Legal · Effective August 16, 2026 · v2026-08-16
AI & Machine Learning Data Use Policy
This AI & Machine Learning Data Use Policy describes how Level Up Labs uses Path 2 anonymized data derived from the Hosted Account Service. It is incorporated by reference into the Terms of Service and the Privacy Policy.
See also the Terms of Service · Privacy Policy · Payment Processing Policy · Cookie Policy.
1. Overview and Scope
This AI & Machine Learning Data Use Policy ("AI Policy") describes how Level Up Labs (a DBA of Level Up Technology LLC) uses data in connection with the artificial intelligence and machine learning systems that underlie BacklogZero®. This AI Policy is incorporated by reference into the Terms of Service and the Privacy Policy, and should be read in conjunction with the Payment Processing Policy and Cookie Policy. Where we execute a Data Processing Agreement ("DPA") with a Customer, that DPA also applies to Path 1 personal data.
BacklogZero comprises (i) the Hosted Account Service (Level Up Labs–operated account management, identity, downloads, licensing, billing, and related APIs at backlogzero.ai) and (ii) the Software Bundle (the self-hosted appliance you download and run in the Customer Environment). This is not a SaaS runtime for your ITSM, Git, or Ansible Automation Platform data: the Software Bundle runs on infrastructure you control, with a local large language model ("LLM") and retrieval-augmented generation ("RAG") by default, plus optional Customer-configured cloud LLM providers.
This AI Policy governs Path 2 anonymized data derived from the Hosted Account Service. Path 1 account-linked Hosted Account Service data is addressed in the Privacy Policy and, where executed, the DPA. The Software Bundle's local ITSM, Git, playbook, and inference corpora are not Path 2 training inputs unless they (or derived metadata) are transmitted to the Hosted Account Service.
The quality, accuracy, and trustworthiness of Hosted Account Service outputs and related models depend on the ongoing training and evaluation of our AI/ML models using anonymized data derived from Hosted Account Service usage. This AI Policy applies to all users and Customers of the Hosted Account Service, globally.
2. Two-Path Data Architecture
Hosted Account Service data follows two distinct paths, described in further operational detail in our Technical and Organizational Measures (TOMs) document (available upon request).
Path 1 – Service Delivery Data: data needed to deliver the Hosted Account Service to a specific Customer account, including Account Records (identity, organization membership, download and entitlement history, billing metadata we receive, support threads, and any diagnostics or operational metadata transmitted to that account). Path 1 is retained on an account-linked basis, is NOT anonymized, and is personal data governed by the Privacy Policy and, where executed, the DPA.
Path 2 – AI/ML Training Data: a separate, aggregated dataset is subjected to genuine anonymization — aggregation across Customers and time periods sufficient to prevent attribution to any individual or Customer, with all direct and reasonably reversible identifiers removed — before any use in training, testing, or evaluating our AI/ML models. This AI Policy governs only Path 2 data; Path 1 data is addressed in the Privacy Policy and, where executed, the DPA.
Path 2 anonymized data — data from which all direct and reasonably reversible identifiers have been removed and which cannot reasonably be re-linked to an individual or a specific Customer — is not personal data under applicable privacy laws, including the GDPR, CCPA/CPRA, and similar frameworks. Path 1 Service Delivery Data, including Account Records, IS personal data, is not anonymized, and is not within the scope of this AI Policy's anonymization commitments.
Software Bundle data (ITSM tickets, Git contents, playbooks, RAG indexes, local prompts and completions, and Crane Configuration-as-Code exports) remains in the Customer Environment. It is neither Path 1 Hosted Account Service data nor Path 2 unless the Customer transmits it (or derived metadata) to us — for example as support diagnostics.
Optional third-party LLM inference (Software Bundle)
If a Customer enables Anthropic, OpenAI, or another supported cloud provider inside the Software Bundle, inference requests leave the Customer Environment to that provider under the Customer's credentials and that provider's terms. That traffic is not Path 2. Level Up Labs does not receive those prompts or completions unless the Customer separately shares them.
3. What Data Is Used for AI/ML
The following categories of anonymized data may be used to train, test, evaluate, benchmark, and improve the AI and machine learning models that power the Hosted Account Service and related BacklogZero capabilities:
- Anonymized account and download workflow signals (for example, feature engagement patterns, download and entitlement event patterns, session metadata — with all identifiers removed).
- Anonymized support and assistance interaction patterns derived from Hosted Account Service use and from Software Bundle support-assistant records only when those records have been transmitted to us (query/response structure and retrieval quality signals, not integration secrets).
- Anonymized software-operations workflow signals associated with account-linked metadata the Customer elects to send (for example, high-level product-area usage, error class frequencies — with no attribution to individuals or tenants).
- Aggregated performance signals used to evaluate model output quality.
We do NOT use the following for AI/ML training under any circumstances:
- Non-anonymized Software Bundle ITSM ticket content, playbook source, or Git repository contents.
- Individual user identifiers, names, or email addresses.
- Payment or billing card information.
- Authentication credentials, integration tokens, or secrets.
- Any data marked as confidential or sensitive by the Customer that has not been subjected to Path 2 anonymization.
