Sourcegraph Cody
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product”
Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.
Watch: audit rights dpa residency
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
US-based data storage creates cross-border transfer implications for non-US users, particularly EEA, UK, and Swiss residents subject to GDPR-equivalent rules. The policy references SCCs as a transfer mechanism, which provides some mitigation.
The absence of a specific retention period and the breadth of retention justifications (disputes, legal rights, enforcement) mean personal data could be held for an extended and indeterminate period post-account closure, which may conflict with GDPR data minimization and storage limitation principles.
Imposes a liability cap of five times the annual license fees for breaches of confidentiality or data security in connection with AI Tool use where the customer otherwise has uncapped liability, and preserves the existing Agreement liability cap for customers without uncapped liability — establishing a tiered liability limitation specific to AI Tool-related confidentiality and security breaches.
Scores derived from 42 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Sourcegraph Cody's training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
- Your outputs and prompts are explicitly yours — Sourcegraph Cody's terms include affirmatively protective IP language.
- Data handling is conditional — 3 privacy or retention clauses warrant review before using Sourcegraph Cody at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Sourcegraph Cody's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 104 verified, verbatim-cited findings below — read the citations.
Based on 113 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Partially verified — Terms of Service — Capture pending; Privacy Policy — Verified (read in full, 34 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Held for review
A core policy document failed verification or contains contested evidence that must not be treated as fully verified.
- Terms of ServiceCapture pendingstatic-revalidated
- Privacy PolicyVerified - read in full - 34 citationsstaticLast captured 2026-07-29
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
The no-training commitment is scoped to Sourcegraph Partner LLMs, not Sourcegraph's own models. The opt-in finetuning carveout means enabling certain product features could expose user data to model training. The terms and limits of that fine-tuning use are not specified here.
"Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
Restricts Sourcegraph Partner LLMs from using Enterprise subscription code to train models, and creates a conditional permission allowing Sourcegraph to finetune a model using customer data only if the customer enables finetuning features — establishing both a training prohibition and a limited opt-in exception.
" Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
Defines the scope of the Privacy Policy, identifies the data controller ('Sourcegraph'), defines 'Services' and 'Customer Personal Data', and establishes that by using the Service the user agrees to the policy terms — creating a binding incorporation of obligations.
" See the changes since the previous version or visit our archives . At Sourcegraph, Inc. ( "Sourcegraph," "we," "our," or "us" ), we value your privacy. This Privacy Policy explains how we collect, use, share and protect your personal inf..."
Disclaims intentional collection of personal information in repositories and free-form inputs, while allocating responsibility for such data to the repository owner rather than Sourcegraph.
" We do not intentionally collect any Personal Information that is stored in your repositories or other free-form content inputs. Any Personal Information within a user's repository is the responsibility of the repository owner."
Continues and elaborates the Amp Free Mode advertising data sharing permission, specifying what information flows to Advertising Partners (aggregated only) and what happens when users click ads (data goes to partner directly), delineating Sourcegraph's sharing boundaries.
" Certain Sourcegraph products, specifically Amp Free Mode, are provided free of charge to users and are sponsored by Advertising Partners. Users of Amp Free Mode are shown ads that may be relevant to them, based on information gathered by..."
Summary section incorporating key obligations and rights by reference: the no-sale commitment, use of third-party subprocessors, cookie use including advertiser-sponsored Amp Free Mode, and user rights under privacy laws — each cross-referencing more detailed sections.
" We do not sell your information. ( read more ) We use a number of trusted third parties to help provide our products. ( read more ) We use cookies to provide, protect, and promote our own products and Amp Free Mode is advertiser-sponsor..."
Defines the scope and applicability of these AI Terms, specifying which AI Tools are covered, establishing the defined term 'AI Tools', and distinguishing the applicability of these terms versus the Sourcegraph Terms based on license type and date — a threshold condition creating a tier-based governance distinction.
