Cody (Sourcegraph)
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product”
Watch: audit rights dpa residency
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
US-based storage and processing may create compliance concerns for EU/EEA, UK, and other jurisdiction users subject to data residency or transfer restrictions. Standard Contractual Clauses are mentioned as a transfer mechanism, but no data residency choice is offered.
This clause limits the effectiveness of user deletion rights by preserving cached and archived copies of posted content. This may conflict with GDPR right-to-erasure expectations and creates ongoing exposure for users who believe they have deleted their content.
Caps liability at five times (5x) annual license fees for breaches of confidentiality or data security in connection with use of Sourcegraph AI Tools where the customer's agreement otherwise provides uncapped liability, and preserves the existing contractual liability cap for customers without uncapped liability, thereby establishing a tiered limitation of liability framework specific to AI Tools usage.
Scores derived from 36 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Cody (Sourcegraph)'s training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
- Your outputs and prompts are explicitly yours — Cody (Sourcegraph)'s terms include affirmatively protective IP language.
- Data handling is conditional — 3 privacy or retention clauses warrant review before using Cody (Sourcegraph) at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Cody (Sourcegraph)'s own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 103 verified, verbatim-cited findings below — read the citations.
Based on 109 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 7 citationsstaticLast captured 2026-08-28
- Privacy PolicyVerified - read in full - 29 citationsstaticLast captured 2026-07-29
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Restricts Sourcegraph Partner LLMs from using Enterprise subscription code to train models, and conditionally permits Sourcegraph to finetune a model using customer data only if the customer enables finetuning features, establishing a permission conditioned on customer action.
" Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
The zero-training guarantee covers Partner LLMs and code specifically. An opt-in finetuning carve-out allows Sourcegraph to use user data for model finetuning, which could constitute training use if enabled. Users should carefully evaluate before enabling finetuning.
"Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
The clause grants Sourcegraph a broad right to perform automated scanning of user-connected codebases and data sources for advertising relevance. The limitation that 'no personal data will be collected' is self-assessed and may not cover all sensitive code or business logic. Users on free tiers should be aware their code is being analyzed for commercial advertising purposes.
"When you use Amp Free Mode, we may perform periodic, automated keyword searches of your files, codebase, or data sources that you have connected to Amp in order to deliver context-specific advertisements to you. No personal data will be c..."
This clause discloses that automatically collected behavioral data (usage patterns, habits, codebase information) is used for targeted advertising. This represents a commercial use of user data that may be unexpected for a developer productivity tool.
"serve you relevant advertisements from Amp Free Mode Advertising Partners;"
Summarizes key legal commitments including non-sale of information, use of third-party subprocessors, cookie use for advertising in Amp Free Mode, and user rights under privacy laws, each incorporating by reference more detailed provisions in the document.
" We do not sell your information. ( read more ) We use a number of trusted third parties to help provide our products. ( read more ) We use cookies to provide, protect, and promote our own products and Amp Free Mode is advertiser-sponsor..."
This clause establishes a data sharing relationship with Advertising Partners. While only aggregated data is shared by Sourcegraph, clicking an ad results in direct data transfer to the Advertising Partner governed by that partner's policies. Users lose control of that data at the point of click.
"Certain Sourcegraph products, specifically Amp Free Mode, are provided free of charge to users and are sponsored by Advertising Partners. Users of Amp Free Mode are shown ads that may be relevant to them, based on information gathered by ..."
Defines the scope of the Privacy Policy, identifies the entity 'Sourcegraph,' defines 'Services,' and carves out Customer Personal Data from this policy's coverage, directing that such data is governed by separate customer agreements; establishes binding consent by use of the Service.
" See the changes since the previous version or visit our archives . At Sourcegraph, Inc. ( "Sourcegraph," "we," "our," or "us" ), we value your privacy. This Privacy Policy explains how we collect, use, share and protect your personal inf..."
Disclaims intentional collection of personal information in repositories or free-form inputs and assigns responsibility for any such data to the repository owner, limiting Sourcegraph's liability.
