Skip to main content
Platform Review
PricingSign in
← All platforms
Developer / Coding · sourcegraph.com

Sourcegraph Cody

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskMEDReviewed 2026-07-29
Creator: medium · GRC: medium · Counsel: medium
creator band
Adequate
enterprise · Caution
Dealbreaker · Training without opt-out
Exhibit A · Terms of Service · verbatim

Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product

cited by the training without opt-out dealbreaker — tap for the citation
52 verified findings11 policy surfaces1/2 core docs verified

Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.

Risk triage

Watch: audit rights dpa residency

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
22
medium
30
low
1/2
docs
Trains on your data?
No training on your content by default
from 4 cited findings
Who owns outputs?
You own your outputs
from 1 cited finding
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →
Risk by role
Select a role to tailor the summary and reorder the findings below.

Scores derived from 42 enriched findings — same verbatim citations as below. AI-generated, not legal advice.

What this means for you
  • Sourcegraph Cody's training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
  • Your outputs and prompts are explicitly yours — Sourcegraph Cody's terms include affirmatively protective IP language.
  • Data handling is conditional — 3 privacy or retention clauses warrant review before using Sourcegraph Cody at scale.

Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.

How to read this page: Overall risk rates what Sourcegraph Cody's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Creator lens
Your prompts, your outputs, your IP
ADEQUATE
Dealbreaker — Training without opt-out. Your inputs/outputs are used to train models and the policy provides no way to decline. see the clause

Based on 104 verified, verbatim-cited findings below — read the citations.

Enterprise lens
Data use, retention, subprocessors, audit
CAUTION
Dealbreaker — Training without opt-out. Your inputs/outputs are used to train models and the policy provides no way to decline. see the clause

Based on 113 verified, verbatim-cited findings below — read the citations.

Automated assessment against a published rubric — not legal advice.

Partially verifiedDeveloper / Coding

Partially verified — Terms of Service — Capture pending; Privacy Policy — Verified (read in full, 34 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Held for review

A core policy document failed verification or contains contested evidence that must not be treated as fully verified.

Document status
  • Terms of Service
    Capture pendingstatic-revalidated
  • Privacy Policy
    Verified - read in full - 34 citationsstaticLast captured 2026-07-29
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

enterprise
Training on your content

The no-training commitment is scoped to Sourcegraph Partner LLMs, not Sourcegraph's own models. The opt-in finetuning carveout means enabling certain product features could expose user data to model training. The terms and limits of that fine-tuning use are not specified here.

"Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
📍 § 3 (Model training)Jump to exact text →
enterprise
Training on your content

Restricts Sourcegraph Partner LLMs from using Enterprise subscription code to train models, and creates a conditional permission allowing Sourcegraph to finetune a model using customer data only if the customer enables finetuning features — establishing both a training prohibition and a limited opt-in exception.

" Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
📍 § 3 (Model training)Jump to exact text →
plan language
Privacy & data use

Defines the scope of the Privacy Policy, identifies the data controller ('Sourcegraph'), defines 'Services' and 'Customer Personal Data', and establishes that by using the Service the user agrees to the policy terms — creating a binding incorporation of obligations.

" See the changes since the previous version or visit our archives . At Sourcegraph, Inc. ( "Sourcegraph," "we," "our," or "us" ), we value your privacy. This Privacy Policy explains how we collect, use, share and protect your personal inf..."
📍 Privacy Policy › “Last modified: October 15, 2025”Jump to exact text →
plan language
Privacy & data use

Disclaims intentional collection of personal information in repositories and free-form inputs, while allocating responsibility for such data to the repository owner rather than Sourcegraph.

" We do not intentionally collect any Personal Information that is stored in your repositories or other free-form content inputs. Any Personal Information within a user's repository is the responsibility of the repository owner."
📍 Privacy Policy › “Personal Information in Repositories”Jump to exact text →
plan language
Privacy & data use

Continues and elaborates the Amp Free Mode advertising data sharing permission, specifying what information flows to Advertising Partners (aggregated only) and what happens when users click ads (data goes to partner directly), delineating Sourcegraph's sharing boundaries.

" Certain Sourcegraph products, specifically Amp Free Mode, are provided free of charge to users and are sponsored by Advertising Partners. Users of Amp Free Mode are shown ads that may be relevant to them, based on information gathered by..."
📍 Privacy Policy › “Advertisers in Amp Free Mode”Jump to exact text →
plan language
Privacy & data use

Summary section incorporating key obligations and rights by reference: the no-sale commitment, use of third-party subprocessors, cookie use including advertiser-sponsored Amp Free Mode, and user rights under privacy laws — each cross-referencing more detailed sections.