" These terms apply to use of AI tools, including but not limited to Deep Search and Enterprise AI (formerly "Cody Enterprise", "Sourcegraph Cody", and "Cody"), hereinafter the "AI Tools", when added to an Enterprise License granted prior ..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" When we send you emails, we may employ clear gifs (also known as web beacons) in HTML-based emails sent to our users to track which emails are opened and which links are clicked by recipients. The information allows for more accurate reporting and improvement of the Services."
Section header for web analytics, introducing the category of third-party analytics data collection.
AI-generated interpretation, not legal advice.
"We use information provided directly by you and third parties to operate, maintain, improve, and provide to you the features of the Services. We may use this information to communicate with you, such as to send you email messages, and to follow up with you to offer news and information about our Service"
The 'improve' and communications purposes are broad and include unsolicited follow-up marketing, which may concern users who expect narrower use of their data.
AI-generated interpretation, not legal advice.
" Sourcegraph's AI Tools use context from your codebase to substantially improve the accuracy of its responses compared to other AI-based tools. However, Sourcegraph does not guarantee the accuracy of the AI Tools' answers. Outputs generated by the AI Tools are provided "as is" and without warranty of any kind. You are solely responsible for reviewing and validating any Outputs before use."
Disclaims any guarantee of accuracy for AI Tool outputs, provides outputs on an 'as is' basis without warranty, and places sole responsibility on the customer to review and validate outputs before use — limiting Sourcegraph's liability for output quality and shifting validation responsibility to the customer.
AI-generated interpretation, not legal advice.
" We may receive information about you from third-party services if you log in or otherwise interact with our Website or Services through a code host or social media, for example, by liking us on Facebook or following us on Twitter. The data we receive depends on your privacy settings with the third party but can include your name, email, third-party user ID, and location. Review, and if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to the Service."
Section header and directive instructing users to review and adjust their third-party privacy settings before linking services to Sourcegraph, establishing a user-facing procedural step related to data collection from third parties.
AI-generated interpretation, not legal advice.
"Google Analytics and Advertising . We may also utilize certain forms of display advertising and other advanced features through Google Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third-party cookies to inform, optimize, and display ads based on your past visits to the Sites."
Use of Google Analytics Remarketing and Demographics & Interest Reporting involves passing user visit data to Google for profiling and retargeting. Under GDPR and similar regimes, this may require explicit consent and may conflict with data minimization principles.
AI-generated interpretation, not legal advice.
"Sourcegraph will retain your information for as long as your account is active or as needed to perform our contractual obligations, provide you services, to comply with tax, legal, and audit obligations, resolve disputes, preserve legal rights, or enforce our agreements."
The absence of a specific retention period and the breadth of retention justifications (disputes, legal rights, enforcement) mean personal data could be held for an extended and indeterminate period post-account closure, which may conflict with GDPR data minimization and storage limitation principles.
AI-generated interpretation, not legal advice.
" If you have uncapped liability for breach of confidentiality or data security in your Agreement with Sourcegraph, a limit of liability of five times (5x) your annual license fees will apply to breaches of confidentiality or data security in connection with your use of Sourcegraph AI Tools. If you do not have uncapped liability in your Agreement with Sourcegraph, the limit of liability in your Agreement shall apply to your use of all features. For more information, see https://sourcegraph.com/docs/cody"Permalink to this finding →
Imposes a liability cap of five times the annual license fees for breaches of confidentiality or data security in connection with AI Tool use where the customer otherwise has uncapped liability, and preserves the existing Agreement liability cap for customers without uncapped liability — establishing a tiered liability limitation specific to AI Tool-related confidentiality and security breaches.
AI-generated interpretation, not legal advice.
"If you are a member of an Organization, we may share your username, email, IP address, and any collected logs about the user associated with that Organization with an owner or administrator of the Organization to investigate or respond to a security incident that affects or compromises the security of that particular Organization. "
Individual user data including IP addresses and logs can be disclosed to organizational administrators without individual user consent, which could expose users in adversarial employer/employee situations.
AI-generated interpretation, not legal advice.
"Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy."
