There is no single Microsoft Copilot file-retention period . The answer depends on whether this is personal Copilot, Copilot used with a work or school account, and whether the item is an upload, an existing OneDrive or SharePoint file, a chat message, or an audit/compliance record. For a file uploaded to consumer Copilot, Microsoft currently publishes two incompatible official statements : its consumer privacy page says the file is stored for up to 30 days , while its Microsoft Support privacy FAQ says up to 18 months . Both also say a conversation about the file is handled as conversation history, separately from the file itself. Consumer privacy page, 30 days Microsoft Support FAQ, 18 months So the safe, practical answer for a personal account is: do not rely on an automatic expiry date for sensitive material . Delete the chat or activity history when you no longer need it, and treat the published 18-month period as a possible retention window until Microsoft reconciles its public documentation. The 30-day statement is about the file , not the chat. On the same consumer privacy page, Microsoft says conversation history is stored by default for 18 months and can be deleted. Microsoft consumer privacy page For a work or school account , do not apply either consumer number. Microsoft says Copilot Chat uploads are stored in the user's OneDrive for Business, while prompts and responses are logged in Microsoft 365 and can be retained, deleted, searched, or held under the organization’s Microsoft Purview policies. A user can request deletion of Copilot activity history, but an administrator’s retention policy, litigation hold, or eDiscovery hold can keep a compliance copy. Microsoft Copilot Chat privacy and protections Retention for Copilot and AI apps
[2][3][4][5]First identify which Copilot and which copy you mean
“How long is my file saved?” can refer to four different things. Deleting one does not necessarily delete the others.
| What you may mean | Typical location | What determines retention | Who can control it |
|---|---|---|---|
| A file uploaded into consumer Copilot | Copilot upload service | Microsoft’s consumer product rules, which currently conflict between 30 days and 18 months | The account holder can delete the associated conversation or activity history |
| The consumer conversation about that file | Copilot conversation history | Consumer account settings and product rules | The account holder can delete one conversation or all activity history |
| A file uploaded to Microsoft Copilot Chat with a work or school account | User’s OneDrive for Business | OneDrive and Microsoft Purview retention settings | User, site owner, and administrator, subject to policy or hold |
| A document already in OneDrive or SharePoint that Copilot reads or cites | Its existing OneDrive or SharePoint location | The file’s ordinary storage, recycle bin, retention label/policy, and any hold | User or owner within permissions, then the administrator’s governance rules |
| Prompts and responses, plus compliance or audit data | Exchange Online hidden folders, Purview, and audit logs | Purview retention, eDiscovery holds, license, and audit settings | Administrators and compliance teams |
The table is the reason a single number is misleading. A 30- or 18-month statement about a consumer upload cannot tell you how long an employer retains a OneDrive file or a compliance copy of a Copilot prompt.
Decision tree: find the right retention rule
flowchart TD
A[Did you use a personal Microsoft account?] -->|Yes| B[Did you upload a new file directly to consumer Copilot?]
B -->|Yes| C[Official consumer pages conflict: up to 30 days vs up to 18 months]
B -->|No, it was chat history or browser context| D[Manage or delete consumer Copilot history]
A -->|No, work or school account| E[Was a new file uploaded to Copilot Chat?]
E -->|Yes| F[File is in OneDrive for Business]
E -->|No, existing OneDrive or SharePoint file| G[Original file keeps its own location and lifecycle]
F --> H[Check OneDrive and Purview retention or eDiscovery]
G --> H
H --> I[Delete may be blocked or a compliance copy may remain]
This compact flowchart is the useful visual aid here because the main risk is choosing the wrong product or storage layer, not understanding a complex technical architecture.
