Guide7 min read

Microsoft Copilot and Your Data: How to Anonymize Before Sharing

Anonymize identifiers before your Copilot prompt: per Microsoft, the commercial and consumer offers handle your data differently.

By Pierre de ONYRI
Worried about your data? Anonymize it before AI

You want to use Microsoft Copilot without exposing your sensitive data. Here's the direct answer. Anonymize identifiers before writing your prompt. That way, your real values never enter Copilot's processing. It's the simplest habit, and it holds for both offers. Because Copilot isn't a single product: it has two faces with different rules. Let's see which, then how ONYRI helps you keep control.

The short answer

The key point fits in one sentence. The question isn't only « can I use Copilot? », but « which Copilot? ». Per Microsoft, the commercial and consumer offers handle your data differently. In every case, one move reduces exposure: replacing sensitive identifiers with tokens before sending.

  • Commercial offer (Microsoft 365 Copilot, Copilot Chat): work or school account.
  • Consumer offer: Copilot with a personal Microsoft account.
  • Common habit for both: anonymize identifiers before writing the prompt.

Copilot's two faces, per Microsoft

Let's start with the commercial offer. Per Microsoft (Microsoft Learn, « Enterprise data protection » page), it follows a clear rule. For Microsoft 365 Copilot and Copilot Chat in work use, prompts and responses aren't used to train the foundation models. The same holds for data accessed via Microsoft Graph. Microsoft then acts as a data processor, under its Data Protection Addendum.

Microsoft calls this framework « enterprise data protection » (EDP). According to Microsoft, it includes encryption at rest and in transit, tenant isolation, and respect for permissions and sensitivity labels. Microsoft also states support for the GDPR and the EU Data Boundary.

The consumer offer follows a different logic. Per Microsoft (« Protecting Your AI Security, Privacy, and Data » page), with a personal account, you control whether your conversations are used to train its AI models. Microsoft states that you can opt out at any time in the settings. In other words, that use can happen as long as you don't opt out.

Why anonymize first, whichever offer you use

Microsoft's guarantees on the commercial offer are real. But they cover the vendor-side processing. They don't change a simple rule. The less real data you send, the less you expose. That's the minimization principle.

Per the CNIL, the minimization principle (article 5-1-c of the GDPR) requires data that is adequate, relevant and limited to what's necessary. Anonymizing identifiers before the prompt fits this logic. You hand the model only what's useful for your request. Your real values, meanwhile, stay with you.

AspectCommercial CopilotConsumer Copilot
Model trainingPer Microsoft, no foundation-model training on your dataPer Microsoft, possible use for training, with opt-out
Microsoft's roleData processor, under the Data Protection AddendumProvider of the consumer service
Framework cited« Enterprise data protection », EU Data BoundaryPrivacy and training settings
Advised habitAnonymize identifiers before the promptAnonymize identifiers before the prompt
Policies as stated by Microsoft (Microsoft Learn; consumer page), subject to change. Minimization framing after the CNIL (GDPR, art. 5).

How ONYRI helps you on Copilot

ONYRI offers a browser extension. It anonymizes the prompt in the browser, before it reaches Copilot. The sensitive values and the token ↔ value mapping stay in the tab. They never reach our servers. The flow takes four steps.

  1. 1You write your message on the Copilot site, as usual.
  2. 2The extension detects sensitive identifiers and replaces them with tokens, in the browser.
  3. 3The anonymized prompt goes to Copilot; the token ↔ value mapping stays in your tab.
  4. 4On display, your real values are restored on the browser side, from the local mapping.

Let's be honest about the scope. Reversible tokens are pseudonymization, not irreversible anonymization. Your data stays personal under the GDPR. Detection is heuristic: it reduces exposure, it doesn't remove it. The anonymized prompt still goes to Copilot. ONYRI limits how much of it is sensitive; it doesn't see Copilot's traffic.

On the plans side, a Free entry lets you test. Advanced features, such as technical secrets and custom rules, belong to the paid plans (Pro, Team). You add your own in-house terms: project names, client codes, internal identifiers.

Diagram: an abstract prompt bar sends text; identifier rows shift from amber (exposed) to cobalt token chips with a checkmark before reaching an AI card; a fork shows two lanes, a shield-marked enterprise lane and a plain lane, to hint at the two offers.
Anonymize identifiers before the prompt, whichever offer you use. Framing: minimization after the CNIL (GDPR, art. 5).

Copilot has two faces, and Microsoft describes them clearly. Depending on the offer, your data is or isn't used for training. But the useful habit stays the same. Anonymize identifiers before writing your prompt. ONYRI does it in your browser, keeping the mapping in the tab. This approach strongly reduces your data's exposure, without claiming to be « 100% safe ».

Frequently asked questions

How do I anonymize my data before sharing it with Microsoft Copilot?
Replace sensitive identifiers with tokens before writing the prompt. That way, your real values never enter Copilot's processing. The ONYRI extension does it in your browser: the token ↔ value mapping stays in the tab and never reaches our servers. The habit holds for the commercial and consumer offers alike.
Does Copilot use my data to train its models?
It depends on the offer. Per Microsoft, for the commercial offer (Microsoft 365 Copilot, Copilot Chat), prompts and responses aren't used to train the foundation models. For the consumer offer, Microsoft states your conversations may be used for training, with an opt-out available in the settings. These policies are subject to change.
Does anonymizing before Copilot make me GDPR-compliant?
No, not on its own. Reversible tokens are pseudonymization, not irreversible anonymization: your data stays personal under the GDPR. The benefit is concrete: your real values don't reach the model, which reduces exposure and serves the minimization the CNIL underlines.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next