" We do not intentionally collect any Personal Information that is stored in your repositories or other free-form content inputs. Any Personal Information within a user's repository is the responsibility of the repository owner."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
"Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
This span carries the plan-specific language - verbatim from the policy.
The zero-training guarantee covers Partner LLMs and code specifically. An opt-in finetuning carve-out allows Sourcegraph to use user data for model finetuning, which could constitute training use if enabled. Users should carefully evaluate before enabling finetuning.
AI-generated interpretation, not legal advice.
"When you use Amp Free Mode, we may perform periodic, automated keyword searches of your files, codebase, or data sources that you have connected to Amp in order to deliver context-specific advertisements to you. No personal data will be collected or processed during a keyword search. Data access is moment-in-time, on a per-advertisement basis, and is not ongoing. Results of keyword scans are exclusively used for advertisement placement applicability and not for any other reason, and results are not co-mingled with any other data collected. The results of keyword searches are not shared with Advertising Partners"
The clause grants Sourcegraph a broad right to perform automated scanning of user-connected codebases and data sources for advertising relevance. The limitation that 'no personal data will be collected' is self-assessed and may not cover all sensitive code or business logic. Users on free tiers should be aware their code is being analyzed for commercial advertising purposes.
AI-generated interpretation, not legal advice.
"serve you relevant advertisements from Amp Free Mode Advertising Partners;"
This clause discloses that automatically collected behavioral data (usage patterns, habits, codebase information) is used for targeted advertising. This represents a commercial use of user data that may be unexpected for a developer productivity tool.
AI-generated interpretation, not legal advice.
"If you join an Organization, you agree to provide the administrator of the Organization with the ability to view your activity in the Organization's access log."
Users who join Organizations consent to employer/admin visibility over their activity. This is relevant to enterprise deployments and could affect user privacy expectations, particularly for employee monitoring compliance in various jurisdictions.
AI-generated interpretation, not legal advice.
"If you remove information or content that you posted to the Services, copies may remain viewable in cached and archived pages of the Services, or if other users have copied or saved that informatio"
This clause limits the effectiveness of user deletion rights by preserving cached and archived copies of posted content. This may conflict with GDPR right-to-erasure expectations and creates ongoing exposure for users who believe they have deleted their content.
AI-generated interpretation, not legal advice.
" Sourcegraph's AI Tools use context from your codebase to substantially improve the accuracy of its responses compared to other AI-based tools. However, Sourcegraph does not guarantee the accuracy of the AI Tools' answers. Outputs generated by the AI Tools are provided "as is" and without warranty of any kind. You are solely responsible for reviewing and validating any Outputs before use."
Disclaims any warranty of accuracy for AI Tools' outputs, provides outputs on an 'as is' basis without warranty of any kind, and assigns to the customer sole responsibility for reviewing and validating outputs before use, limiting Sourcegraph's liability for output quality.
AI-generated interpretation, not legal advice.
"When you register for a Sourcegraph account, participate in forums, comment on blog posts, submit a feedback survey, submit prompts, or correspond with us, we may collect account information (username, password, email), profile information (display name, avatar URL), Content you post, add, receive, or share on our hosted services, and any payment information. W"
The explicit inclusion of 'submit prompts' in the data collection list means that user AI prompts are treated as collected personal information. Combined with the subprocessor sharing clause (prompts shared with service providers), this creates a meaningful chain of data exposure for AI interactions.
AI-generated interpretation, not legal advice.
"Google Analytics and Advertising . We may also utilize certain forms of display advertising and other advanced features through Google Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third-party cookies to inform, optimize, and display ads based on your past visits to the Sites."
Use of Google Analytics remarketing features results in past-visit behavioral data being shared with Google for ad optimization. This implicates GDPR, CCPA, and ePrivacy obligations. Opt-out is available but not automatic.
AI-generated interpretation, not legal advice.
" We may also collect analytics data, or use third-party analytics tools, to help us measure traffic and usage trends for the Services. These tools collect information sent by your browser or mobile device, including the pages you visit, your use of third-party applications, and other information that assists us in analyzing and improving the Services. Although we do our best to honor the privacy preferences of our users, we are not able to respond to Do Not Track signals from your browser at this time."
