← Back to all vendors
dev tools

GitHub

github.com

7 flagged clauses across 5 risk dimensions

C
⏱️
0min

to read this ToS

GitHub's fine print is longer than you think.

🎧Longer than your Spotify Wrapped β€” for ALL of last year.

Caffeine required:
β˜•β˜•

The 5 things you actually need to know

  • 1

    They can use your public code to train AI models, but not private code unless you enable specific features.

  • 2

    You own your code, but grant them broad rights to host, display, and even archive it (forever).

  • 3

    If you leave, they'll delete your stuff within 90 days, but anything others forked or contributed to is gone.

  • 4

    They can change these terms with 30 days notice, and if you don't like it, tough luck, keep using it and you agree.

  • 5

    They won't pay you for your code if they use it, and they're not liable for most damages from using the app.

Generated by AI from the actual contract β€” but for the lawyer-level breakdown, scroll down πŸ‘‡

πŸ€–

AI training

1 flag
  • Severity 4
    "By using automated means to access, collect, or otherwise use (β€œAccess”) any publicly accessible Content from the Service for the purpose of developing or training any commercially available artificial intelligence model, machine learning system, or similar technology (a "Commercial AI System"), you hereby waive any and all policies, terms, conditions, or contractual provisions governing products, services, websites or datasets you own or operate that would otherwise prohibit, restrict, or place conditions upon GitHub's Access to any publicly accessible data, information or content associated with your products or services, including for the purpose of developing or training any Commercial AI System."

    GitHub accesses publicly available content from your services to develop or train its Commercial AI Systems, and you waive any terms that would otherwise prohibit this.

    Your own terms of service are overridden, allowing GitHub to use your public data for AI training without restriction.

πŸ”„

Auto-renewal

clear

No flags in this category.

πŸ’Έ

Price hikes

clear

No flags in this category.

🌍

Data residency

clear

No flags in this category.

πŸšͺ

Termination friction

1 flag
  • Severity 2
    "GitHub has the right to suspend or terminate your access to all or any part of the Website at any time, with or without cause, with or without notice, effective immediately."

    GitHub can suspend or terminate your access to the service at any time, for any reason, with or without notice.

    Your access to the service can be revoked immediately and without explanation.

βš–οΈ

Liability caps

1 flag
  • Severity 4
    "You understand and agree that we will not be liable to you or any third party for any loss of profits, use, goodwill, or data, or for any incidental, indirect, special, consequential or exemplary damages, however arising, that result from the use, disclosure, or display of your User-Generated Content; your use or inability to use the Service; any modification, price change, suspension or discontinuance of the Service; the Service generally or the software or systems that make the Service available; unauthorized access to or alterations of your transmissions or data; statements or conduct of any third party on the Service; any other user interactions that you input or receive through your use of the Service; or any other matter relating to the Service."

    GitHub is not liable for any losses or damages arising from your use of the service, including lost profits, data, or goodwill, or from any modification, suspension, or discontinuance of the service.

    You cannot hold GitHub responsible for any financial or operational harm you experience due to their service.

πŸ›‘

Indemnification

1 flag
  • Severity 3
    "You agree to indemnify us, defend us, and hold us harmless from and against any and all claims, liabilities, and expenses, including attorneys’ fees, arising out of your use of the Website and the Service, including but not limited to your violation of this Agreement, provided that GitHub (1) promptly gives you written notice of the claim, demand, suit or proceeding; (2) gives you sole control of the defense and settlement of the claim, demand, suit or proceeding (provided that you may not settle any claim, demand, suit or proceeding unless the settlement unconditionally releases GitHub of all liability); and (3) provides to you all reasonable assistance, at your expense."

    You agree to defend and hold GitHub harmless from any claims arising from your use of the service or violation of the agreement.

    You must cover GitHub's legal costs and damages if your actions lead to a lawsuit against them.

πŸ‘»

Silent term changes

3 flags
  • Severity 3
    "We will notify our Users of material changes to this Agreement, such as price increases, at least 30 days prior to the change taking effect by posting a notice on our Website or sending email to the primary email address specified in your GitHub account."

    GitHub will inform users about significant changes, like price increases, at least 30 days before they happen by posting a notice or sending an email.

    You will receive advance notice of major changes, giving you time to decide if you want to continue using the service.

  • Severity 3
    "Customer's continued use of the Service after those 30 days constitutes agreement to those revisions of this Agreement."

    If you continue to use the service after 30 days, you agree to the revised terms.

    Your continued use of the service after the notice period implies your acceptance of any new terms.

  • Severity 3
    "We reserve the right, at our sole discretion, to amend these Terms of Service at any time and will update these Terms of Service in the event of any such amendments."

    GitHub reserves the right to change the Terms of Service at its discretion and will update them when changes occur.

    GitHub can unilaterally change the rules governing your use of their service at any time.

Better alternatives

Higher-rated vendors in developer tooling that may be safer than GitHub.

Recent changes detected

Feb 28, 2024

GitHub Copilot Business reversed its explicit no-training promise and began defaulting to opt-in code collection for AI training. Organizations must now actively find and disable a settings toggle to prevent their proprietary code from entering training pipelines.

Enterprises using Copilot Business under the assumption their code wasn't being harvested β€” especially those with export-controlled, regulated, or trade-secret-protected codebases.