GitHub Models
GDPR Compliance
Data Handling
GitHub publicly discloses AI inference/data hosting subprocessors with processing locations including the United States, Belgium, Germany, Iceland, and Singapore. GitHub Models documentation reviewed did not provide an EU-only residency option or customer-selectable EU-only inference routing guarantee.
GitHub's general privacy materials state personal data is retained while the account is active and as needed for contractual/legal purposes. GitHub's Terms of Service state that upon account cancellation, GitHub will delete the full profile and repository content within 90 days, though some information may remain in encrypted backups. No GitHub Models-specific retention period for prompts/completions was found in the primary sources reviewed.
For GitHub-hosted AI model serving, GitHub discloses model-provider commitments for some Copilot-hosted models, including zero data retention arrangements with certain providers and statements that prompts/responses are not used for model training. However, no primary GitHub Models-specific statement was found that globally and explicitly says all GitHub Models customer/API data is not used for training.
Certifications & EU AI Act
GitHub states it is committed to safe, secure, and trustworthy AI, follows Microsoft's Responsible AI Standard, aligns implementation with the NIST AI RMF, and has completed Responsible AI Impact Assessment plus security and privacy reviews. No explicit statement claiming EU AI Act compliance for GitHub Models was found.
Verification
- https://docs.github.com/en/github-models ↗
- https://docs.github.com/en/billing/concepts/product-billing/github-models ↗
- https://github.com/customer-terms ↗
- https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors ↗
- https://github.com/trust-center/privacy ↗
- https://docs.github.com/en/copilot/reference/ai-models/model-hosting ↗
- https://docs.github.com/en/enterprise-cloud@latest/admin/overview/accessing-compliance-reports-for-your-enterprise ↗
- https://github.com/trust-center ↗
- https://docs.github.com/en/site-policy/github-terms/github-terms-of-service ↗
- https://docs.github.com/fr/site-policy/privacy-policies/github-general-privacy-statement ↗
GitHub Models is documented as a metered GitHub service, but the most specific processor/privacy terms GitHub publishes are generally at the GitHub platform, Enterprise/Copilot, and subprocessor-list level rather than a dedicated GitHub Models DPA or residency page. Primary sources reviewed do not provide an EU-only inference guarantee, and the disclosed AI subprocessors include both EU and non-EU processing locations.
Models (2)
| Model | Modality | Context | Input | Output |
|---|---|---|---|---|
Microsoft: Phi 4 microsoft/phi-4 | text | 16K | $0.065 | $0.140 |
WizardLM-2 8x22B microsoft/wizardlm-2-8x22b | text | 66K | $0.620 | $0.620 |