Personal Copilot: the current 30-day and 18-month conflict
Microsoft’s consumer privacy page says that a document shared with Copilot is stored securely for up to 30 days and then automatically deleted. It also says that conversations about the file are treated as ordinary conversations. Consumer privacy page
Microsoft Support’s privacy FAQ, however, says that a shared image or document is stored securely for up to 18 months and then automatically deleted. It likewise says the file and related conversation are treated like other conversations and can be deleted. Microsoft Support privacy FAQ
These are not merely two ways of expressing the same period. They conflict. Microsoft has not published an official mapping that says which consumer users, platforms, account types, upload paths, or rollout versions receive each period. A publication-ready answer should therefore not pretend that the shorter period supersedes the longer one.
What is clear for consumer accounts
- Microsoft’s consumer page says conversations are saved by default for 18 months, and you can delete individual conversations or all history. Consumer privacy page
- An older, product-wide Edge privacy page says conversation history for Copilot in Bing, Edge, or copilot.microsoft.com is stored until the user chooses to delete it. That creates a second reason not to infer a universal chat expiry from the 18-month statement. Microsoft Edge privacy documentation
- Microsoft says it does not train Copilot generative models on uploaded files, regardless of the consumer privacy setting. Consumer privacy page
- That is not the same as saying the material is never processed, logged, reviewed for safety, or retained. The consumer FAQ says some conversations can be subject to automated and human review for product improvement and digital safety, and suspected Code of Conduct violations can be reviewed. Microsoft Support privacy FAQ
A safe rule for a personal document
If you uploaded, for example, a bank statement to ask Copilot to explain a charge, treat the upload as retained until you remove the associated activity and do not depend on the automatic 30-day expiry. Delete the individual conversation in Copilot, then use the Privacy Dashboard to delete all Copilot app activity if you need broader removal. The dashboard can also export the activity history first so you can confirm what you are about to remove. Manage Copilot activity history in the Privacy Dashboard
This is a privacy precaution, not evidence that every uploaded file remains for 18 months. The point is that Microsoft’s published terms are inconsistent, and deletion is the available control rather than waiting for an undocumented reconciliation.
Work and school Copilot: files, chats, and compliance are separate
With a work or school account, Microsoft Copilot Chat has enterprise data protection. Microsoft says that an uploaded file is stored in the user’s OneDrive for Business. It also says that the full uploaded file is not sent as a generated web-search query. Microsoft Copilot Chat privacy and protections
That means the upload is not governed by the consumer 30- or 18-month statements. Its lifecycle follows the organization’s OneDrive and Purview configuration. Microsoft’s Copilot data-protection architecture specifically lists user-uploaded files in OneDrive Copilot Chat folders and says retention and deletion follow configured Microsoft Purview policies. Microsoft Copilot data-protection architecture
Prompts and responses are another layer. Microsoft stores Copilot interaction data in Microsoft 365 services. Purview can discover, audit, and retain it, and its retention guidance describes messages copied to hidden folders in the user’s Exchange Online mailbox for compliance search. Microsoft 365 Copilot privacy Retention for Copilot and AI apps
What a user can delete at work or school
Users can delete a specific conversation from the Copilot Chat history, where that option is available. They can also send a request to delete their Copilot activity history from My Account > Data and Privacy > Data options > Copilot activity history. Microsoft says this covers prompts and responses across the listed Microsoft 365 apps and Copilot Chat, but it does not remove content that Copilot helped create and that was saved into a file. Delete Microsoft Copilot activity history Copilot Chat history
For an uploaded work file, delete the file from the relevant OneDrive location as well. If it is an existing SharePoint or OneDrive document that Copilot merely summarized, deleting the Copilot chat does not delete the original document. Delete or manage that original through the normal SharePoint or OneDrive workflow, within your permissions.