Restricts keyword scan results to advertisement placement applicability only, prohibits their use for any other purpose, prohibits co-mingling with other collected data, and prohibits sharing results with Advertising Partners, establishing binding data-use limitations on Amp Free Mode processing.
AI-generated interpretation, not legal advice.
"Certain Sourcegraph products, specifically Amp Free Mode, are provided free of charge to users and are sponsored by Advertising Partners. Users of Amp Free Mode are shown ads that may be relevant to them, based on information gathered by Sourcegraph about their habits and codebase. The only information Sourcegraph shares with Advertising Partners is aggregated information about our Amp Free Mode customer base as a whole. If you click on an advertisement, any information you provide will be directly to the Advertising Partner and not to Sourcegraph."
This clause establishes a data sharing relationship with Advertising Partners. While only aggregated data is shared by Sourcegraph, clicking an ad results in direct data transfer to the Advertising Partner governed by that partner's policies. Users lose control of that data at the point of click.
AI-generated interpretation, not legal advice.
" If you have uncapped liability for breach of confidentiality or data security in your Agreement with Sourcegraph, a limit of liability of five times (5x) your annual license fees will apply to breaches of confidentiality or data security in connection with your use of Sourcegraph AI Tools. If you do not have uncapped liability in your Agreement with Sourcegraph, the limit of liability in your Agreement shall apply to your use of all features. For more information, see https://sourcegraph.com/docs/cody"Permalink to this finding →
Caps liability at five times (5x) annual license fees for breaches of confidentiality or data security in connection with use of Sourcegraph AI Tools where the customer's agreement otherwise provides uncapped liability, and preserves the existing contractual liability cap for customers without uncapped liability, thereby establishing a tiered limitation of liability framework specific to AI Tools usage.
AI-generated interpretation, not legal advice.
"We may share your Personal Information with another entity in connection with a company transaction, such as a merger, acquisition, sale of assets or shares, reorganization, or bankruptcy. In these cases we may transfer some or all of your Personal Information to another entity, subject to this Privacy Policy. We may also share your Personal Information with any companies owned by or under common ownership with Sourcegraph, subject to this Privacy Policy. "
This is a standard but meaningful risk clause: personal data can be transferred to acquirers or affiliates with minimal user control. The phrase 'subject to this Privacy Policy' provides only weak protection since acquiring entities may update or supersede the policy.
AI-generated interpretation, not legal advice.
"If you are a member of an Organization, we may share your username, email, IP address, and any collected logs about the user associated with that Organization with an owner or administrator of the Organization to investigate or respond to a security incident that affects or compromises the security of that particular Organization. "
This clause enables organizational administrators to receive detailed user activity data. For users in enterprise or team environments, this effectively means their employer/org admin can access behavioral and access logs, which is a meaningful reduction in individual privacy.
AI-generated interpretation, not legal advice.
"Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy."
US-based storage and processing may create compliance concerns for EU/EEA, UK, and other jurisdiction users subject to data residency or transfer restrictions. Standard Contractual Clauses are mentioned as a transfer mechanism, but no data residency choice is offered.
AI-generated interpretation, not legal advice.
" Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
"Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
This span carries the plan-specific language - verbatim from the policy.
Restricts Sourcegraph Partner LLMs from using Enterprise subscription code to train models, and conditionally permits Sourcegraph to finetune a model using customer data only if the customer enables finetuning features, establishing a permission conditioned on customer action.
AI-generated interpretation, not legal advice.
" Sourcegraph also collects Usage Data (usage and operations data in connection with your use of AI features, such as metrics on frequency and length of a user feature engagement) and User Feedback (any form of feedback that the user submits, including thumbs up and thumbs down clicks and comments or ideas shared for the purpose of giving feedback). For the avoidance of doubt, Usage Data and User Feedback do not capture Customer Content."
