GenAgent Trust Hub
Menu

GitLab

BTier BLow risk · 55/100
  • Your data trains their AI only if you opt in.
  • Your data is used for personalized ads, including by third-party ad companies.
  • Data is shared with partners and affiliates; you can opt out.
  • The policy describes staff access for safety and legal checks.

GitLab collects account, code, and device data; AI inputs are not trained without consent, but ads cookies and public posts linger.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy · April 23, 2026 ↗Terms ↗27 min read · professional or legal expert level25 lines verified word for word

Collected

What is collected

Account info, your code and comments, device and IP data, cookies, and sometimes partner data.

Read the exact line

Privacy policy

“When you register for an account with GitLab, we collect information that identifies you such as your name, username, email address, country and/or region, and password.”

Training

How it is used

They run the service, improve it, market to you, and send AI prompts to third parties, but say they need consent to train models.

Read the exact line

Privacy policy

“However, we will not use your AI-inputs to train any language models without your instruction or prior consent.”

Sharing

Who may see it

Other users and the public can see public profiles; vendors, partners, and affiliates may get data too.

Read the exact line

Privacy policy

“We may share your Personal Data with other users of the Services and with the public if you choose to make your SaaS Profile public.”

Kept

How long it is kept

They keep data while your account is active; public posts and some history may stay forever.

Read the exact line

Privacy policy

“GitLab will only retain your Personal Data for as long as your account is active or as needed to perform our contractual obligations, provide you the Services, comply with legal obligations, resolve disputes, preserve legal rights, or enforce our agreements.”

Controls

Your controls

You can update your profile, delete a SaaS account in settings, or file a privacy request.

Read the exact line

Privacy policy

“If you only want to delete your SaaS account, you may do so by logging into your account and going to the “Delete Account” option in your User Settings.”

Fine print

The fine print

They post policy updates and may email you; full lawsuit, refund, and rules were not in the terms page we got.

Read the exact line

Privacy policy

“If we decide to make a significant change to our Privacy Statement, we will post a notice of the update on the homepage of our Website.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Delete your SaaS account

    Log in, User Settings, “Delete Account”; for all systems, Make a Privacy Request and select “Delete my personal data.”

  2. Opt out of interest-based ads

    Cookies Policy (linked from the Privacy Statement)

  3. Unsubscribe from marketing

    Unsubscribe link in marketing emails or the preference center

  4. Export projects

    SaaS Export functionality or clone repositories; profile via the API

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · How long it is kept

Even after you leave, some of your name or comments on public stuff can stay forever.

Read the exact line

Privacy policy

“Please note that due to the open source nature of our Services, we may retain limited Personal Data indefinitely in order to provide a transactional history.”

For example, a comment you left on a public issue may still show after you delete your account.

2 · How it is used

They use tracking cookies so ads can follow what you do online.

Read the exact line

Privacy policy

“In addition, we use cookies to gather information to provide interest-based advertising which is tailored to you based on your online activity.”

For example, visiting pricing pages could later show you GitLab ads on other sites.

3 · How it is used

Your code and AI prompts can be sent to outside AI companies to run Duo features.

Read the exact line

Privacy policy

“To provide these features, GitLab may transmit your code, supporting contextual information, and other prompts you submit to the Services to third-parties, such as private code modeling service providers.”

For example, a snippet you paste for Code Suggestions may go to another vendor’s model.

4 · How it is used

They say they will not train AI on your prompts unless you agree first.

Read the exact line

Privacy policy

“However, we will not use your AI-inputs to train any language models without your instruction or prior consent.”

For example, your private code in Duo should not become training data unless you opt in.

5 · How long it is kept

If others copied your public repo, GitLab will not delete those copies for you.

Read the exact line

Privacy policy

“Be advised that if you allow your repository to be forked or cloned by making it public or by providing specific authorization, such repositories will fall outside the scope of your request for deletion.”

For example, a public project someone forked can keep your old commits after you delete your account.

6 · What is collected

They can add data about you from other companies and public social media.

Read the exact line

Privacy policy

“We may also receive social listening data from companies that monitor public social media posts.”