Why deletion is not always immediate or absolute in an organization
An administrator can set Purview retention policies for Microsoft Copilot experiences, OneDrive, SharePoint, and other locations. In the Copilot retention path, expired or deleted interaction items move to a hidden SubstrateHolds folder for at least one day; the timer job typically makes the permanent deletion on a later run within one to seven days. A litigation hold, eDiscovery hold, delay hold, or another applicable retention policy suspends permanent deletion. Retention for Copilot and AI apps
For OneDrive and SharePoint files, a retention policy or label can preserve the original in a hidden Preservation Hold library when a user changes or deletes it. That preserved content is not meant to be edited or removed by an end user. Retention for SharePoint and OneDrive
This is intentional compliance behavior. A chat disappearing from the user interface is not proof that all searchable or retained copies have been permanently deleted. Microsoft explicitly warns that app-visible messages are not an accurate way to verify compliance retention and permanent deletion. Retention for Copilot and AI apps
Three realistic examples
1. Personal account, newly uploaded document
Hypothetical: Priya signs in to copilot.microsoft.com with a personal Microsoft account and uploads insurance-claim.pdf for a plain-language summary.
- The upload is a consumer Copilot file, not an employer-managed OneDrive item.
- Microsoft’s current pages say either up to 30 days or up to 18 months for that file. The applicable term is not publicly resolved. Consumer privacy page Microsoft Support privacy FAQ
- Her chat history has a separate lifecycle. She should delete the conversation after use and, if appropriate, clear the account’s Copilot app activity history in the Privacy Dashboard. Manage Copilot activity history
Decision: For a document containing claim numbers, medical details, or identification information, use a local or trusted specialist tool instead unless uploading is necessary and permitted by the document owner.
2. Work account, document uploaded into Copilot Chat
Hypothetical: Mateo, an employee, drops a confidential product forecast into Microsoft Copilot Chat to compare two scenarios.
- The file is stored in Mateo’s OneDrive for Business, not under the consumer file rule. Microsoft Copilot Chat privacy and protections
- The prompt and answer may be stored as Copilot interaction data for audit and eDiscovery. Microsoft 365 Copilot privacy
- Mateo may remove the chat and request deletion of activity history, but the company’s OneDrive retention policy or a legal hold can preserve the document or chat data. Delete Microsoft Copilot activity history Retention for Copilot and AI apps
Decision: Mateo should follow the company’s AI-use and information-classification policy. If the forecast is restricted, he should ask the information owner or security team before uploading it, rather than assuming “not used for model training” makes the use policy-compliant.
3. Existing SharePoint document cited by Copilot
Hypothetical: A project manager asks Copilot in Microsoft 365 to summarize a SharePoint project plan that already exists in a team site.
- The plan remains a SharePoint file with its own permissions, version history, recycle-bin behavior, and Purview retention. Copilot access does not make its lifecycle equal to a consumer upload’s lifecycle. Retention for SharePoint and OneDrive Microsoft Copilot data-protection architecture
- Deleting the Copilot conversation will not delete the SharePoint project plan.
- If the plan is subject to a retention label or eDiscovery hold, deleting it from the site may retain a compliance copy. Retention for SharePoint and OneDrive
Decision: Manage the project plan in SharePoint. Manage the Copilot interaction separately.
Audit logs are not the same as the file or chat
Organizations can also have Copilot-related audit records. Microsoft says Copilot and AI-application audit records can include the user, time, location, and references to files, sites, or other resources accessed to make a response. Audit logs for Copilot and AI applications
Under Audit (Standard), Microsoft retains audit records for 180 days by default. Audit (Premium), licensing, and a custom audit-retention policy can change that duration, including longer periods for eligible users. It follows that 180 days is a common audit default, not a promise that all Copilot data is removed at 180 days. Manage audit-log retention policies
Do not confuse an audit record that a file was accessed with the file’s contents, the chat’s prompts and responses, or the original OneDrive/SharePoint document. They are different data classes and may have different retention rules.
What to do now
If you are using a personal Microsoft account
- Open your Copilot conversation history and delete the individual conversation containing the upload.
- In the Microsoft Privacy Dashboard, review or export Copilot app activity history, then use Delete all activity history if you need a broad deletion request. Microsoft Support instructions
- Check your Copilot privacy settings for model-training and personalization choices. These controls affect future use of conversation activity; they are not a substitute for deleting an already-uploaded sensitive document. Consumer privacy page
- Do not upload identity documents, health information, passwords, financial account details, or someone else’s confidential file merely because you expect automatic deletion.
