232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE
RECORD OPENED 5 OCT 2026 · 1 CLAUSES ON FILE
dev

Does GitLab train on your data?

GitLab's AI terms mention training once: to forbid you from using GitLab Duo to train a competing model. Whether GitLab trains on your code isn't stated.

LAST CHECKED
5 Oct 2026 · 5 days ago
CONFIDENCE
medium
RIGHT OF REPLY
Asked · no reply
Verdict
No clause on file

Evidence 1 — All plans (GitLab Duo / AI Functionality)
AI Addendum · All plans (GitLab Duo / AI Functionality)
EVIDENCE 01 OF 01

This clause is real, but it doesn't resolve the training question - see the finding below.

"Customer represents and warrants that it will not use AI Functionality to create, train, or improve (directly or indirectly) a similar or competing foundational or large language model or other generative artificial intelligence service that competes with the provider of the applicable GitLab Model or Customer Model."
CHECKED
17 Aug 2026
STILL LIVE AS OF
5 Oct 2026
APPLIES TO
All plans (GitLab Duo / AI Functionality)
JURISDICTION
global
HOW IT WAS TAKEN
Fetched from the company
SHA-256
5FB93236…0A9A

Why this is still UNCLEAR: GitLab wrote dedicated AI terms, defined the inputs precisely, and left the question out. The terms define "Input" as what the customer provides plus the supporting Customer Content processed to generate Output, and state that both Input and Output are Customer Content that the customer continues to own. They name GitLab Models as the ones GitLab hosts. The single training sentence in the document is the one quoted here, and it runs the other way: a warranty from the customer not to train a competitor. Nothing says whether GitLab may train its own models on Input. The handbook privacy page is no help either — all three of its "training" references are the annual privacy training GitLab staff complete. The terms do say where the answer would live: "these Terms, along with the Agreement and the DPA, govern Customer's access to and use of AI Functionality and GitLab Models" — the subscription agreement and the data processing addendum, neither of which this site archives. And the handbook page read here is not GitLab's privacy statement; it links onward to the customer-facing "GitLab Privacy Statement", a further document. So "left out" overstates it: the question is routed to documents out of frame, which is the pointer pattern rather than pure silence.

What each plan can refuse

The same questions, asked of every plan we could identify. Every cell comes from a quoted clause or a documented search - see the evidence above.

All plans (GitLab Duo / AI Functionality)UNCLEAR
OPT-OUT
Not established
RETENTION
Not stated
EXPOSURE
—
DE-IDENTIFIED
—
HUMAN REVIEW
Not established

How to opt out of GitLab AI training

Plan by plan, from what GitLab's own policy says about refusing. Where it publishes the steps, they're listed here with the limits they carry. Where there's nothing to switch off, or nothing graded, this says so instead of inventing a menu path.

All plans (GitLab Duo / AI Functionality)

Not graded, so no route is pointed at. GitLab wrote dedicated AI terms, defined the inputs precisely, and left the question out. The terms define "Input" as what the customer provides plus the supporting Customer Content processed to generate Output, and state that both Input and Output are Customer Content that the customer continues to own. They name GitLab Models as the ones GitLab hosts. The single training sentence in the document is the one quoted here, and it runs the other way: a warranty from the customer not to train a competitor. Nothing says whether GitLab may train its own models on Input. The handbook privacy page is no help either — all three of its "training" references are the annual privacy training GitLab staff complete. The terms do say where the answer would live: "these Terms, along with the Agreement and the DPA, govern Customer's access to and use of AI Functionality and GitLab Models" — the subscription agreement and the data processing addendum, neither of which this site archives. And the handbook page read here is not GitLab's privacy statement; it links onward to the customer-facing "GitLab Privacy Statement", a further document. So "left out" overstates it: the question is routed to documents out of frame, which is the pointer pattern rather than pure silence.

Each step's source and archived copy →

What this policy has done since we started watching

2 CAPTURES SINCE 13 AUG 2026

The record starts here. GitLab's 2 documents were first captured on 13 Aug 2026, and there's no earlier copy to compare them against, so this verdict has no history behind it yet. From now on every re-read is diffed against those copies, and anything that moves appears here.

Everything we read

DOCUMENT
CHECKED
SNAPSHOT
Privacy Policy
13 Aug 2026
AI Addendumquoted
17 Aug 2026

Vendor response

From the company? What a reply does and what moves a grade.

We wrote to GitLab on 19 Aug 2026, quoting the clauses above and inviting a correction. Nothing has come back. That's published because a company declining to comment on its own policy is something a reader should know, and because the invitation should be on the record whether or not it's taken up. Any reply goes here, word for word.

Report a wrong clause

Compared with GitHub · Writing about GitLab? Embed this verdict as a card that stays current.