Microsoft Copilot is reasonably secure, but it isn’t private by default. For personal accounts, Microsoft says it uses Copilot conversations to train its AI models unless you opt out, stores conversation history for 18 months, has some conversations reviewed by people, and can use your Copilot history to personalize ads if you have personalized ads turned on. Work and school accounts, people under 18 and users in some countries are treated differently.
Here’s what Microsoft’s own privacy FAQ says, who is excluded from training, and the settings that make the biggest difference.
Does Microsoft use Copilot chats to train AI? #
Yes, for most consumer users. Microsoft’s Copilot privacy FAQ says that “except for certain categories of users or users who have opted out, Microsoft uses data from Bing, MSN, Copilot, and interactions with ads on Microsoft for AI training.”
Microsoft says it removes identifying details first: “We remove information that may identify you, like names, phone numbers, device or account identifiers, sensitive personal data, physical addresses, and email addresses, before training AI models.” For images and files, it says it takes steps such as removing metadata and blurring faces.
That de-identification helps, but it isn’t a guarantee. A conversation about your specific situation can still be recognizable from its details, and automated removal can miss things.
Who is excluded from Copilot training? #
According to the same FAQ, Microsoft doesn’t use conversations for training from:
- people signed in with a work or school account (Microsoft Entra ID)
- people using Copilot inside Microsoft 365 consumer apps
- people who aren’t signed in
- users under 18
- users in Brazil, China (excluding Hong Kong), Israel, Nigeria, South Korea and Vietnam
If you’re outside those groups, you’re included unless you opt out.
Does opting out delete what’s already been used? #
No. Microsoft says: “Opting out will exclude your future conversations from being used for training these AI models, unless you choose to opt back in.” Past conversations aren’t pulled back out. If you’re going to opt out, do it before you start using Copilot for anything personal.
How long does Copilot keep your conversations? #
Microsoft says: “By default, we store conversation activity for 18 months.” You can delete individual conversations or your entire history at any time.
Do humans read Copilot chats? #
Some. Microsoft says “some Copilot conversations are subject to both automated and human review for product improvement and digital safety purposes.” According to its FAQ, there’s no setting to opt out of human review. That’s similar to other big chatbots; we compare them in do humans read your AI chats?
Does Copilot use your chats for ads? #
It can. Copilot’s personalization setting is separate from your ad settings, but Microsoft says that if you have personalized ads enabled and Copilot personalization on, it will use your Copilot conversation history to help personalize the ads you see. Turning off either one stops that link.
For how other AI companies handle this, see do AI chatbots use your chats for ads?
Copilot privacy settings to change #
These are the controls that matter most. Setting names and menu locations change between versions of the Copilot app and website, so look for these in the privacy section of Copilot’s settings (usually under your profile):
- Turn off model training. This stops your future conversations being used to train Microsoft’s models.
- Turn off personalization and memory if you don’t want Copilot remembering details about you between chats. This also breaks the link between your chats and personalized ads.
- Turn off personalized ads in your Microsoft account’s privacy dashboard at account.microsoft.com.
- Delete your conversation history, or individual conversations you don’t want kept.
- Use Copilot without signing in for one-off questions. Microsoft says conversations from users who aren’t signed in aren’t used for training, though they’re still processed on Microsoft’s servers.
Our step-by-step guide to deleting your data from AI chatbots covers Copilot alongside ChatGPT, Gemini and others.
Is Copilot safe for work documents? #
It depends entirely on which Copilot and which account.
- A work or school account (Microsoft Entra ID): Microsoft excludes these from training, and your organization’s administrators control how Copilot is set up. This is the version your employer is likely to approve.
- A personal Microsoft account: consumer terms apply, including default training and 18-month history. Pasting work material into a personal Copilot account may break your employer’s rules, even on your own phone.
When in doubt, ask your IT team which AI tools are approved. Our guide to using AI at work without leaking data explains the difference between consumer and business accounts across the major chatbots.
What’s the most private alternative? #
Every cloud chatbot, Copilot included, involves sending your words to someone else’s servers. Settings reduce what happens to them afterwards; they don’t change that first step.
If you want an AI for questions you’d rather nobody else stored, the alternative is a model that runs on your own device. Personal LLM runs open models such as Qwen 3.5 and Gemma 4 directly on an iPhone or Android phone. There’s no account, no server and no conversation history anywhere but the phone. After a one-time model download from Hugging Face, it works in airplane mode, which is the easiest way to confirm nothing is being sent. Ads in the free version come from Google AdMob and only load when you’re online.
The trade-off is capability. A phone-sized model can’t search the web and is less capable than the models behind Copilot. Many people split the work: Copilot for web-connected questions and documents their employer has approved, and a local model for anything personal.
Frequently asked questions #
Is Microsoft Copilot safe to use? #
For everyday questions, yes. It’s run by a large company with strong security practices. The privacy trade-offs are that consumer conversations are used for training by default, kept for 18 months, sometimes reviewed by people, and can inform ads if personalization and ad settings are on.
Does Copilot save my conversations? #
Yes. Microsoft stores conversation activity for 18 months by default. You can delete individual conversations or your whole history from Copilot’s settings.
Can I stop Copilot from training on my data? #
Yes. Turn off model training in Copilot’s privacy settings. Microsoft says this applies to future conversations only, so change it before you share anything personal.
Is Copilot with a work account more private? #
Microsoft says it doesn’t use conversations from work or school accounts signed in with Microsoft Entra ID for training. Your employer’s administrators control other settings and may be able to access activity under company policy.