If you are using a work or school account
- Determine whether the item was a new Copilot Chat upload or an existing OneDrive/SharePoint file.
- Delete the specific chat if the interface offers that control, and use the My Account deletion request for Copilot activity history when appropriate. Microsoft Support instructions
- For a new upload, find and manage the file in OneDrive for Business. For an existing file, manage the original in its OneDrive or SharePoint location.
- If this is a sensitive-data incident, contact your administrator or compliance team. Do not promise a colleague that deleting the chat has permanently purged all copies.
If you administer the organization
- Document distinct retention settings for Microsoft Copilot experiences, OneDrive, SharePoint, Exchange, and audit logs. New Purview retention policies use separate Copilot locations rather than treating them as ordinary Teams chats. Retention for Copilot and AI apps
- Check whether Copilot Chat uploads in users’ OneDrive for Business folders are in scope for your OneDrive policy. Microsoft Copilot data-protection architecture
- Test deletion and retention behavior with non-sensitive test data, then verify with Purview/eDiscovery rather than relying on the Copilot interface. Microsoft says the interface is not an authoritative view of compliance retention. Retention for Copilot and AI apps
- Make a documented incident path for employees who accidentally upload restricted information. A preservation duty or legal hold may constrain deletion, so involve legal/compliance before changing holds or retention policies.
Common mistakes and their better replacements
| Mistake | Better rule |
|---|---|
| “Copilot keeps everything for 30 days.” | That is one consumer-page statement about an uploaded file, not a universal Copilot rule. |
| “The 18-month number is the chat period and the 30-day number is the file period everywhere.” | Consumer documentation conflicts on the file period, and workplace retention is policy-driven. |
| “I deleted the chat, so the source file is gone.” | Delete and verify the original OneDrive or SharePoint file separately. |
| “I cleared history, so legal or compliance copies must be gone.” | A Purview policy or eDiscovery hold can preserve data beyond user deletion. |
| “Not used to train the model means safe to upload.” | Training is one use. Storage, access controls, policy, and legal duties are separate questions. |
Limits of this answer
Microsoft changes product names, user interfaces, account flows, and privacy terms frequently. It currently uses “Microsoft Copilot” for several experiences that once had more distinct names. The exact screen, available deletion option, storage location, and applicable retention policy can vary by account, subscription, region, and tenant configuration.
Most importantly, Microsoft’s public consumer documentation does not currently provide one internally consistent retention period for a file uploaded to Copilot. This answer reports that conflict instead of selecting the more reassuring number. If you need a written commitment for a regulated use, obtain the applicable Microsoft contract terms and your organization’s approved retention configuration, rather than relying on a consumer FAQ.
Evidence
Sources used for this answer.
Question signals show what people need. Primary documentation supports the answer. Both remain visible.
- 01How long does CoPilot save files for?Microsoft Q&A · question signal · checked 25 Aug 2026
- 02Consumer privacy pagemicrosoft.com · primary evidence · checked 25 Aug 2026
- 03Microsoft Support privacy FAQsupport.microsoft.com · primary evidence · checked 25 Aug 2026
- 04Microsoft Edge privacy documentationlearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 05Manage Copilot activity history in the Privacy Dashboardsupport.microsoft.com · primary evidence · checked 25 Aug 2026
- 06Microsoft Copilot Chat privacy and protectionslearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 07Microsoft Copilot data-protection architecturelearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 08Microsoft 365 Copilot privacylearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 09Retention for Copilot and AI appslearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 10Delete Microsoft Copilot activity historysupport.microsoft.com · primary evidence · checked 25 Aug 2026
- 11Copilot Chat historysupport.microsoft.com · primary evidence · checked 25 Aug 2026
- 12Retention for SharePoint and OneDrivelearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 13Audit logs for Copilot and AI applicationslearn.microsoft.com · implementation guidance · checked 25 Aug 2026
- 14Manage audit-log retention policieslearn.microsoft.com · implementation guidance · checked 25 Aug 2026