Defines 'Usage Data' and 'User Feedback' as additional data categories collected by Sourcegraph, and clarifies via a 'for the avoidance of doubt' statement that these categories do not capture Customer Content, thereby establishing a definitional boundary that limits the scope of the Customer Content restrictions.
AI-generated interpretation, not legal advice.
" When you register for a Sourcegraph account, participate in forums, comment on blog posts, submit a feedback survey, submit prompts, or correspond with us, we may collect account information (username, password, email), profile information (display name, avatar URL), Content you post, add, receive, or share on our hosted services, and any payment information. We do not process or store your payment information, but our third-party payment processor does."
Specifies the categories of personal information Sourcegraph collects directly from users (account info, profile info, content, payment info) and disclaims responsibility for payment data storage by delegating that to a third-party processor, creating a disclosure obligation and subprocessor reference.
AI-generated interpretation, not legal advice.
" Event analytics data and metadata to better understand usage within the Services, including click patterns and length and frequency of feature utilization, tied to an internally-generated user ID number. When you visit our website or use our Services, we may automatically collect the following information."
Discloses use of cookies to identify browsers, facilitate login, and track user navigation and behavior over time, fulfilling cookie disclosure obligations under privacy regulations.
AI-generated interpretation, not legal advice.
Common questions about Cody (Sourcegraph)'s policies
- Does Cody (Sourcegraph) train its AI models on your data?
- Training possible — conditions or opt-outs apply — based on 4 verified findings from Cody (Sourcegraph)'s published policy. Informational only, not legal advice.
- Who owns the content you create with Cody (Sourcegraph)?
- You own your outputs — based on 1 verified finding from Cody (Sourcegraph)'s published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Cody (Sourcegraph)'s own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
21 verified clausesClauses in Cody (Sourcegraph)'s policies that work in your favour — commitments the platform made to you.
- Privacy & data use
“Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy. For all website visitor…”
Enumerates data subject rights including the right to restrict processing and the right to complain to a supervisory authority, establishing legally enforceable rights available to users under applicable privacy laws.
Location: exact-text link only — source has no section structureJump to exact text → - Privacy & data usechildren's data
“Sourcegraph does not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to register as Users. If you are based in the European Union, we will not knowingly collect your information if you are under th…”
This clause restricts Sourcegraph from knowingly collecting personal information from children under age 13 (or 16 in the EU), prohibits minors below applicable consent age from registering, and imposes an obligation to…
Location: exact-text link only — source has no section structureJump to exact text → - Model trainingdoes-not-train
“Sourcegraph collects the following Customer Content solely to provide the Service and not for product improvement purposes: Inputs (submitted queries) Outputs (completions generated) Candidate Context (Code, User Content, or other relevant information that…”
The data use limitation to service delivery is a favorable restriction. The separation of Customer Content from Usage Data/User Feedback provides clarity. However, no cross-reference to a privacy policy or DPA specifying…
📍 § 4 (Data collection and use)Jump to exact text → - Data retentiondeletion rights & post-termination survival
“Sourcegraph has entered into partnerships with certain Large Language Models ("LLMs") ( "Sourcegraph Partner LLMs" ) to provide the services. Sourcegraph Partner LLMs will not retain any Input or Output from the model, including embeddings, beyond the time it…”
Imposes a Zero Retention obligation on Sourcegraph Partner LLMs, prohibiting them from retaining any Input, Output, or embeddings beyond the time needed to generate the Output, while carving out an exception permitting S…
📍 § 2 (Sourcegraph Partner LLMs)Jump to exact text → - Indemnity & liabilityindemnity direction
“Sourcegraph will indemnify you against any claims alleging that your use of AI Tools or any Outputs infringe third-party intellectual property rights in accordance with the indemnification terms in your agreement. Sourcegraph's indemnification obligation is…”
This is an unusually strong indemnity provision in favor of the user. The uncapped indemnity is conditional on (1) a signed Order Form, (2) use of the most current version, and (3) use of provided filters. Failure to mee…
📍 § 5 (Full IP Indemnification)Jump to exact text → - Subprocessors & data sharing
“Our service providers process your Personal Information as needed to provide our Services to you, including your content and processing prompts to help you write code. They may only process your Personal Information pursuant to our instructions and to perfor…”
Obligates service providers to process personal information only per Sourcegraph's instructions and for specified purposes, and references the Subprocessors page as the authoritative list, creating a data-processing rest…
Location: exact-text link only — source has no section structureJump to exact text →
+ 15 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
1 verified clauseWhat Cody (Sourcegraph) requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcement
“You may not use Sourcegraph AI Tools for unlawful purposes or in violation of our Acceptable Use Policy .”
