AI question hub/Security & safety
Reviewed, source-backed answer 7 min read English · original

How long does Microsoft Copilot retain uploaded files, and how can users control or delete them?

A product-specific privacy guide separating consumer and workplace Copilot, uploaded files, chat history, audit records, retention policies, and deletion controls.

Real question signalMicrosoft Q&A
How long does CoPilot save files for?
View the original question
Direct answer

There is no single retention period for everything called Microsoft Copilot. First identify your account and app version, then distinguish the uploaded file from the chat, saved memories, and any original file in OneDrive or SharePoint.

Microsoft’s older Copilot privacy FAQ gives an upload limit of 18 months, but it now explicitly applies only to the older app. Microsoft has separate guidance for the updated app introduced on August 18, 2026. Do not carry an older 30-day or 18-month statement across products or versions. Older-app FAQ Updated-app guidance

Delete unneeded conversations through the controls for your version, check saved memories separately, and manage any source file in its own storage location. For work or school accounts, ask your administrator about OneDrive and Microsoft Purview retention: deleting a visible chat may leave a required compliance copy. Work and school retention

[2][3][4][5]

Identify the account and the stored item

Check the account shown in the app. A personal Microsoft account, a work or school Microsoft Entra account, and Copilot inside Microsoft 365 apps can have different terms.

Then identify what you want removed:

Item Where to check
Conversation Copilot chat history and account activity controls
Saved memory Copilot personalization settings
Uploaded or existing document The app’s file controls and the original storage location
Work compliance copy Your administrator’s retention and hold policies
Audit record The organization’s audit settings

Deleting one item does not establish that every related copy has been removed.

Find the applicable retention rule

  1. Identify whether the account is personal or managed by an organization.
  2. For a personal account, use documentation for the app version you actually use, including whether you are inside a Microsoft 365 app.
  3. Locate the file and its related conversation. Check whether Copilot also saved information as a memory.
  4. Use the relevant deletion controls. At work, follow the organization’s retention and incident procedures.
  5. If you need confirmation of permanent deletion, request it from the provider or administrator; the chat interface alone cannot establish it.

Personal accounts: match the guidance to your app version

The original question arose from pages quoting different periods. On September 5, 2026, Microsoft’s documentation distinguishes an older app from an updated app released on August 18. The old FAQ’s 18-month upload statement is therefore version-specific. It also describes training choices for that older experience; a blanket claim that all consumer uploads are excluded from training would be misleading. Older-app FAQ

For the updated app, start with Microsoft’s current privacy overview and the linked controls. The pages checked here do not establish a universal expiry for every kind of upload. If a file is sensitive and you need a definite retention commitment, obtain the terms applicable to that feature before uploading it. Current privacy overview

The updated controls let you delete individual chats and manage saved memories. Turning memory off does not itself delete existing memories. Review both when removing personal information. Current privacy controls

Work and school Copilot: files, chats, and compliance are separate

With a work or school account, Microsoft Copilot Chat has enterprise data protection. Microsoft says that an uploaded file is stored in the user’s OneDrive for Business. It also says that the full uploaded file is not sent as a generated web-search query. Microsoft Copilot Chat privacy and protections

Consumer retention periods do not determine the lifetime of a work or school upload. Its lifecycle follows the organization’s OneDrive and Purview configuration. Microsoft’s Copilot data-protection architecture specifically lists user-uploaded files in OneDrive Copilot Chat folders and says retention and deletion follow configured Microsoft Purview policies. Microsoft Copilot data-protection architecture

Prompts and responses are another layer. Microsoft stores Copilot interaction data in Microsoft 365 services. Purview can discover, audit, and retain it, and its retention guidance describes messages copied to hidden folders in the user’s Exchange Online mailbox for compliance search. Microsoft 365 Copilot privacy Retention for Copilot and AI apps

What a user can delete at work or school

Users can delete a specific conversation from the Copilot Chat history, where that option is available. They can also send a request to delete their Copilot activity history from My Account > Data and Privacy > Data options > Copilot activity history. Microsoft says this covers prompts and responses across the listed Microsoft 365 apps and Copilot Chat, but it does not remove content that Copilot helped create and that was saved into a file. Delete Microsoft Copilot activity history Copilot Chat history

For an uploaded work file, delete the file from the relevant OneDrive location as well. If it is an existing SharePoint or OneDrive document that Copilot merely summarized, deleting the Copilot chat does not delete the original document. Delete or manage that original through the normal SharePoint or OneDrive workflow, within your permissions.