" We do not sell your information. ( read more ) We use a number of trusted third parties to help provide our products. ( read more ) We use cookies to provide, protect, and promote our own products and Amp Free Mode is advertiser-sponsor..."
📍 Privacy Policy › “Short version”Jump to exact text →
enterprise
Tier differences

Defines the scope and applicability of these AI Terms, specifying which AI Tools are covered, establishing the defined term 'AI Tools', and distinguishing the applicability of these terms versus the Sourcegraph Terms based on license type and date — a threshold condition creating a tier-based governance distinction.

" These terms apply to use of AI tools, including but not limited to Deep Search and Enterprise AI (formerly "Cody Enterprise", "Sourcegraph Cody", and "Cody"), hereinafter the "AI Tools", when added to an Enterprise License granted prior ..."
📍 “Last modified: January 22, 2026”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 22
Tier-specific - 3
Total citations - 52
Severity
Surface
Document
Tier
Privacy & data use
CautionHigh
" When we send you emails, we may employ clear gifs (also known as web beacons) in HTML-based emails sent to our users to track which emails are opened and which links are clicked by recipients. The information allows for more accurate reporting and improvement of the Services."
Privacy Policy › “Email beacons”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Section header for web analytics, introducing the category of third-party analytics data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
"We use information provided directly by you and third parties to operate, maintain, improve, and provide to you the features of the Services. We may use this information to communicate with you, such as to send you email messages, and to follow up with you to offer news and information about our Service"
Privacy Policy › “How does Sourcegraph use my information provided directly by me and third parties?”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

The 'improve' and communications purposes are broad and include unsolicited follow-up marketing, which may concern users who expect narrower use of their data.

AI-generated interpretation, not legal advice.

Indemnity & liability
CautionHigh
" Sourcegraph's AI Tools use context from your codebase to substantially improve the accuracy of its responses compared to other AI-based tools. However, Sourcegraph does not guarantee the accuracy of the AI Tools' answers. Outputs generated by the AI Tools are provided "as is" and without warranty of any kind. You are solely responsible for reviewing and validating any Outputs before use."
§ 8 (Accuracy)Jump to exact text →
Source: other- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Disclaims any guarantee of accuracy for AI Tool outputs, provides outputs on an 'as is' basis without warranty, and places sole responsibility on the customer to review and validate outputs before use — limiting Sourcegraph's liability for output quality and shifting validation responsibility to the customer.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
CautionHigh
" We may receive information about you from third-party services if you log in or otherwise interact with our Website or Services through a code host or social media, for example, by liking us on Facebook or following us on Twitter. The data we receive depends on your privacy settings with the third party but can include your name, email, third-party user ID, and location. Review, and if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to the Service."
Privacy Policy › “Information we receive from third parties”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Section header and directive instructing users to review and adjust their third-party privacy settings before linking services to Sourcegraph, establishing a user-facing procedural step related to data collection from third parties.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Google Analytics and Advertising . We may also utilize certain forms of display advertising and other advanced features through Google Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third-party cookies to inform, optimize, and display ads based on your past visits to the Sites."
Privacy Policy › “Third-party tracking and online advertising of Sourcegraph”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Use of Google Analytics Remarketing and Demographics & Interest Reporting involves passing user visit data to Google for profiling and retargeting. Under GDPR and similar regimes, this may require explicit consent and may conflict with data minimization principles.

AI-generated interpretation, not legal advice.

Data retention
NeutralHigh
"Sourcegraph will retain your information for as long as your account is active or as needed to perform our contractual obligations, provide you services, to comply with tax, legal, and audit obligations, resolve disputes, preserve legal rights, or enforce our agreements."
Privacy Policy › “How long does Sourcegraph retain my Personal Information?”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

