Does GitLab train on your data?
GitLab's AI terms mention training once: to forbid you from using GitLab Duo to train a competing model. Whether GitLab trains on your code isn't stated.
This clause is real, but it doesn't resolve the training question - see the finding below.
"Customer represents and warrants that it will not use AI Functionality to create, train, or improve (directly or indirectly) a similar or competing foundational or large language model or other generative artificial intelligence service that competes with the provider of the applicable GitLab Model or Customer Model."
- 17 Aug 2026
- 5 Oct 2026
- All plans (GitLab Duo / AI Functionality)
- global
- Fetched from the company
- 5FB93236…0A9A
Why this is still UNCLEAR: GitLab wrote dedicated AI terms, defined the inputs precisely, and left the question out. The terms define "Input" as what the customer provides plus the supporting Customer Content processed to generate Output, and state that both Input and Output are Customer Content that the customer continues to own. They name GitLab Models as the ones GitLab hosts. The single training sentence in the document is the one quoted here, and it runs the other way: a warranty from the customer not to train a competitor. Nothing says whether GitLab may train its own models on Input. The handbook privacy page is no help either — all three of its "training" references are the annual privacy training GitLab staff complete. The terms do say where the answer would live: "these Terms, along with the Agreement and the DPA, govern Customer's access to and use of AI Functionality and GitLab Models" — the subscription agreement and the data processing addendum, neither of which this site archives. And the handbook page read here is not GitLab's privacy statement; it links onward to the customer-facing "GitLab Privacy Statement", a further document. So "left out" overstates it: the question is routed to documents out of frame, which is the pointer pattern rather than pure silence.
What each plan can refuse
The same questions, asked of every plan we could identify. Every cell comes from a quoted clause or a documented search - see the evidence above.
- Not established
- Not stated
- —
- —
- Not established
How to opt out of GitLab AI training
Plan by plan, from what GitLab's own policy says about refusing. Where it publishes the steps, they're listed here with the limits they carry. Where there's nothing to switch off, or nothing graded, this says so instead of inventing a menu path.
All plans (GitLab Duo / AI Functionality)
Not graded, so no route is pointed at. GitLab wrote dedicated AI terms, defined the inputs precisely, and left the question out. The terms define "Input" as what the customer provides plus the supporting Customer Content processed to generate Output, and state that both Input and Output are Customer Content that the customer continues to own. They name GitLab Models as the ones GitLab hosts. The single training sentence in the document is the one quoted here, and it runs the other way: a warranty from the customer not to train a competitor. Nothing says whether GitLab may train its own models on Input. The handbook privacy page is no help either — all three of its "training" references are the annual privacy training GitLab staff complete. The terms do say where the answer would live: "these Terms, along with the Agreement and the DPA, govern Customer's access to and use of AI Functionality and GitLab Models" — the subscription agreement and the data processing addendum, neither of which this site archives. And the handbook page read here is not GitLab's privacy statement; it links onward to the customer-facing "GitLab Privacy Statement", a further document. So "left out" overstates it: the question is routed to documents out of frame, which is the pointer pattern rather than pure silence.
What this policy has done since we started watching
The record starts here. GitLab's 2 documents were first captured on 13 Aug 2026, and there's no earlier copy to compare them against, so this verdict has no history behind it yet. From now on every re-read is diffed against those copies, and anything that moves appears here.
Vendor response
We wrote to GitLab on 19 Aug 2026, quoting the clauses above and inviting a correction. Nothing has come back. That's published because a company declining to comment on its own policy is something a reader should know, and because the invitation should be on the record whether or not it's taken up. Any reply goes here, word for word.
Report a wrong clause