For example, a public tweet about GitLab might be mixed into their marketing view of you.

7 · What is collected

Sales and event calls may be recorded and written down for internal training.

Read the exact line

Privacy policy

“We may record and transcribe sales calls hosted on various videoconferencing technologies to enable our sales and support teams to share conversational insights, create training and presentations, and improve their internal processes.”

For example, a sales Zoom call could be transcribed and used to train their team.

8 · How it is used

They say they generally do not peek inside private projects except for security, law, uptime, or support you ask for.

Read the exact line

Privacy policy

“Except to host the Services, GitLab does not process Personal Data in private groups or projects unless the following situations arise: to maintain security or to remediate a security incident; to scan for malware and vulnerabilities that violate the Website Terms of Use; to comply with our legal obligations; to ensure the availability of the Services; to provide support to a repository owner upon request; or on the basis of your consent.”

For example, a private repo is not routinely read by staff unless they scan for malware or you open a ticket.

9 · The fine print

You must be at least 13; they say they will close under-13 accounts if they find them.

Read the exact line

Privacy policy

“Further, GitLab does not knowingly collect Personal Data from, or direct any of our Services to, children under the age of 13.”

For example, a 12-year-old who signs up should have the account closed if GitLab learns their age.

10 · How long it is kept

They claim they use basic security controls to protect your data.

Read the exact line

Privacy policy

“We employ administrative, technical, and physical security controls where appropriate, to protect your information from unauthorized access or destruction.”

For example, they point to technical measures for GitLab.com rather than promising a specific audit in this text.

Words to know

Legal words from the lines above, in plain English.

inputs and outputs
Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
consent
Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
retention
How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
cookies
Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
targeted advertising
Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
prompt
What you type or say to an AI to get a response. For example, asking a chatbot to write a birthday message is a prompt, and it may be stored.
third parties
Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
service providers
Outside companies that handle your data on the app's instructions, such as a cloud host or an email sender. For example, the company that stores the app's files in the cloud sees your data but only does what the app tells it.
How we got here · grade B · score 55/100 · 15 of 15 policy answers backed by a verified quote · 4 not stated
  • What does the app collect beyond what it needs to work?

    Besides your account and the code you put in GitLab, they collect device data, IP address, cookies, usage metrics, and some data from partners.

  • Does it record your voice, face or body, and what happens to that?

    They may record and transcribe webinars, trainings, and sales calls and keep those transcripts for internal use.

  • Are your chats and uploads used to train AI models, and is that off by default?

    They say they will not use your AI inputs to train language models without your instruction or prior consent.

  • Can employees or contractors read your conversations, and when?

    They say they do not process personal data in private groups except for security, malware, legal duties, uptime, owner-requested support, or consent.

  • Are you profiled or tracked for advertising?

    They use cookies for interest-based ads and name analytics providers such as Google Analytics and Google Signals.

  • Do they sell or share your data, and can you opt out?

    They share with service providers and, where permitted and with consent if required, with partners and resellers, plus affiliates.

  • What rights do they take over what you type and what the AI makes?

    Not stated in the documents.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    You can delete a SaaS account in settings, but they may keep limited personal data indefinitely for public history, and chatbot transcripts for 12 months.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    Not stated in the documents.

  • Do they commit to basic security, and have they leaked data?

    They describe administrative, technical, and physical security controls and point to more detail for GitLab.com.

  • Is there a real age gate, and are teens protected?

    Users must be at least 13 except educational licenses; they do not describe extra age checks beyond closing accounts if they learn someone is under 13.

  • Will they tell you when the rules change, and is the policy specific?

    The privacy statement is dated and they say they will post a homepage notice for significant changes and may email for material changes.

  • Can they close your account without warning, and can you get your data out first?

    They may delete inactive accounts and say they will email you first; they do not describe a general export-before-close for every shutdown.

  • If something goes wrong, who pays?

    Not stated in the documents.

  • Do subscriptions renew on their own, and can you get a refund?

    Not stated in the documents.

The privacy policy is 6,192 words at a professional or legal expert level (Flesch reading ease 7.3); the terms are 225 words at a professional or legal expert level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton