
Microsoft Copilot conversations can feel like a simple chat experience, but behind the scenes there’s an important compliance story. Microsoft Purview provides retention capabilities that help organizations manage how Copilot and other AI app interactions are stored, retained, searched, and deleted. This page explains what happens to prompts and responses after users interact with Copilot, where that data is stored, and how retention policies affect its lifecycle. If you’re responsible for governance, compliance, or simply want to understand what happens to Copilot chat data in Microsoft 365, this is a helpful place to start.
“Learn about retention for Copilot and AI apps | Microsoft Learn”
“Copilot or another AI app Behind the scenes, Exchange mailboxes are used to store data copied from these messages. Data from generative AI messages is stored in a hidden folder in the mailbox of the user who runs the AI app. This hidden folder isn’t designed to be directly accessible to users or administrators, but instead, store data that compliance administrators can search with eDiscovery tools.
The Exchange mailbox for retaining these messages has the RecipientTypeDetails attribute of UserMailbox, which also stores message data for Teams private channels and cloud-based Teams users.
After a retention policy is configured for AI app interactions, a timer job from the Exchange service periodically evaluates items in the hidden mailbox folder where these messages are stored. The timer job typically takes 1-7 days to run. When these items have expired their retention period, they’re moved to the SubstrateHolds folder—another hidden folder that’s in every user mailbox to store “soft-deleted” items before they’re permanently deleted.
Messages remain in the SubstrateHolds folder for at least 1 day, and then if they’re eligible for deletion, the timer job permanently deletes them the next time it runs.”
Note:
Previously, messages from Microsoft 365 Copilot and Microsoft 365 Copilot Chat were automatically included in the retention policy location named Teams chats and Copilot interactions because they were retained and deleted by using the same mechanisms. Users didn’t have to be using Teams for the retention policy to apply to Copilot.
Retention policies for Microsoft 365 Copilot and Microsoft 365 Copilot Chat are now separate from Teams chats, and newly created retention policies support the following locations:
- Microsoft Copilot experiences
- Microsoft 365 Copilot
- Security Copilot
- Copilot in Fabric
- Copilot Studio
- Enterprise AI apps
- Entra-registered AI apps
- ChatGPT Enterprise
- Microsoft Foundry
- Other AI apps
- ChatGPT
- Google Gemini
- Microsoft Copilot (consumer version)
- DeepSeek