Prohibits the customer from using Sourcegraph AI Tools for unlawful purposes or in violation of the Acceptable Use Policy, incorporating that policy by reference as an enforceable restriction on permitted use.
📍 § 7 (Acceptable use)Jump to exact text →
What the policies actually cover
10 topics- Product telemetry & usage tracking5 clauses
- Advertising & tracking4 clauses
- Sale or sharing of personal data3 protective3 clauses
- Sensitive data (biometric, location, health)1 protective1 clause
- Children's data1 protective1 clause
- Government & law-enforcement disclosure1 clause
- Does not train on your content4 protective4 clauses
- Damages & liability cap2 clauses
- Indemnity direction1 protective1 clause
- Deletion rights & post-termination survival2 protective4 clauses
28 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy addresses how long content is retained, and the policy document, § 3 (Model training) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we co...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we co...”Open source citation
The clause provides a deletion or time-bounded retention path.
“You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as c...”Open source citation
The clause provides a deletion or time-bounded retention path.
“You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as c...”Open source citation
The clause affirms user ownership or retention of rights.
“As between the parties, you own all Inputs to and Outputs generated by your use of Sourcegraph. You retain ownership of your code and responsibility for ensuring any code snippets emitted by Sourcegraph comply with software licenses and copyright law.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | indemnity liability | conditional | MEDIUM | 2 |
| All applicable tiers | output ownership | improves | LOW | 2 |
| All applicable tiers | privacy data use | worsens | HIGH | 8 |
| All applicable tiers | prompt ownership | improves | LOW | 2 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 6 |
| All applicable tiers | training use | worsens | HIGH | 4 |
| Enterprise | data retention | improves | LOW | 2 |
| Enterprise | training use | improves | LOW | 2 |
| Free | privacy data use | worsens | HIGH | 1 |
| Free | subprocessors data sharing | conditional | MEDIUM | 1 |
| Free | tier differences | conditional | MEDIUM | 2 |
| Government | tier differences | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
model training worsened from low/no training claim to high/training permitted.
“Sourcegraph Partner LLMs will not retain any Input, Output, or Candidate Context beyond the time it takes to generate the Output ( "Zero Retention" ), except that Partner LLMs may temporarily retain Inputs and Outputs solely for the purpose of detecting and preventing abuse or serious harm, and will not use such data for model training or any other purpose, provided that you access AI Tools through Sourcegraph's Partner LLMs. This Zero Retention obligation does not restrict Sourcegraph from storing or persisting Inputs or Outputs to enable the functionality of the AI Tools. Sourcegraph may update this definition from time to time to reflect changes in Partner LLM retention practices by updating the 'last modified' date on this page.”Before citation
“We use personal data to: Provide, operate, and maintain the Services , including enabling access, administering accounts, supporting features, and delivering functionality to our customers. Secure and protect the Services , including monitoring for misuse, detecting and investigating security incidents, maintaining audit logs, and enforcing our policies. Understand and improve how customers use the Services , including analyzing aggregated usage patterns, performance metrics, and reliability data to develop new features, improve existing functionality, and support product planning. Conduct research and analysis , including analyzing trends and publishing findings based on aggregated or de-identified data and deriving Inferences about how customers and users interact with our products and Services, including usage preferences, feature adoption patterns, and engagement trends, to improve our products and Services. Track Analytics , including tracking feature adoption and usage, understanding usage patterns across users and teams, and measuring engagement to improve the functionality of existing features and develop new products and features. Operate and improve our Website and marketing activities , including understanding Website usage, measuring engagement, and promoting the Services. Communicate with you , including responding to inquiries or form submissions, providing support and customer success services (which may include proactive outreach based on usage patterns to offer guidance, training, or assistance), sending service-related notices, and sharing information about updates or changes to the Services.”After citation
Latest stance: third party or vendor sharing on privacy data use
