microsoft may be stored and processed in your region, in the United States, and in any other jurisdiction where Microsoft or its affiliates, subsidiaries, or service providers operate facilities.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| copilot.microsoft.com | app | observed |
Assessment
Reasoning: The same product surface serves two regimes. On a personal account, consumer terms allow training and worldwide processing and there is no processor agreement for the employer. Signed in with a work account, enterprise data protection applies and the Microsoft 365 Copilot terms take over. The account in use decides the exposure, which is exactly what a network view cannot see and a prompt-level view can.
Flags: Consumer terms unless signed in with a work account · GDPR Art. 28 (no processor agreement on personal accounts) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Consumer-regime terms verified against the Microsoft Privacy Statement.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.