GitLab Privacy Statement
https://about.gitlab.com/privacy/ • 218 KB fetched
Open original page
GitLab Privacy Statement
Close
To search repositories and projects, login to gitlab.com .
Suggestions GitLab Duo Agent Platform Code Suggestions (AI) CI/CD GitLab on AWS GitLab on Google Cloud Why GitLab?
* Platform Execution & Workflows
* CI/CD
* Source Code Management
* Agile Delivery
Security & Governance
* Application Security Testing
* Governance & Compliance
* Supply Chain Security
Context & AI
* Agentic Orchestration
* Context Graph
* Visibility & Measurement
Explore the Platform
Why GitLab
One platform for speed with control across your software lifecycle.
Learn more
* Solutions Outcomes
* DevOps Modernization
* Security Modernization
* AI Modernization
By size
* Enterprise
* Small Business
* Startups
Industries
* Financial Services
* Public Sector
* Telecommunications
* Automotive
* Education
* Aerospace
View all Solutions
GitLab Transcend
Catch our latest innovations announced at the last Transcend.
Read the blog
* Pricing
* Resources Discover
* Docs
* University
* Demo Series
* Demo Hub
* Services
Connect
* Blog
* Community
* Customers
* Partners
* Events
View all resources
What’s new in GitLab
Stay updated with our latest features and improvements.
Read the latest
* Company
* About
* Jobs
* Press
* Handbook
* Leadership
* Investor relations
* Trust Center
* AI Transparency Center
* Newsletter
* Contact us
* Talk to sales
* Support portal
* Customer portal
Request a demo Get free trial Sign in
* English
* Deutsch
* Español
* Français
* Italiano
* 日本語
* Português
Get free trial
Ship at agent speed. Prove every step. Transcend returns on October 6. Register now
Jump to a section
* What Personal Data does GitLab Collect about Me?
* What Personal Data is Not Collected by GitLab?
* How does GitLab Use My Personal Data and Our Legal Basis for Processing?
* With Whom does GitLab Share My Personal Data?
* How does GitLab Secure My Personal Data?
* What are My Rights and Choices Regarding Personal Data?
* U.S. State Privacy Rights
* Other Important Privacy Information
GitLab Privacy Statement
Last updated: April 23, 2026
To see our California Consumer Privacy Act ("CCPA") Notice at Collection , please click on the link or see the “U.S. State Privacy Rights” section below.
Introduction
At GitLab, we take the privacy and security of your information seriously. This privacy statement (“Privacy Statement”) will explain how GitLab B.V. and GitLab Inc. ("GitLab", "we", "our", "us") handle your personal data. "Personal Data," as used in this Privacy Statement, is information that identifies or can reasonably be linked directly or indirectly to an identifiable person. The privacy practices and standards detailed in this Privacy Statement apply to all data subjects globally, unless specifically noted otherwise. In particular, this Privacy Statement will touch on the following sections:
* What Personal Data does GitLab Collect about Me?
* What Personal Data is Not Collected by GitLab?
* How Does GitLab Use My Personal Data and Our Legal Basis for Processing?
* With Whom does GitLab Share My Personal Data?
* How does GitLab Secure My Personal Data?
* What are My Rights and Choices Regarding Personal Data?
* U.S. State Privacy Rights
* Other Important Privacy Information
This Privacy Statement applies to the GitLab websites ("Websites"), GitLab.com and GitLab Dedicated ("SaaS"), Self-managed ("Self-managed"), and additional software products and services; collectively "Services.
What Personal Data does GitLab Collect about Me?
The categories of Personal Data collected by GitLab change depending on the Services you use and whether those Services are free or paid. We have described below which Services correlate with the processing in each Personal Data category.
Information You Provide Directly
We collect the Personal Data you provide to us, for example:
Account Information: When you register for an account with GitLab, we collect information that identifies you such as your name, username, email address, country and/or region, and password. This is collected for free and paid users of the SaaS product.