US-based data storage creates cross-border transfer implications for non-US users, particularly EEA, UK, and Swiss residents subject to GDPR-equivalent rules. The policy references SCCs as a transfer mechanism, which provides some mitigation.
AI-generated interpretation, not legal advice.
"Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product"
The no-training commitment is scoped to Sourcegraph Partner LLMs, not Sourcegraph's own models. The opt-in finetuning carveout means enabling certain product features could expose user data to model training. The terms and limits of that fine-tuning use are not specified here.
AI-generated interpretation, not legal advice.
" Sourcegraph Partner LLMs do not use code from Enterprise subscriptions to train models. Sourcegraph may finetune a model using your data if you enable finetuning features within the product."
Restricts Sourcegraph Partner LLMs from using Enterprise subscription code to train models, and creates a conditional permission allowing Sourcegraph to finetune a model using customer data only if the customer enables finetuning features — establishing both a training prohibition and a limited opt-in exception.
AI-generated interpretation, not legal advice.
" When you use our Services, Sourcegraph automatically collects data about the Services and how they are used, including: Aggregated and high-level information about usage through a server ping. The server ping sends a payload containing data such as total number of users and whether certain features are enabled or in"
Discloses that Sourcegraph automatically collects aggregated and high-level usage data including server pings with payload data such as total number of users and enabled features, establishing the scope and nature of automatic data collection obligations.
AI-generated interpretation, not legal advice.
" We use information provided directly by you and third parties to operate, maintain, improve, and provide to you the features of the Services. We may use this information to communicate with you, such as to send you email messages, and to follow up with you to offer news and information about our Services. We may also send you Service-related emails or messages (e.g., account verification, change or updates to features of the Services, technical and security notices). For more information about your communication preferences, see Will Sourcegraph send me emails below."
Describes Sourcegraph's permitted and obligatory uses of collected personal data including operating/maintaining/improving services, communicating with users, and sending service-related and promotional emails, establishing the lawful basis and scope of data use.
AI-generated interpretation, not legal advice.
" Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy. For all website visitors and Services users, no matter their country of location, we will: provide clear methods of unambiguous, informed consent when we do collect your personal information; only collect the minimum amount of personal data necessary for the purpose it is collected for, unless you choose to provide us more; offer you simple methods of requesting access, correction, or deletion your information that we have collected, which we will make reasonable efforts to accommodate; and provide Service users notice, choice, accountability, security, and access, and we limit the purpose for processing. We also provide our users a method of recourse and enforcement. If you are located in the European Union, you are entitled to the following rights with regard to your personal information and data: Right of access to your personal data, to know what information about you we hold Right to correct any incorrect or incomplete personal data about yourself that we hold"
Enumerates data subject rights including the right to restrict or suspend processing of personal data, establishing a user entitlement to limit Sourcegraph's processing activities under applicable privacy law.
AI-generated interpretation, not legal advice.
" When you visit our website or use our Services, we may send one or more cookies — a small text file containing a string of alphanumeric characters — to your computer that uniquely identifies your browser and lets us help you log in faster and enhance your navigation through the Services. A cookie may also convey information to us about how you use the Services (e.g., the pages you view, the links you click, how frequently you access the Services, and other actions you take on the Services), and allow us to track your usage of the Services over time. For more information, see "Third-party tracking and online advertising" below."
Describes Sourcegraph's use of cookies to collect behavioral data including page views, link clicks, access frequency, and usage tracking over time, and cross-references a third-party tracking section, establishing data collection obligations and user tracking practices.
AI-generated interpretation, not legal advice.
" When you visit or use our Services, we automatically collect information about your device, which may include the type of hardware and software you are using (for example, your operating system and browser type), IP address, and other unique identifiers for devices used to access our Website and Hosted Services."
Section header for location data, introducing the category of geographic data collection.
AI-generated interpretation, not legal advice.
