Custom models: provide specific disclosure of data shared with third-party services #203487
Unanswered
DrOleson
asked this question in
Copilot Conversations
Replies: 1 comment
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Product Feedback
💬 Feature/Topic Area
Copilot Enterprise
Body
Summary
The current consent wording for enabling custom models in GitHub Copilot is too general for us to complete a meaningful privacy, security, and compliance review.
The wording indicates that "data" may be shared with third-party services, but it does not explain with sufficient specificity what data is shared, with whom, for what purpose, or under which processing conditions.
Problem
We need to understand the actual data flow before enabling a feature that may transmit source code, prompts, repository context, metadata, or other information to external services.
The current disclosure does not clearly specify:
A general authorization to share data with unspecified third-party services is difficult to assess and prevents us from approving the feature.
Requested improvement
Please provide a clear, provider-specific description of the data processing that occurs when custom models are enabled.
This could be included directly in the consent dialog or in clearly linked and versioned documentation. For each provider or configuration, the documentation should identify:
Scope
This is not limited to a particular IDE or Copilot interface. It concerns the disclosure presented when custom models are enabled and any Copilot experience that may send data to a third-party model provider.
Desired outcome
The goal is not to prevent necessary data processing. The goal is to provide enough transparency for us to understand, assess, and approve it.
More specific consent wording, supported by a provider-level data-flow or processing matrix, would make the feature significantly easier to adopt in enterprise environments.
All reactions