The absence of a specific retention period and the breadth of retention justifications (disputes, legal rights, enforcement) mean personal data could be held for an extended and indeterminate period post-account closure, which may conflict with GDPR data minimization and storage limitation principles.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" If you have uncapped liability for breach of confidentiality or data security in your Agreement with Sourcegraph, a limit of liability of five times (5x) your annual license fees will apply to breaches of confidentiality or data security in connection with your use of Sourcegraph AI Tools. If you do not have uncapped liability in your Agreement with Sourcegraph, the limit of liability in your Agreement shall apply to your use of all features. For more information, see https://sourcegraph.com/docs/cody"
Source: other- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Imposes a liability cap of five times the annual license fees for breaches of confidentiality or data security in connection with AI Tool use where the customer otherwise has uncapped liability, and preserves the existing Agreement liability cap for customers without uncapped liability — establishing a tiered liability limitation specific to AI Tool-related confidentiality and security breaches.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"If you are a member of an Organization, we may share your username, email, IP address, and any collected logs about the user associated with that Organization with an owner or administrator of the Organization to investigate or respond to a security incident that affects or compromises the security of that particular Organization. "
Privacy Policy › “Security purposes”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Individual user data including IP addresses and logs can be disclosed to organizational administrators without individual user consent, which could expose users in adversarial employer/employee situations.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
"Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy."
Privacy Policy › “Global privacy practices”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

US-based data storage creates cross-border transfer implications for non-US users, particularly EEA, UK, and Swiss residents subject to GDPR-equivalent rules. The policy references SCCs as a transfer mechanism, which provides some mitigation.

AI-generated interpretation, not legal advice.

Training on your content
enterprise planCautionHigh
"Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
§ 3 (Model training)Jump to exact text →
Source: other- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

The no-training commitment is scoped to Sourcegraph Partner LLMs, not Sourcegraph's own models. The opt-in finetuning carveout means enabling certain product features could expose user data to model training. The terms and limits of that fine-tuning use are not specified here.

AI-generated interpretation, not legal advice.

Training on your content
enterprise planCautionHigh
" Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
§ 3 (Model training)Jump to exact text →
Source: other- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts Sourcegraph Partner LLMs from using Enterprise subscription code to train models, and creates a conditional permission allowing Sourcegraph to finetune a model using customer data only if the customer enables finetuning features — establishing both a training prohibition and a limited opt-in exception.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" When you use our Services, Sourcegraph automatically collects data about the Services and how they are used, including: Aggregated and high-level information about usage through a server ping. The server ping sends a payload containing data such as total number of users and whether certain features are enabled or in"
Privacy Policy › “Usage data”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Discloses that Sourcegraph automatically collects aggregated and high-level usage data including server pings with payload data such as total number of users and enabled features, establishing the scope and nature of automatic data collection obligations.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" We use information provided directly by you and third parties to operate, maintain, improve, and provide to you the features of the Services. We may use this information to communicate with you, such as to send you email messages, and to follow up with you to offer news and information about our Services. We may also send you Service-related emails or messages (e.g., account verification, change or updates to features of the Services, technical and security notices). For more information about your communication preferences, see Will Sourcegraph send me emails below."
Privacy Policy › “How does Sourcegraph use my information provided directly by me and third parties?”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Describes Sourcegraph's permitted and obligatory uses of collected personal data including operating/maintaining/improving services, communicating with users, and sending service-related and promotional emails, establishing the lawful basis and scope of data use.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy. For all website visitors and Services users, no matter their country of location, we will: provide clear methods of unambiguous, informed consent when we do collect your personal information; only collect the minimum amount of personal data necessary for the purpose it is collected for, unless you choose to provide us more; offer you simple methods of requesting access, correction, or deletion your information that we have collected, which we will make reasonable efforts to accommodate; and provide Service users notice, choice, accountability, security, and access, and we limit the purpose for processing. We also provide our users a method of recourse and enforcement. If you are located in the European Union, you are entitled to the following rights with regard to your personal information and data: Right of access to your personal data, to know what information about you we hold Right to correct any incorrect or incomplete personal data about yourself that we hold"
Privacy Policy › “Global privacy practices”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Enumerates data subject rights including the right to restrict or suspend processing of personal data, establishing a user entitlement to limit Sourcegraph's processing activities under applicable privacy law.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" When you visit our website or use our Services, we may send one or more cookies — a small text file containing a string of alphanumeric characters — to your computer that uniquely identifies your browser and lets us help you log in faster and enhance your navigation through the Services. A cookie may also convey information to us about how you use the Services (e.g., the pages you view, the links you click, how frequently you access the Services, and other actions you take on the Services), and allow us to track your usage of the Services over time. For more information, see "Third-party tracking and online advertising" below."
Privacy Policy › “Cookies”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Describes Sourcegraph's use of cookies to collect behavioral data including page views, link clicks, access frequency, and usage tracking over time, and cross-references a third-party tracking section, establishing data collection obligations and user tracking practices.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" When you visit or use our Services, we automatically collect information about your device, which may include the type of hardware and software you are using (for example, your operating system and browser type), IP address, and other unique identifiers for devices used to access our Website and Hosted Services."
Privacy Policy › “Device data”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Section header for location data, introducing the category of geographic data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" When you interact with our Services, we collect information that could be used to identify you ( "Personal Information" ). Examples include a username and password, an email address, a name, and an IP address. Some of the information we collect is stored in a manner that cannot be linked back to you ( "Non-Personal Information" ). Non-Personal Information includes aggregated, non-personally identifying information that does not identify a user or cannot otherwise be reasonably linked or connected with them."
Privacy Policy › “What information do we collect, and for what purpose”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Defines 'Personal Information' and 'Non-Personal Information' as operative terms used throughout the policy to determine which legal obligations and protections apply to collected data.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" We may also collect analytics data, or use third-party analytics tools, to help us measure traffic and usage trends for the Services. These tools collect information sent by your browser or mobile device, including the pages you visit, your use of third-party applications, and other information that assists us in analyzing and improving the Services. Although we do our best to honor the privacy preferences of our users, we are not able to respond to Do Not Track signals from your browser at this time."
Privacy Policy › “Web analytics”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Section header for Amp Free Mode keyword scanning, introducing the category of automated keyword-based data processing for advertising purposes.