Why deletion is not always immediate or absolute in an organization

An administrator can set Purview retention policies for Microsoft Copilot experiences, OneDrive, SharePoint, and other locations. In the Copilot retention path, expired or deleted interaction items move to a hidden SubstrateHolds folder for at least one day; the timer job typically makes the permanent deletion on a later run within one to seven days. A litigation hold, eDiscovery hold, delay hold, or another applicable retention policy suspends permanent deletion. Retention for Copilot and AI apps

For OneDrive and SharePoint files, a retention policy or label can preserve the original in a hidden Preservation Hold library when a user changes or deletes it. That preserved content is not meant to be edited or removed by an end user. Retention for SharePoint and OneDrive

This is intentional compliance behavior. A chat disappearing from the user interface is not proof that all searchable or retained copies have been permanently deleted. Microsoft explicitly warns that app-visible messages are not an accurate way to verify compliance retention and permanent deletion. Retention for Copilot and AI apps

Examples of what deletion affects

The action you need depends on where the information is stored.

Situation What to manage What chat deletion does not establish
Personal document upload Conversation, saved memory, and attachment controls for your app version That an old expiry statement applies or every copy is gone
Work upload into Copilot Chat Chat and the file in OneDrive for Business That organizational retention or holds no longer apply
Existing SharePoint document The original document in SharePoint That deleting the conversation deletes the source file

For work uploads, see Copilot Chat protection. Source documents can also be affected by SharePoint and OneDrive retention policies.

Audit logs are not the same as the file or chat

Organizations can also have Copilot-related audit records. Microsoft says Copilot and AI-application audit records can include the user, time, location, and references to files, sites, or other resources accessed to make a response. Audit logs for Copilot and AI applications

Under Audit (Standard), Microsoft retains audit records for 180 days by default. Audit (Premium), licensing, and a custom audit-retention policy can change that duration, including longer periods for eligible users. It follows that 180 days is a common audit default, not a promise that all Copilot data is removed at 180 days. Manage audit-log retention policies

Do not confuse an audit record that a file was accessed with the file’s contents, the chat’s prompts and responses, or the original OneDrive/SharePoint document. They are different data classes and may have different retention rules.

What to do now

For a personal account, open the chat’s menu and use Delete. For broader history removal, follow the account’s activity-history instructions. Review saved memories separately under personalization, and check attachment controls for the feature used. Current controls Activity-history management

For work or school use, manage the chat and source file separately within your permissions. If you uploaded restricted material, contact the administrator or security team so they can assess all affected locations and any preservation obligations.

Administrators should document retention for Copilot interactions, OneDrive, SharePoint, and audit records separately, then test deletion with non-sensitive data. Verify compliance retention through the administrative tools. Purview guidance

Limits of this answer

The consumer version distinction and current privacy controls were checked on September 5, 2026. This is not confirmation of an individual account’s backend deletion or a review of every contractual retention term. For a regulated use, rely on the applicable contract and the organization’s approved configuration.

Evidence

Sources used for this answer.

Question signals show what people need. Primary documentation supports the answer. Both remain visible.

  1. 01
    How long does CoPilot save files for?Microsoft Q&A · question signal · checked 25 Aug 2026
  2. 02
    Consumer privacy pagemicrosoft.com · primary evidence · checked 25 Aug 2026
  3. 03
    Older-app FAQsupport.microsoft.com · primary evidence · checked 25 Aug 2026
  4. 04
    Microsoft Edge privacy documentationlearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  5. 05
    Activity-history managementsupport.microsoft.com · primary evidence · checked 25 Aug 2026
  6. 06
    Microsoft Copilot Chat privacy and protectionslearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  7. 07
    Microsoft Copilot data-protection architecturelearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  8. 08
    Microsoft 365 Copilot privacylearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  9. 09
    Work and school retentionlearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  10. 10
    Delete Microsoft Copilot activity historysupport.microsoft.com · primary evidence · checked 25 Aug 2026
  11. 11
    Copilot Chat historysupport.microsoft.com · primary evidence · checked 25 Aug 2026
  12. 12
    Retention for SharePoint and OneDrivelearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  13. 13
    Audit logs for Copilot and AI applicationslearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  14. 14
    Manage audit-log retention policieslearn.microsoft.com · implementation guidance · checked 25 Aug 2026
  15. 15
    Updated-app guidancesupport.microsoft.com · primary evidence · checked 5 Sept 2026
  16. 16
    Current privacy controlssupport.microsoft.com · primary evidence · checked 5 Sept 2026