GitLab
- Your data trains their AI only if you opt in.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared with partners and affiliates; you can opt out.
- The policy describes staff access for safety and legal checks.
GitLab collects account, code, and device data; AI inputs are not trained without consent, but ads cookies and public posts linger.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account info, your code and comments, device and IP data, cookies, and sometimes partner data.
Read the exact line
Privacy policy
“When you register for an account with GitLab, we collect information that identifies you such as your name, username, email address, country and/or region, and password.”
Training
They run the service, improve it, market to you, and send AI prompts to third parties, but say they need consent to train models.
Read the exact line
Privacy policy
“However, we will not use your AI-inputs to train any language models without your instruction or prior consent.”
Sharing
Other users and the public can see public profiles; vendors, partners, and affiliates may get data too.
Read the exact line
Privacy policy
“We may share your Personal Data with other users of the Services and with the public if you choose to make your SaaS Profile public.”
Kept
They keep data while your account is active; public posts and some history may stay forever.
Read the exact line
Privacy policy
“GitLab will only retain your Personal Data for as long as your account is active or as needed to perform our contractual obligations, provide you the Services, comply with legal obligations, resolve disputes, preserve legal rights, or enforce our agreements.”
Controls
You can update your profile, delete a SaaS account in settings, or file a privacy request.
Read the exact line
Privacy policy
“If you only want to delete your SaaS account, you may do so by logging into your account and going to the “Delete Account” option in your User Settings.”
Fine print
They post policy updates and may email you; full lawsuit, refund, and rules were not in the terms page we got.
Read the exact line
Privacy policy
“If we decide to make a significant change to our Privacy Statement, we will post a notice of the update on the homepage of our Website.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Delete your SaaS account
Log in, User Settings, “Delete Account”; for all systems, Make a Privacy Request and select “Delete my personal data.”
Opt out of interest-based ads
Cookies Policy (linked from the Privacy Statement)
Unsubscribe from marketing
Unsubscribe link in marketing emails or the preference center
Export projects
SaaS Export functionality or clone repositories; profile via the API
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
Even after you leave, some of your name or comments on public stuff can stay forever.
Read the exact line
Privacy policy
“Please note that due to the open source nature of our Services, we may retain limited Personal Data indefinitely in order to provide a transactional history.”
For example, a comment you left on a public issue may still show after you delete your account.
They use tracking cookies so ads can follow what you do online.
Read the exact line
Privacy policy
“In addition, we use cookies to gather information to provide interest-based advertising which is tailored to you based on your online activity.”
For example, visiting pricing pages could later show you GitLab ads on other sites.
Your code and AI prompts can be sent to outside AI companies to run Duo features.
Read the exact line
Privacy policy
“To provide these features, GitLab may transmit your code, supporting contextual information, and other prompts you submit to the Services to third-parties, such as private code modeling service providers.”
For example, a snippet you paste for Code Suggestions may go to another vendor’s model.
They say they will not train AI on your prompts unless you agree first.
Read the exact line
Privacy policy
“However, we will not use your AI-inputs to train any language models without your instruction or prior consent.”
For example, your private code in Duo should not become training data unless you opt in.
If others copied your public repo, GitLab will not delete those copies for you.
Read the exact line
Privacy policy
“Be advised that if you allow your repository to be forked or cloned by making it public or by providing specific authorization, such repositories will fall outside the scope of your request for deletion.”
For example, a public project someone forked can keep your old commits after you delete your account.
They can add data about you from other companies and public social media.
Read the exact line
Privacy policy
“We may also receive social listening data from companies that monitor public social media posts.”
For example, a public tweet about GitLab might be mixed into their marketing view of you.
Sales and event calls may be recorded and written down for internal training.
Read the exact line
Privacy policy
“We may record and transcribe sales calls hosted on various videoconferencing technologies to enable our sales and support teams to share conversational insights, create training and presentations, and improve their internal processes.”
For example, a sales Zoom call could be transcribed and used to train their team.
They say they generally do not peek inside private projects except for security, law, uptime, or support you ask for.
Read the exact line
Privacy policy
“Except to host the Services, GitLab does not process Personal Data in private groups or projects unless the following situations arise: to maintain security or to remediate a security incident; to scan for malware and vulnerabilities that violate the Website Terms of Use; to comply with our legal obligations; to ensure the availability of the Services; to provide support to a repository owner upon request; or on the basis of your consent.”
For example, a private repo is not routinely read by staff unless they scan for malware or you open a ticket.
You must be at least 13; they say they will close under-13 accounts if they find them.
Read the exact line
Privacy policy
“Further, GitLab does not knowingly collect Personal Data from, or direct any of our Services to, children under the age of 13.”
For example, a 12-year-old who signs up should have the account closed if GitLab learns their age.
They claim they use basic security controls to protect your data.
Read the exact line
Privacy policy
“We employ administrative, technical, and physical security controls where appropriate, to protect your information from unauthorized access or destruction.”
For example, they point to technical measures for GitLab.com rather than promising a specific audit in this text.
Words to know
Legal words from the lines above, in plain English.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- consent
- Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- retention
- How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
- cookies
- Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
- targeted advertising
- Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
- prompt
- What you type or say to an AI to get a response. For example, asking a chatbot to write a birthday message is a prompt, and it may be stored.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- service providers
- Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
How we got here · grade B · score 55/100 · 15 of 15 policy answers backed by a verified quote · 4 not stated
What does the app collect beyond what it needs to work?
Besides your account and the code you put in GitLab, they collect device data, IP address, cookies, usage metrics, and some data from partners.
Does it record your voice, face or body, and what happens to that?
They may record and transcribe webinars, trainings, and sales calls and keep those transcripts for internal use.
Are your chats and uploads used to train AI models, and is that off by default?
They say they will not use your AI inputs to train language models without your instruction or prior consent.
Can employees or contractors read your conversations, and when?
They say they do not process personal data in private groups except for security, malware, legal duties, uptime, owner-requested support, or consent.
Are you profiled or tracked for advertising?
They use cookies for interest-based ads and name analytics providers such as Google Analytics and Google Signals.
Do they sell or share your data, and can you opt out?
They share with service providers and, where permitted and with consent if required, with partners and resellers, plus affiliates.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
You can delete a SaaS account in settings, but they may keep limited personal data indefinitely for public history, and chatbot transcripts for 12 months.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe administrative, technical, and physical security controls and point to more detail for GitLab.com.
Is there a real age gate, and are teens protected?
Users must be at least 13 except educational licenses; they do not describe extra age checks beyond closing accounts if they learn someone is under 13.
Will they tell you when the rules change, and is the policy specific?
The privacy statement is dated and they say they will post a homepage notice for significant changes and may email for material changes.
Can they close your account without warning, and can you get your data out first?
They may delete inactive accounts and say they will email you first; they do not describe a general export-before-close for every shutdown.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 6,192 words at a professional or legal expert level (Flesch reading ease 7.3); the terms are 225 words at a professional or legal expert level.