Profile Information: We collect information that you voluntarily provide in your user profile; this may include your public avatar (which may be a photo), additional email addresses, company/organization name, job title, country, social media handles, and biography. Please note this information will be visible to other users of the Services and to the public, although you can limit the visibility of certain profile fields through your account and profile privacy settings. This is collected for free and paid users of the SaaS product.
Payment and Identity Verification Information: If you purchase a paid subscription from GitLab, we will collect payment information from you that may include your name, billing address and credit card or bank information. We may also use your credit card information and telephone number to verify your identity and prevent abuse of our pipelines. Please note that GitLab does not directly process or store your entire credit card number, but we do direct that information to our third-party payment processors for processing. This is collected for paid users of the Self-managed and SaaS products.
Contact Information: If you request GitLab to contact you, or sign up for marketing materials, events, or participate in user research and development, GitLab may collect information such as name, address, email address, telephone number, company name, and size of company. This may be collected through the Websites, such as through our live video and chat function on our marketing pages or during account registration.
Licensee Information: We collect licensee name, email address, and similar information associated with the individual that receives a license key for the paid users of the Self-managed product.
Content you provide through the use of the Services: Examples of content we collect and store include but are not limited to: the summary and description added to an issue, your repositories, commits, project contributions, profile metadata, activity data, comments, and any inputs and outputs generated by Artificial Intelligence (“AI”) and Machine-Learning (“ML”) powered features. Content also includes any code, files and links you upload to the Services. This is collected for the free and paid users of the SaaS product.
Customer Support and Professional Services Information: If you contact GitLab customer support or receive professional services, we will collect information about you related to your account and to the requests you are making or the services being provided. Customer Support information is collected through the Websites, such as the GitLab Community Forum and the GitLab Support Portal . For Community Programs , support will be provided through the GitLab Service Desk .
Call Recordings: We may record and transcribe GitLab webinars, trainings, and online events. In addition, we may record and transcribe sales calls hosted on various videoconferencing technologies to enable our sales and support teams to share conversational insights, create training and presentations, and improve their internal processes.
Other Content You Submit: We may also collect other content that you submit to our Services. For example: feedback, comments and blog posts, or when you participate in any interactive features, surveys, contests, promotions, prize draws, activities or events. When you participate in interactive channels, we may collect and process information for demographic analysis. Such collection is not tied to any specific products, but may be collected through the Websites.
Information about Your Use of the Services We Collect Automatically
We may collect certain Personal Data automatically through your use of the Services, for example:
Device Information and Identifiers: When you access and use our Services, we automatically collect information about your device, which may include: device type, your device operating system, browser type and version, language preference, IP address, hardware identifiers, and mobile IDs. We may also derive your approximate location from this information, including country, city, state and postal code. This information may be collected through any use of the Services.
Subscription Data: We may automatically collect information about the number of active users, licensing timetables, historical user count, and IP address. This is collected for the free and paid users of the Self-managed and SaaS products, including trial subscriptions. Subscription Data details can be found in the Metrics Dictionary .
Customer Product Usage Information: We may automatically collect Customer Product Usage Information to gather insights into the success of stages and features, track how value is delivered through the use of the Services, help generate optimal customer implementation of the Services, and understand end-to-end user behavior. Depending on the category of Customer Product Usage Information collected, the metrics are stored in an aggregated and/or pseudonymized format. Please see our Customer Product Usage Information page for more details regarding the purposes, de-identification, data elements, configuration and opt-out instructions for Customer Product Usage Information. This is collected for the free and paid users of the Self-managed and SaaS products.
Website Usage Data: When you visit our Websites, we automatically log information about how you interact with the sites, such as the referring site, date and time of visit, and the pages you have viewed or links you have clicked. For our Websites, GitLab uses session replay, which captures a de-identified log of the marketing Websites that you visit.
Cookies and Similar Tracking Technologies: GitLab uses cookies and similar technologies to provide functionality, such as storing your settings, and to recognize you as you use our Services. In addition, we use cookies to gather information to provide interest-based advertising which is tailored to you based on your online activity. Please review our Cookies Policy to learn about our practices and the controls we provide you.