" When you interact with our Services, we collect information that could be used to identify you ( "Personal Information" ). Examples include a username and password, an email address, a name, and an IP address. Some of the information we collect is stored in a manner that cannot be linked back to you ( "Non-Personal Information" ). Non-Personal Information includes aggregated, non-personally identifying information that does not identify a user or cannot otherwise be reasonably linked or connected with them."
Defines 'Personal Information' and 'Non-Personal Information' as operative terms used throughout the policy to determine which legal obligations and protections apply to collected data.
AI-generated interpretation, not legal advice.
" We may also collect analytics data, or use third-party analytics tools, to help us measure traffic and usage trends for the Services. These tools collect information sent by your browser or mobile device, including the pages you visit, your use of third-party applications, and other information that assists us in analyzing and improving the Services. Although we do our best to honor the privacy preferences of our users, we are not able to respond to Do Not Track signals from your browser at this time."
Section header for Amp Free Mode keyword scanning, introducing the category of automated keyword-based data processing for advertising purposes.
AI-generated interpretation, not legal advice.
Common questions about Sourcegraph Cody's policies
- Does Sourcegraph Cody train its AI models on your data?
- No training on your content by default — based on 4 verified findings from Sourcegraph Cody's published policy. Informational only, not legal advice.
- Who owns the content you create with Sourcegraph Cody?
- You own your outputs — based on 1 verified finding from Sourcegraph Cody's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Sourcegraph Cody's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
20 verified clausesClauses in Sourcegraph Cody's policies that work in your favour — commitments the platform made to you.
- Privacy & data use
“Information we collect will be stored and processed in the United States in accordance with this Privacy Policy but we understand that users from other countries may have different expectations and rights with regard to their privacy. For all website visitor…”
Enumerates data subject rights including the right to restrict or suspend processing of personal data, establishing a user entitlement to limit Sourcegraph's processing activities under applicable privacy law.
📍 Privacy Policy › “Global privacy practices”Jump to exact text → - Privacy & data usechildren's data
“Sourcegraph does not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to register as Users. If you are based in the European Union, we will not knowingly collect your information if you are under th…”
This segment restricts Sourcegraph from knowingly collecting personal information from children under 13 (or 16 in the EU), prohibits minors below the applicable consent age from registering, and establishes a remedial o…
📍 Privacy Policy › “Children's privacy”Jump to exact text → - Model trainingdoes-not-train
“Sourcegraph collects the following Customer Content solely to provide the Service and not for product improvement purposes: Inputs (submitted queries) Outputs (completions generated) Candidate Context (Code, User Content, or other relevant information that…”
The scope of data use for customer content is limited to service provision. Segregation of usage data and user feedback from customer content is explicitly clarified. This is a user-favorable data use provision.
📍 § 4 (Data collection and use)Jump to exact text → - Subprocessors & data sharing
“Sourcegraph has entered into partnerships with certain Large Language Models ("LLMs") ( "Sourcegraph Partner LLMs" ) to provide the services. Sourcegraph Partner LLMs will not retain any Input or Output from the model, including embeddings, beyond the time it…”
Imposes a Zero Retention obligation on Sourcegraph Partner LLMs, prohibiting them from retaining any Input, Output, or embeddings beyond the time required to generate the Output, while simultaneously carving out an excep…
📍 § 2 (Sourcegraph Partner LLMs)Jump to exact text → - Privacy & data useproduct telemetry/usage tracking
“When you visit or use our Services, we may collect information related to accessing systems and data, including IP addresses, usernames, and data accessed. This information is only retained for the purposes of identifying, analyzing, and resolving potential…”
Section header for device data, introducing the category of device-related automatically collected information.
📍 Privacy Policy › “Access, authorization, and activity audit logs”Jump to exact text → - Indemnity & liabilityindemnity direction
“Sourcegraph will indemnify you against any claims alleging that your use of AI Tools or any Outputs infringe third-party intellectual property rights in accordance with the indemnification terms in your agreement. Sourcegraph's indemnification obligation is…”
This is a platform-indemnifying-user clause, which is favorable to the user. The uncapped nature is contingent on using the latest version and filters, which creates a compliance obligation on the user side to maintain t…
📍 § 5 (Full IP Indemnification)Jump to exact text →
+ 14 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
1 verified clauseWhat Sourcegraph Cody requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcement
“You may not use Sourcegraph AI Tools for unlawful purposes or in violation of our Acceptable Use Policy .”
