NewsSecurityDeveloper Tools

GitHub Copilot September 28: Chat Data Is Now Permanent

GitHub Copilot data retention and billing changes September 28 2026

On September 28, GitHub flips three Copilot switches at once. One stores your chat history permanently. One removes refunds for unused seats. One quietly upgrades your code review to a more expensive mode without announcing a price change. You have 23 days to prepare.

Your Copilot Chat Is No Longer Deleted After 28 Days

This is the one most teams have missed. When GitHub merges Copilot Chat on github.com, Copilot Chat in GitHub Mobile, and the Copilot cloud agent into a single unified experience on September 28, it also merges their data policies. The cloud agent already retained session data for the life of your account. Now all surfaces inherit that rule.

Before September 28: github.com chat and mobile prompts delete after 28 days. After September 28: that data stays until the account is closed or you actively request deletion. GitHub’s official changelog is direct — “chat data, which used to have a 28-day retention limit, will now be kept for the lifetime of the account.”

For Business and Enterprise customers, GitHub does not use this data to train its public models — a Data Protection Agreement is available. For Free, Pro, and Pro+ users, interaction data feeds model training by default unless you opt out in Copilot settings.

The opt-out is a trap worth understanding: if your organization opts out of the unified experience entirely, you lose access to Copilot on github.com and GitHub Mobile. There is no path to keeping 28-day retention on the new unified surface. GitHub is not offering that choice.

What to do now: confirm whether your organization has an active Data Protection Agreement in place. If you have GDPR or contractual data retention obligations, assess them against the new lifetime retention policy before September 28. You can submit a data deletion request for existing chat history through GitHub’s privacy settings, but the burden is on you to do it.

Seats Go Prepaid. No Refunds.

Starting October 1, every Copilot Business and Enterprise seat assigned to a user is charged upfront at the start of the billing cycle. This is already live for new signups as of September 1. If you are an existing customer, you have until your next billing cycle on or after October 1 before the change applies.

The critical detail: revoking a seat mid-cycle does not trigger a prorated refund. The seat cost is gone. Only additions in the middle of a cycle remain prorated to the end of the period. GitHub’s billing documentation confirms: “Revoking a seat does not result in a prorated refund.”

This matters most for teams that have been loose with seat assignments — onboarding contractors temporarily, leaving trial seats active, or forgetting to offboard departing employees. Those seats become sunk costs once the new model takes effect.

Audit your Copilot seats now. In your GitHub organization admin settings, navigate to Copilot and review the seat management list. Every inactive or unrecognized seat you revoke before your next billing cycle saves you money.

Code Review Just Got More Expensive by Default

Copilot’s code review has two effort settings: Lite and Balanced. Lite is faster, lighter, and burns fewer AI credits and GitHub Actions minutes per pull request. Balanced reads more repository context, provides deeper analysis, and costs more per review.

Today, the default is Lite. On September 28, the default switches to Balanced. GitHub framed this as a feature change, not a price change — but for teams running code review on every pull request, it functions as one. The Balanced effort level went GA in August alongside the announcement that it would become the default.

If Balanced reviews are right for your team — deep feedback, complex codebases — the switch is probably welcome. If you have been happy with Lite, set it explicitly in repository or organization settings before September 28.

Three Actions Before September 28

  1. Review your data retention exposure. Confirm whether your organization has a GitHub Data Protection Agreement. If you have regulatory or contractual obligations, assess them against lifetime chat retention. Request deletion of existing chat history if needed.
  2. Audit and revoke unused seats. Run a full seat inventory now. Revoke anyone not actively using Copilot before your next billing cycle on or after October 1 — seats you keep after that date are paid in full with no refund.
  3. Pin your code review effort level. If you want Lite, change the setting at the repository or organization level before September 28. Letting the default flip means higher costs on every PR going forward.

The Bottom Line

GitHub is treating Copilot as enterprise software now, with enterprise billing and governance to match. That is the right direction. But three significant changes landing simultaneously on September 28 — with the data retention change buried in a billing announcement — deserved louder communication than they received. The opt-out-or-lose-browser-access tradeoff is a decision developers should have been told about more directly.

The deadline is September 28. The checklist is above. Run it now before the defaults flip.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News