Email Engagement Information: When we send you emails, they may include technology such as a web beacon, that tells us your device type, email client, and whether you have received and opened an email, or clicked on any links contained in the email.
Third-Party Integrations: The Services allow for integrations with third-party git applications, such as GitPod, or third-party extensions, such as those in the Visual Studio code marketplace. Further, the Services may contain buttons, links, tools and content from third-party services, such as Meta and X. We may collect information about your use of these integrated applications and extensions, and when you see or interact with these integrations some information may be automatically sent to these third-party companies. However, any third-party integrations’ policies and procedures are not controlled by GitLab, and this Privacy Statement does not cover how third-party integrations use your information. We recommend you read the privacy statements of any third-party companies before connecting to or using their applications or services.
Version Data and Error Tracking: For Self-managed instances, we automatically check for the version of the software you are running, along with accompanying data such as hostname, HTTP Agent, Header, and IP address. These version checks help ensure your instance is up-to-date with the latest security patches and features. We also collect error trace data from GitLab.com and connect that data to profile data so that we can diagnose and resolve technical issues.
GitLab Pages Data: For websites published using GitLab Pages , we collect server access logs containing website visitor IP addresses with time of access and pages visited within the site. This data is kept for 7 -days and then it is disposed of on a rolling basis with new logs. Any other data collected is subject to the website publisher’s own privacy statement.
Information from Third-Parties and Partners
We may collect Personal Data from other parties in the following ways:
Vendors and Partners: We may receive information about you from third-parties such as vendors, resellers, partners, or affiliates. For example, we receive information from our resellers about you and your orders, or we may supplement the data we collect with demographic information licensed from third-parties in order to personalize the Services and our offers to you. Likewise, our sales, marketing, and recruiting teams may receive access to third-party databases containing information to enrich and cleanse business contacts and other corporate data, which may include your email, phone number, and general geographic location through reverse IP address lookup services. We may also receive social listening data from companies that monitor public social media posts. Furthermore, we may combine information across GitLab learning platforms with account information stored in our data warehouse, to create a comprehensive view of your journey with GitLab. In addition, we may use a B2B content experience platform to create personalized content journeys by re-identifying previously anonymous information from website visits and connecting it with your account information, once you've identified yourself in our systems.
Third-Party Services: GitLab allows you to sign up for/in to our Services using third-party accounts, such as Meta or Google. When you give permission for this to happen, GitLab will receive information about you from your third-party account, such as name, email address, location and demographic information. In addition, GitLab allows you to connect the Services through third-party applications, like Jira and Slack. As part of this interaction, third-party applications may send Personal Data to GitLab in accordance with the privacy settings of the third-party service. This Personal Data may include contact information, location, chat commands, and information related to your GitLab projects.
Other Users of the Services: Other users of the Services may provide information about you when they submit issues and comments, or we may receive information when you are designated as a representative or administrator on your company's account.
When you are asked to provide Personal Data, you may decline. And you may use web browser or operating system controls to prevent certain types of automatic data collection. But if you choose not to provide or allow information that is necessary for certain products or features, those products or features may not be available or function correctly.
Information Processed by AI-Powered Features
When you use the GitLab Duo suite of AI capabilities, including Code Suggestions , Agent Platform , and other AI/ML features, your Personal Data will be processed in accordance with this Privacy Statement.
To provide these features, GitLab may transmit your code, supporting contextual information, and other prompts you submit to the Services to third-parties, such as private code modeling service providers. Further, GitLab may collect AI prompts and output to debug and troubleshoot the services and enforce our Website Terms of Use . We may also collect first-party usage data and de-identified prompts related to Duo features for the purposes of identifying and developing product improvements and assessing features engagement. However, we will not use your AI-inputs to train any language models without your instruction or prior consent. This data may be collected in both the SaaS and Self-managed products where AI-features are enabled.
What Personal Data is Not Collected by GitLab?