AI-generated interpretation, not legal advice.

Common questions about Sourcegraph Cody's policies

Does Sourcegraph Cody train its AI models on your data?
No training on your content by default — based on 4 verified findings from Sourcegraph Cody's published policy. Informational only, not legal advice.
Who owns the content you create with Sourcegraph Cody?
You own your outputs — based on 1 verified finding from Sourcegraph Cody's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Sourcegraph Cody's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

20 verified clauses

Clauses in Sourcegraph Cody's policies that work in your favour — commitments the platform made to you.

  • Privacy & data use
    Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy. For all website visitor…

    Enumerates data subject rights including the right to restrict or suspend processing of personal data, establishing a user entitlement to limit Sourcegraph's processing activities under applicable privacy law.

    📍 Privacy Policy › “Global privacy practices”Jump to exact text →
  • Privacy & data usechildren's data
    Sourcegraph does not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to register as Users. If you are based in the European Union, we will not knowingly collect your information if you are under th…

    This segment restricts Sourcegraph from knowingly collecting personal information from children under 13 (or 16 in the EU), prohibits minors below the applicable consent age from registering, and establishes a remedial o…

    📍 Privacy Policy › “Children's privacy”Jump to exact text →
  • Model trainingdoes-not-train
    Sourcegraph collects the following Customer Content solely to provide the Service and not for product improvement purposes: Inputs (submitted queries) Outputs (completions generated) Candidate Context (Code, User Content, or other relevant information that…

    The scope of data use for customer content is limited to service provision. Segregation of usage data and user feedback from customer content is explicitly clarified. This is a user-favorable data use provision.

    📍 § 4 (Data collection and use)Jump to exact text →
  • Subprocessors & data sharing
    Sourcegraph has entered into partnerships with certain Large Language Models ("LLMs") ( "Sourcegraph Partner LLMs" ) to provide the services. Sourcegraph Partner LLMs will not retain any Input or Output from the model, including embeddings, beyond the time it…

    Imposes a Zero Retention obligation on Sourcegraph Partner LLMs, prohibiting them from retaining any Input, Output, or embeddings beyond the time required to generate the Output, while simultaneously carving out an excep…

    📍 § 2 (Sourcegraph Partner LLMs)Jump to exact text →
  • Privacy & data useproduct telemetry/usage tracking
    When you visit or use our Services, we may collect information related to accessing systems and data, including IP addresses, usernames, and data accessed. This information is only retained for the purposes of identifying, analyzing, and resolving potential…

    Section header for device data, introducing the category of device-related automatically collected information.