Prohibits use of Sourcegraph AI Tools for unlawful purposes or in violation of the Acceptable Use Policy, incorporating the AUP by reference as an enforceable restriction on permitted use.
📍 § 7 (Acceptable use)Jump to exact text →
What the policies actually cover
10 topics- Product telemetry & usage tracking1 protective9 clauses
- Advertising & tracking1 protective7 clauses
- Sale or sharing of personal data2 protective2 clauses
- Sensitive data (biometric, location, health)1 protective1 clause
- Children's data1 protective1 clause
- Government & law-enforcement disclosure1 clause
- Does not train on your content4 protective4 clauses
- Damages & liability cap2 clauses
- Indemnity direction1 protective1 clause
- Deletion rights & post-termination survival1 protective3 clauses
21 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “How long does Sourcegraph retain my Personal Information?” addresses how long content is retained, and the policy document, § 4 (Data collection and use) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we co...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we co...”Open source citation
The clause provides a deletion or time-bounded retention path.
“You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as c...”Open source citation
The clause provides a deletion or time-bounded retention path.
“You have certain rights regarding your personal data, depending on where you live and applicable laws. Because our Services are provided to enterprise customers, your rights may be exercised individually or in coordination with your organization. These rights apply to personal data we process as a Data Controller as described in this Privacy Policy. If your personal data is contained within User Content (such as c...”Open source citation
The clause affirms user ownership or retention of rights.
“As between the parties, you own all Inputs to and Outputs generated by your use of Sourcegraph. You retain ownership of your code and responsibility for ensuring any code snippets emitted by Sourcegraph comply with software licenses and copyright law.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | indemnity liability | conditional | MEDIUM | 2 |
| All applicable tiers | output ownership | improves | LOW | 2 |
| All applicable tiers | privacy data use | worsens | HIGH | 8 |
| All applicable tiers | prompt ownership | improves | LOW | 2 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 6 |
| All applicable tiers | training use | worsens | HIGH | 4 |
| Enterprise | data retention | improves | LOW | 2 |
| Enterprise | tier differences | conditional | MEDIUM | 2 |
| Enterprise | training use | improves | LOW | 2 |
| Free | privacy data use | worsens | HIGH | 2 |
| Free | subprocessors data sharing | conditional | MEDIUM | 2 |
| Government | tier differences | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
model training worsened from low/no training claim to high/training permitted.
“Sourcegraph Partner LLMs will not retain any Input, Output, or Candidate Context beyond the time it takes to generate the Output ( "Zero Retention" ), except that Partner LLMs may temporarily retain Inputs and Outputs solely for the purpose of detecting and preventing abuse or serious harm, and will not use such data for model training or any other purpose, provided that you access AI Tools through Sourcegraph's Partner LLMs. This Zero Retention obligation does not restrict Sourcegraph from storing or persisting Inputs or Outputs to enable the functionality of the AI Tools. Sourcegraph may update this definition from time to time to reflect changes in Partner LLM retention practices by updating the 'last modified' date on this page.”Before citation
“We use personal data to: Provide, operate, and maintain the Services , including enabling access, administering accounts, supporting features, and delivering functionality to our customers. Secure and protect the Services , including monitoring for misuse, detecting and investigating security incidents, maintaining audit logs, and enforcing our policies. Understand and improve how customers use the Services , including analyzing aggregated usage patterns, performance metrics, and reliability data to develop new features, improve existing functionality, and support product planning. Conduct research and analysis , including analyzing trends and publishing findings based on aggregated or de-identified data and deriving Inferences about how customers and users interact with our products and Services, including usage preferences, feature adoption patterns, and engagement trends, to improve our products and Services. Track Analytics , including tracking feature adoption and usage, understanding usage patterns across users and teams, and measuring engagement to improve the functionality of existing features and develop new products and features. Operate and improve our Website and marketing activities , including understanding Website usage, measuring engagement, and promoting the Services. Communicate with you , including responding to inquiries or form submissions, providing support and customer success services (which may include proactive outreach based on usage patterns to offer guidance, training, or assistance), sending service-related notices, and sharing information about updates or changes to the Services.”After citation
Latest stance: training permitted on training use