We prohibit under our Subscription Agreement the input of sensitive or special categories of Personal Data to the Services, which includes Personal Data related to race, ethnicity, political opinions, religion, trade union membership, genetic data, biometric data, health data and sexual orientation. Although GitLab prohibits the collection of sensitive or special categories of personal data, we realize that users might store this kind of information in a GitLab group; however, GitLab does not intentionally collect the Personal Data of individuals that are stored in users' groups or other free-form content inputs. If Personal Data is stored in a user group then the group owner is responsible for its processing.
Further, GitLab does not knowingly collect Personal Data from, or direct any of our Services to, children under the age of 13. With the exception of Educational Licenses, users must be at least 13 years of age to create an account. If we learn or have reason to believe that a user is under 13, we will promptly close that account and delete associated Personal Data in accordance with applicable law.
How does GitLab Use My Personal Data and Our Legal Basis for Processing?
GitLab collects and processes each category of Personal Data for the purposes listed in the tables below.
When our processing is subject to international laws, including but not limited to the General Data Protection Regulation ("GDPR") that governs individuals located in the European Economic Area ("EEA"), we have attributed one of the legal bases enumerated under the GDPR to the “Purpose of Processing” activity. To the extent a jurisdiction allows for different legal bases than those enumerated under GDPR, we will apply only those appropriate legal bases to the purposes of processing as required under applicable law.
Performance of a Contract:
We use your Personal Data to provide the Services you have subscribed to, and to complete and administer the contract you have entered into with GitLab, which includes the Subscription Agreement , the Website Terms of Use , event and training agreements, and any agreement to process payment info
Links found on this page
- gitlab.com [direct]
- GitLab Duo Agent Platform [direct]
- Code Suggestions (AI) [direct]
- CI/CD [direct]
- GitLab on AWS [direct]
- GitLab on Google Cloud [direct]
- Why GitLab? [direct]
- Source Code Management [direct]
- Agile Delivery [direct]
- Application Security Testing [direct]
- Governance & Compliance [direct]
- Supply Chain Security [direct]
- Context Graph [direct]
- Visibility & Measurement [direct]
- Explore the Platform [direct]
- DevOps Modernization [direct]
- Security Modernization [direct]
- AI Modernization [direct]
- Enterprise [direct]
- Small Business [direct]
- Startups [direct]
- Financial Services [direct]
- Public Sector [direct]
- Telecommunications [direct]
- Automotive [direct]
- Education [direct]
- Aerospace [direct]
- View all Solutions [direct]
- GitLab Transcend Catch our latest innovations announced at the last Transcend. Read the blog [direct]
- Pricing [direct]
- Docs [direct]
- University [direct]
- Demo Series [direct]
- Demo Hub [direct]
- Services [direct]
- Blog [direct]
- Community [direct]
- Customers [direct]
- Partners [direct]
- Events [direct]
- View all resources [direct]
- What’s new in GitLab Stay updated with our latest features and improvements. Read the latest [direct]
- About [direct]
- Jobs [direct]
- Press [direct]
- Handbook [direct]
- Leadership [direct]
- Investor relations [direct]
- Trust Center [direct]
- AI Transparency Center [direct]
- Newsletter [direct]
- Talk to sales [direct]
- Support portal [direct]
- Customer portal [direct]
- Request a demo [direct]
- Get free trial [direct]
- English [direct]
- Deutsch [direct]
- Español [direct]
- Français [direct]
- Italiano [direct]
- 日本語 [direct]
- Português [direct]
- Ship at agent speed. Prove every step. Transcend returns on October 6. Register now [direct]
- California Consumer Privacy Act ("CCPA") Notice at Collection [direct]
- GitLab Dedicated [direct]
- GitLab Community Forum [direct]
- Community Programs [direct]
- Service Desk [direct]
- Metrics Dictionary [direct]
- Customer Product Usage Information [direct]
- Cookies Policy [direct]
- GitLab Pages [direct]
- Code Suggestions [direct]
- Agent Platform [direct]
- other AI/ML [direct]
- Website Terms of Use [direct]
- first-party usage data [direct]
- Subscription Agreement [direct]
- Customer Success Services [direct]