BlogsGitLabAI Data Usage and Privacy Controls

AI Data Usage and Privacy Controls

AI Data Usage and Privacy Controls

5
posts
2021–2026

GitLab differentiates itself by offering unconditional data commitments for AI training, ensuring customer data is never used without explicit consent, regardless of subscription tier. This contrasts with industry trends towards opt-out-by-default data collection. GitLab provides transparency through its AI Transparency Center and offers the Duo Agent Platform for self-managed deployments, allowing customers to keep data within their own infrastructure and use self-hosted AI models. This approach also includes plans to de-identify service usage data by limiting access to identifiable information and introducing a new system to de-identify users and other personal information from multi-user instances before the information lands in GitLab's analytics environment. This will allow GitLab to roll up more aggregated, de-identified user-level activity at the account level. However, there is a gap for single-user namespaces where de-identification may not be perfect.

2026

Atlassian will train on your data: Opt out with GitLab

5/4/2026

This post highlights a significant shift in Atlassian's AI data usage policy, moving to an opt-out-by-default model for training AI offerings on customer metadata and in-app content. It contrasts this with GitLab's unwavering commitment to not train on customer data at any tier. The post details the types of data Atlassian will collect, the implications for different subscription tiers, and the governance challenges posed by opt-out-by-default practices. It emphasizes GitLab's principles of unconditional data commitments, transparency, auditability, and separation of customer data from vendor AI training. It also introduces GitLab Duo Agent Platform for self-managed deployments as a solution for customers who need to keep data within their own infrastructure.

GitHub Copilot's policy for AI training: A governance wake-up call

4/20/2026

This post highlights GitLab's commitment to not using customer code for AI model training, contrasting it with GitHub's policy change. It emphasizes GitLab's contractual prohibitions against AI vendors using customer data and points to the GitLab AI Transparency Center as an auditable source of information on data handling, model usage, and subprocessors. The post also details how this approach addresses the needs of regulated industries by providing contractual certainty, auditability, and separation from vendor incentives, and mentions the AI Continuity Plan as a response to vendor changes.

2025

Why enterprise independence matters more than ever in DevSecOps

9/2/2025

This post announces the general availability of the GitLab Duo Agent Platform and reiterates GitLab's commitment to enterprise independence, transparency, and developer-first principles in the context of AI integration. It details how the Duo Agent Platform provides visibility into agent decision-making, expanded AI model support for vendor independence, and enhanced governance controls. The post highlights the AI Transparency Center for clear documentation on data governance, privacy, and ethical AI principles, emphasizing that customer data is not used for training. It also discusses model flexibility, the AI continuity plan for evaluating and switching models, and deployment flexibility across on-premises, SaaS, and GitLab Dedicated options. Security and compliance are presented as built-in features, contrasting with fragmented platforms. The post also touches on the importance of open-source community engagement and data governance, ensuring users maintain control over their data and AI processing.

2024

Introducing the GitLab AI Transparency Center

4/11/2024

This post announces the launch of the GitLab AI Transparency Center, which consolidates GitLab's AI Ethics Principles for Product Development, AI Continuity Plan, and AI features documentation. It elaborates on the AI Ethics Principles, covering avoiding unfair bias, safeguarding against security risks, preventing potentially harmful uses, considering data usage, and holding accountability. It also explains the AI Continuity Plan, highlighting GitLab's flexibility in not being tied to a single AI model provider and its process for selecting third-party AI vendors. The post emphasizes GitLab's commitment to transparency and privacy in its AI features.

2021

GitLab solicits input on its plans to de-identify service usage data

3/4/2021

This post details plans to de-identify service usage data by limiting access to identifiable information and introducing a new system to de-identify users and other personal information from multi-user instances before the information lands in GitLab's analytics environment. This will allow GitLab to roll up more aggregated, de-identified user-level activity at the account level. It also acknowledges that de-identification may not be perfect for single-user namespaces and solicits input on the design and implementation over the next 30 days.