Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Practical Guides

Copilot Chats May Persist for Your Account’s Lifetime—Audit the Policy Now

|Author: QUASA Editorial Team|6 min read| 10
Copilot Chats May Persist for Your Account’s Lifetime—Audit the Policy Now

GitHub set out three forthcoming Copilot changes on August 28, 2026: a unified experience planned no earlier than September 28, account-lifetime retention for affected github.com chats, and separate billing changes from October 1 for certain Business and Enterprise customers. The August 28 Copilot notice also confirms that the unified policy will be enabled by default after launch.

Administrators need to treat the rollout as several control decisions, not one product update. A recent ReleaseBytes summary independently describes the September 28 policy boundary and October 1 billing change, but retention, access, code-review defaults and seat costs require separate evidence and owners.

One rollout creates distinct governance decisions

The first decision is whether retaining affected chat data for the life of the account complies with the organization’s privacy and records-management requirements. The second is whether users must keep Copilot access on github.com and GitHub Mobile, because opting out of the unified experience will remove access on those surfaces after launch.

A third decision applies to Copilot code review. Starting September 28, the Default review-effort value is scheduled to resolve to Balanced for existing and new repositories and organizations using the feature. Administrators that intend to retain Lite must select Lite explicitly at the organization or repository level before that date.

Billing is a fourth control area, limited to the affected payment arrangements and account types. Approval of the new payment treatment does not establish that longer chat retention is acceptable; similarly, leaving the unified policy enabled does not prove that assigned seats have been reconciled.

Account-lifetime retention replaces the 28-day baseline

GitHub Copilot chat records assessed for account-lifetime retention in a dated policy audit.

The retention change is tied to Copilot on github.com moving to the agent-sessions experience previously used by the Copilot cloud agent. Once the unified experience launches, affected chat data will be retained for the life of the account instead of the current 28-day period.

This changes the retention duration that administrators must record in a data-governance assessment. The published change does not provide a configurable shorter retention period, explain how existing conversations will migrate, or detail whether individual agent sessions will receive separate deletion controls.

Remaining opted in requires no setting change because the unified experience will be enabled by default after launch. Opting out has a direct operational consequence: affected users or teams will lose Copilot access on github.com and GitHub Mobile rather than keeping those surfaces under the former retention arrangement.

Seat billing follows a different clock

Assigned GitHub Copilot seats reconciled with upfront billing and a pending authorization hold.

The October change is not a new Copilot Business or Enterprise list price. For existing customers on those plans that pay by credit card or PayPal, all assigned seats will incur an upfront charge at the start of the next billing cycle, with the updated treatment beginning October 1.

Current Copilot billing-cycle documentation calculates charges from seats assigned during the billing cycle and notes that a temporary advance authorization hold may appear as a pending charge for usage-based costs. Finance teams should distinguish such a hold from a settled seat charge when reconciling the payment method.

Under the forthcoming rules for affected customers, new Business or Enterprise seat assignments require payment before users receive access. Seats added during a billing cycle remain prorated from assignment through the cycle’s end, while revoking a seat does not produce a prorated refund; the removal is reflected in the next monthly cycle.

The cost control is therefore based on assignment records, not evidence that a person actively used Copilot. Administrators should reconcile the seat inventory against joiner, mover and leaver records and identify which entity owns the applicable payment method.

The dated control matrix

  • September 1, 2026: reenabling begins for new Copilot Business and Enterprise sign-ups paid by credit card or PayPal, alongside stronger account vetting and payment before access for new seat assignments.
  • Before September 28, 2026: business and enterprise administrators should record their intended unified-policy value. Repositories or organizations that must retain Lite for code review should replace Default with an explicit Lite selection.
  • No earlier than September 28, 2026: the unified Copilot experience may launch, become enabled by default and introduce account-lifetime retention for affected github.com chat data.
  • After the unified launch: opting out removes Copilot access on github.com and GitHub Mobile for affected users or teams.
  • From October 1, 2026: the updated billing treatment begins for existing Business and Enterprise customers paying by credit card or PayPal, with assigned seats charged upfront at the start of the next billing cycle.

“No earlier than September 28” is an audit deadline and earliest launch boundary, not a guarantee that the experience will launch on that day. The control record should distinguish that published boundary from the date the organization observes the new policy in its own settings.

What the pre-rollout audit should capture

A dated GitHub Copilot audit records retention, access, review settings and seat-billing decisions.
  1. List each enterprise and organization in scope, its responsible administrator and the current Copilot policy state.
  2. Record the unified-policy value once the Copilot cloud-agent option appears in settings, including the account scope and observation time.
  3. Document whether privacy, security, legal and records-management owners accept account-lifetime retention for affected github.com chats.
  4. Identify teams that require Copilot on github.com or GitHub Mobile and record the access loss that opting out would cause.
  5. Inventory organization- and repository-level code-review effort settings, flag every Default value and document whether Balanced or explicit Lite is intended.
  6. Reconcile assigned Business and Enterprise seats paid by credit card or PayPal before the billing cycle beginning on or after October 1.
  7. Record the finance owner, applicable spend controls and the method for distinguishing authorization holds from settled charges.
  8. Log unresolved questions about existing conversations, session deletion and account closure rather than treating assumptions as approved policy.

Each audit entry should identify the account and setting scope, observed value, timestamp, approving owner and accepted consequence. A screenshot without scope or time may not establish which organization or policy state was reviewed.

The unified experience remains a planned change, with September 28 as the earliest stated launch date. The next material evidence will be the new policy option in account settings, the actual launch timing and any additional documentation explaining migration or deletion of retained conversations.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0