    📍 Privacy Policy › “Access, authorization, and activity audit logs”Jump to exact text →
  • Indemnity & liabilityindemnity direction
    Sourcegraph will indemnify you against any claims alleging that your use of AI Tools or any Outputs infringe third-party intellectual property rights in accordance with the indemnification terms in your agreement. Sourcegraph's indemnification obligation is…

    This is a platform-indemnifying-user clause, which is favorable to the user. The uncapped nature is contingent on using the latest version and filters, which creates a compliance obligation on the user side to maintain t…

    📍 § 5 (Full IP Indemnification)Jump to exact text →

+ 14 more verified clauses of this kind on this platform, cited in full in the report.

📋 Rules you must follow

1 verified clause

What Sourcegraph Cody requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

  • Moderation & enforcement
    You may not use Sourcegraph AI Tools for unlawful purposes or in violation of our Acceptable Use Policy .

    Prohibits use of Sourcegraph AI Tools for unlawful purposes or in violation of the Acceptable Use Policy, incorporating the AUP by reference as an enforceable restriction on permitted use.

    📍 § 7 (Acceptable use)Jump to exact text →

What the policies actually cover

10 topics
  • Product telemetry & usage tracking1 protective9 clauses
  • Advertising & tracking1 protective7 clauses
  • Sale or sharing of personal data2 protective2 clauses
  • Sensitive data (biometric, location, health)1 protective1 clause
  • Children's data1 protective1 clause
  • Government & law-enforcement disclosure1 clause
  • Does not train on your content4 protective4 clauses
  • Damages & liability cap2 clauses
  • Indemnity direction1 protective1 clause
  • Deletion rights & post-termination survival1 protective3 clauses

21 further verified clauses are cited on this page but not yet assigned a topic.

Cross-clause notes

Cross-referenceacross documents

Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “How long does Sourcegraph retain my Personal Information?” addresses how long content is retained, and the policy document, § 4 (Data collection and use) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

160
clauses
45
patterns
45
stances
privacy sharing · 26training use · 6data retention · 4ip ownership · 4tier conditionality · 3legal burden · 2
data retentionMEDIUMPrivacy Policy › “Data Storage, Security, and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we co...
Open source citation
data retentionMEDIUMPrivacy Policy › “Data Storage, Security, and Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we co...
Open source citation
data retentionLOWPrivacy Policy › “Your Rights”

The clause provides a deletion or time-bounded retention path.

You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as c...
Open source citation
data retentionLOWPrivacy Policy › “Your Rights”

The clause provides a deletion or time-bounded retention path.

You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as c...
Open source citation
ip ownershipLOW§ 1 (Ownership of AI Inputs and Outputs)

The clause affirms user ownership or retention of rights.

As between the parties, you own all Inputs to and Outputs generated by your use of Sourcegraph. You retain ownership of your code and responsibility for ensuring any code snippets emitted by Sourcegraph comply with software licenses and copyright law.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersindemnity liabilityconditionalMEDIUM2
All applicable tiersoutput ownershipimprovesLOW2
All applicable tiersprivacy data useworsensHIGH8
All applicable tiersprompt ownershipimprovesLOW2
All applicable tierssubprocessors data sharingconditionalMEDIUM6
All applicable tierstraining useworsensHIGH4
Enterprisedata retentionimprovesLOW2
Enterprisetier differencesconditionalMEDIUM2
Enterprisetraining useimprovesLOW2
Freeprivacy data useworsensHIGH2
Freesubprocessors data sharingconditionalMEDIUM2
Governmenttier differencesconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

worsenedhigh materialityJul 8Jul 10, 2026

model training worsened from low/no training claim to high/training permitted.

Before · low
Sourcegraph Partner LLMs will not retain any Input, Output, or Candidate Context beyond the time it takes to generate the Output ( "Zero Retention" ), except that Partner LLMs may temporarily retain Inputs and Outputs solely for the purpose of detecting and preventing abuse or serious harm, and will not use such data for model training or any other purpose, provided that you access AI Tools through Sourcegraph's Partner LLMs. This Zero Retention obligation does not restrict Sourcegraph from storing or persisting Inputs or Outputs to enable the functionality of the AI Tools. Sourcegraph may update this definition from time to time to reflect changes in Partner LLM retention practices by updating the 'last modified' date on this page.
Before citation
After · high
We use personal data to: Provide, operate, and maintain the Services , including enabling access, administering accounts, supporting features, and delivering functionality to our customers. Secure and protect the Services , including monitoring for misuse, detecting and investigating security incidents, maintaining audit logs, and enforcing our policies. Understand and improve how customers use the Services , including analyzing aggregated usage patterns, performance metrics, and reliability data to develop new features, improve existing functionality, and support product planning. Conduct research and analysis , including analyzing trends and publishing findings based on aggregated or de-identified data and deriving Inferences about how customers and users interact with our products and Services, including usage preferences, feature adoption patterns, and engagement trends, to improve our products and Services. Track Analytics , including tracking feature adoption and usage, understanding usage patterns across users and teams, and measuring engagement to improve the functionality of existing features and develop new products and features. Operate and improve our Website and marketing activities , including understanding Website usage, measuring engagement, and promoting the Services. Communicate with you , including responding to inquiries or form submissions, providing support and customer success services (which may include proactive outreach based on usage patterns to offer guidance, training, or assistance), sending service-related notices, and sharing information about updates or changes to the Services.
After citation
Jul 29, 2026model trainingHIGH