“Our servers and operations are located in the United States, and we have team members located around the world. If you access our Website or Services from outside the United States, your personal data will be transferred to, stored, and processed in the United States and potentially in other countries where our teammates are located. Transfers from the European Economic Area, United Kingdom, and Switzerland. For personal data originating from the EEA, UK, or Switzerland, we rely on the Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office as the legal mechanism for transferring your personal data to the United States. United States Privacy Rights. If you are a resident of California or another U.S. state with comprehensive privacy legislation, please note that we may transfer your personal data to Service Providers and other third parties as described in the How We Share Personal Data section above.”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we collect and process. For detailed information about our security practices, please refer to our Security Page . While we are committed to maintaining industry-standard or better security practices and continuously work to protect your data, no method of transmission over the Internet is completely secure. We cannot guarantee absolute security of your personal data. Your Security Responsibilities. You are responsible for maintaining the confidentiality of your Account Information and for any activity that occurs under your account. If you believe your account has been compromised, please contact us immediately at security@sourcegraph.com . Enterprise customers and their administrators are responsible for managing user access, permissions, and security configurations within their organizational workspace. Data Retention. We retain your personal data for as long as necessary to perform our contractual obligations and provide the Services to you and your organization. When personal data is no longer necessary for these purposes, we delete it in accordance with our data retention policies, though we may retain certain information necessary to attribute work product to and maintain the integrity of the organizational workspace.”Open timeline citation
Latest stance: deletion or time bound on data retention
“You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as customer source code) that we process as a Data Processor on behalf of our customers, please direct your request to the relevant customer organization. We will assist the customer in responding to your request in accordance with our customer agreements and applicable law. Access and Portability. You have the right to access and receive a copy of the personal data we hold about you in a structured, commonly used, machine-readable format. Where technically feasible, you may request that we transmit your personal data directly to another controller. Correction. You have the right to request correction of inaccurate or incomplete personal data. If you use our Services, you can update certain Account Information and Contact Information through your account settings. Deletion. You have the right to request deletion of your personal data, subject to certain limitations. For Website visitors: We will delete your personal data upon request, subject to our need to retain certain information to comply with legal obligations or fulfill legitimate business interests.”Open timeline citation
Latest stance: training permitted on training use
“We use personal data to: Provide, operate, and maintain the Services , including enabling access, administering accounts, supporting features, and delivering functionality to our customers. Secure and protect the Services , including monitoring for misuse, detecting and investigating security incidents, maintaining audit logs, and enforcing our policies. Understand and improve how customers use the Services , including analyzing aggregated usage patterns, performance metrics, and reliability data to develop new features, improve existing functionality, and support product planning. Conduct research and analysis , including analyzing trends and publishing findings based on aggregated or de-identified data and deriving Inferences about how customers and users interact with our products and Services, including usage preferences, feature adoption patterns, and engagement trends, to improve our products and Services. Track Analytics , including tracking feature adoption and usage, understanding usage patterns across users and teams, and measuring engagement to improve the functionality of existing features and develop new products and features. Operate and improve our Website and marketing activities , including understanding Website usage, measuring engagement, and promoting the Services. Communicate with you , including responding to inquiries or form submissions, providing support and customer success services (which may include proactive outreach based on usage patterns to offer guidance, training, or assistance), sending service-related notices, and sharing information about updates or changes to the Services.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-08-28· verified 2026-08-28
- Privacy Policy:Last captured 2026-07-29· verified 2026-07-29
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↓ 30 fewer findings this quarter vs last (64 vs 94). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Cody (Sourcegraph)'s policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Cody (Sourcegraph)'s own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.