> The GitHub Copilot collects activity from the user’s Visual Studio Code editor, tied to a timestamp, and metadata.
[...]
> This data will only be used by GitHub for:
[...]
> - Improving the underlying code generation models, e.g. by providing positive and negative examples (but always so that your private code is not used as input to suggest code for other users of GitHub Copilot)
I'm inclined to believe this. After all, why would they taint the training data with code from a random guy who is asking for help when they have more than a hundred thousand repos with 100+ stars?
[0] [https://docs.github.com/en/github/copilot/about-github-copil...]
I've had previous employers that were highly concerned about far more innocuous data leaking to competitors, e.g. autocomplete search terms. This means that a Copilot installation at any company that competes (or might compete) with MS should be considered a security breach, IMO. Given Microsoft's presence in so many markets, in general I think it would be foolish to risk this at any company.