Latest stance: training permitted on training use

We use personal data to: Provide, operate, and maintain the Services , including enabling access, administering accounts, supporting features, and delivering functionality to our customers. Secure and protect the Services , including monitoring for misuse, detecting and investigating security incidents, maintaining audit logs, and enforcing our policies. Understand and improve how customers use the Services , including analyzing aggregated usage patterns, performance metrics, and reliability data to develop new features, improve existing functionality, and support product planning. Conduct research and analysis , including analyzing trends and publishing findings based on aggregated or de-identified data and deriving Inferences about how customers and users interact with our products and Services, including usage preferences, feature adoption patterns, and engagement trends, to improve our products and Services. Track Analytics , including tracking feature adoption and usage, understanding usage patterns across users and teams, and measuring engagement to improve the functionality of existing features and develop new products and features. Operate and improve our Website and marketing activities , including understanding Website usage, measuring engagement, and promoting the Services. Communicate with you , including responding to inquiries or form submissions, providing support and customer success services (which may include proactive outreach based on usage patterns to offer guidance, training, or assistance), sending service-related notices, and sharing information about updates or changes to the Services.
Open timeline citation
Jul 29, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we collect and process. For detailed information about our security practices, please refer to our Security Page . While we are committed to maintaining industry-standard or better security practices and continuously work to protect your data, no method of transmission over the Internet is completely secure. We cannot guarantee absolute security of your personal data. Your Security Responsibilities. You are responsible for maintaining the confidentiality of your Account Information and for any activity that occurs under your account. If you believe your account has been compromised, please contact us immediately at security@sourcegraph.com . Enterprise customers and their administrators are responsible for managing user access, permissions, and security configurations within their organizational workspace. Data Retention. We retain your personal data for as long as necessary to perform our contractual obligations and provide the Services to you and your organization. When personal data is no longer necessary for these purposes, we delete it in accordance with our data retention policies, though we may retain certain information necessary to attribute work product to and maintain the integrity of the organizational workspace.
Open timeline citation
Jul 29, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We may receive personal data from: Your Organization , such as Contact Information and Account Information necessary to provision and manage your access to the Services. Authentication and Identity Providers , such as Account Information when you use SSO or similar authentication mechanisms. Service Providers , such as Support Data, usage analytics, and performance metrics from providers who help us deliver and improve our Website and Services. Billing and Payment Providers , such as Billing and Payment Information for processing payments according to our customer agreements. Security and Fraud Prevention Providers , such as information about potential risks or threats to our Services. Sales and Marketing Service Providers , such as Contact Information and Marketing Information to identify prospective customers and understand market engagement. Third-Party Data Providers , such as professional and organizational information about users and contacts to better understand how our Services are used. Publicly Available Sources , such as Contact information and organizational information.
Open timeline citation
Jul 29, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on data retention

Professional or Employment Information : Job title, organizational affiliation, work contact information Inferences : Usage patterns and preferences derived from Usage Data, Marketing Data, or Analytics Data. Geolocation Data : Location Data derived from IP addresses and similar sources. We disclose these categories of personal information to our service providers. We retain each category of personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, tax, audit, and accounting obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed for these purposes, we delete or de-identify it in accordance with our standard data management practices.
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-06-09· verified 2026-06-09verified once — no re-scan in 94 days
  • Privacy Policy:Last captured 2026-07-29· verified 2026-07-29

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↓ 38 fewer findings this quarter vs last (62 vs 100). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Sourcegraph Cody's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Sourcegraph Cody's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Sourcegraph Cody's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.