“We use personal data to: Provide, operate, and maintain the Services , including enabling access, administering accounts, supporting features, and delivering functionality to our customers. Secure and protect the Services , including monitoring for misuse, detecting and investigating security incidents, maintaining audit logs, and enforcing our policies. Understand and improve how customers use the Services , including analyzing aggregated usage patterns, performance metrics, and reliability data to develop new features, improve existing functionality, and support product planning. Conduct research and analysis , including analyzing trends and publishing findings based on aggregated or de-identified data and deriving Inferences about how customers and users interact with our products and Services, including usage preferences, feature adoption patterns, and engagement trends, to improve our products and Services. Track Analytics , including tracking feature adoption and usage, understanding usage patterns across users and teams, and measuring engagement to improve the functionality of existing features and develop new products and features. Operate and improve our Website and marketing activities , including understanding Website usage, measuring engagement, and promoting the Services. Communicate with you , including responding to inquiries or form submissions, providing support and customer success services (which may include proactive outreach based on usage patterns to offer guidance, training, or assistance), sending service-related notices, and sharing information about updates or changes to the Services.”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“Data Storage. We store personal data on servers located in the United States. Data Security. We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards to protect the personal data we collect and process. For detailed information about our security practices, please refer to our Security Page . While we are committed to maintaining industry-standard or better security practices and continuously work to protect your data, no method of transmission over the Internet is completely secure. We cannot guarantee absolute security of your personal data. Your Security Responsibilities. You are responsible for maintaining the confidentiality of your Account Information and for any activity that occurs under your account. If you believe your account has been compromised, please contact us immediately at security@sourcegraph.com . Enterprise customers and their administrators are responsible for managing user access, permissions, and security configurations within their organizational workspace. Data Retention. We retain your personal data for as long as necessary to perform our contractual obligations and provide the Services to you and your organization. When personal data is no longer necessary for these purposes, we delete it in accordance with our data retention policies, though we may retain certain information necessary to attribute work product to and maintain the integrity of the organizational workspace.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We may receive personal data from: Your Organization , such as Contact Information and Account Information necessary to provision and manage your access to the Services. Authentication and Identity Providers , such as Account Information when you use SSO or similar authentication mechanisms. Service Providers , such as Support Data, usage analytics, and performance metrics from providers who help us deliver and improve our Website and Services. Billing and Payment Providers , such as Billing and Payment Information for processing payments according to our customer agreements. Security and Fraud Prevention Providers , such as information about potential risks or threats to our Services. Sales and Marketing Service Providers , such as Contact Information and Marketing Information to identify prospective customers and understand market engagement. Third-Party Data Providers , such as professional and organizational information about users and contacts to better understand how our Services are used. Publicly Available Sources , such as Contact information and organizational information.”Open timeline citation
Latest stance: third party or vendor sharing on data retention
“Professional or Employment Information : Job title, organizational affiliation, work contact information Inferences : Usage patterns and preferences derived from Usage Data, Marketing Data, or Analytics Data. Geolocation Data : Location Data derived from IP addresses and similar sources. We disclose these categories of personal information to our service providers. We retain each category of personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, tax, audit, and accounting obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed for these purposes, we delete or de-identify it in accordance with our standard data management practices.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-06-09· verified 2026-06-09verified once — no re-scan in 94 days
- Privacy Policy:Last captured 2026-07-29· verified 2026-07-29
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↓ 38 fewer findings this quarter vs last (62 vs 100). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Sourcegraph Cody's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Sourcegraph Cody's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Sourcegraph Cody's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.