- Crane-exported AAP configuration (Crane is a deterministic compiler and is not used for AI/ML training).
4. How Anonymized Data Is Used
Anonymized data is used for the following AI/ML purposes:
- Training and fine-tuning models that support the Hosted Account Service and related BacklogZero assistance, recommendation, and quality features.
- Evaluating model accuracy, relevance, and trustworthiness.
- Detecting and mitigating model bias, safety issues, or quality regressions.
- Benchmarking model performance across diverse customer environments.
- Developing and testing new AI-powered features and capabilities.
- Generating aggregate benchmark insights that compare a Customer's account-linked signals against broader, cross-Customer industry benchmarks, where the benchmark dataset is genuinely anonymized under Path 2 and no individual Customer or account is identifiable in, or re-derivable from, the comparison set.
Legal basis (Path 2 only)
Because data used for AI/ML training and the benchmark insights described above is genuinely anonymized under Path 2 and does not constitute personal data, it is not subject to legal basis requirements under the GDPR, CCPA/CPRA, or similar frameworks. Our use of such data is consistent with Article 5(1)(b) of the GDPR (further processing for compatible purposes) and GDPR Recital 26 (anonymized data is outside scope). The same anonymization-based analysis applies under other comparable frameworks, including Canada's PIPEDA, Brazil's LGPD (Article 12), Australia's Privacy Act 1988, and Switzerland's nFADP, each of which similarly excludes properly anonymized data from personal-data obligations.
Personalization features (Path 1 account data)
Separately from the Path 2 AI/ML training uses described above, Level Up Labs uses a Customer's own Path 1 Service Delivery Data — including that Customer's Account Records and account-linked usage patterns, which are NOT anonymized — to generate product recommendations directed to that specific Customer account (for example, suggesting features, download channels, configuration options, or integrations that may benefit that Customer based on its own observed activity). Because this feature operates on account-linked personal data, it is governed by the Privacy Policy and, where executed, the DPA, rather than this AI Policy's anonymized-data provisions. Legal basis: legitimate interest in improving the Service for the Customer and, where applicable, performance of the contract with the Customer (GDPR Art. 6(1)(b) and (f)); a comparable basis applies under CCPA/CPRA and other frameworks.
Customers and authorized users may opt out of this personalization feature at any time by contacting hello@leveluplabs.ai. Opting out does not affect Path 2 AI/ML training, which remains governed by Section 5 below. Software Bundle playbook generation on the Customer's host is not this hosted personalization feature; it is the Customer's processing of the Customer's own data.
5. No Opt-Out for Path 2 Anonymized Data Use
Because the use of genuinely anonymized Path 2 data for AI/ML training and testing is a core and non-severable function of the Hosted Account Service — essential to maintaining the accuracy, trustworthiness, and improvement of Service outputs — there is no right to opt out of this Path 2 use. This no-opt-out rule does NOT apply to the Path 1 personalization feature described in Section 4 above, which Customers and authorized users may opt out of as described there.
This is a deliberate design choice. The commitment Level Up Labs makes in return is strict: Path 2 AI/ML training is conducted exclusively on genuinely anonymized, aggregated information, and that anonymized dataset is never re-linked to an individual or a specific Customer account.
This approach differs from AI/ML training practices that involve personal or identifiable data, which would require separate consent and are not a practice of Level Up Labs with respect to Path 2 training. Customers who require a zero-Path-2-training environment that is technically incompatible with the Hosted Account Service's architecture should not use the Hosted Account Service. Customers may, however, opt out of the Path 1 personalization feature in Section 4 without affecting their ability to use the Service. Use of the Software Bundle without creating a hosted account does not, by itself, contribute data to Path 2.
6. What We Never Do
Level Up Labs makes the following firm commitments:
- We will never use non-anonymized Customer Data for AI/ML training.
- We will never sell anonymized data to third parties for AI training.
- We will never use Customer data to train models that are made available to other Customers in a manner that could expose Customer-specific information.
- We will never use AI/ML data practices beyond those described here without updating this AI Policy and providing advance notice.
- We will never retaliate or degrade Service quality based on a Customer's use of any applicable privacy right.
7. Anonymization Standards
Level Up Labs applies rigorous anonymization standards to all data used for AI/ML purposes:
- All direct identifiers (names, email addresses, user IDs, account numbers) are removed or replaced with non-reversible tokens prior to any AI/ML use.
- Account and operational metadata is processed to remove strings or other content that could identify an individual or organization.
- Aggregation thresholds are applied to ensure that no dataset used for training can be traced to a single user or Customer account.
- Anonymization processes are reviewed against the "reasonably likely to re-identify" standard consistent with GDPR Recital 26 and applicable guidance.
- Internal access to pre-anonymization data is restricted to authorized personnel under the principle of least privilege.
8. AI Model Governance
Level Up Labs maintains internal AI governance practices to ensure responsible use of AI in the Service, including:
- Model evaluation and quality review prior to production deployment.
- Ongoing monitoring of model outputs for accuracy, relevance, and potential bias.
- Human review capabilities for flagged outputs.
- Documentation of training data sources, model versions, and evaluation results.
- An internal assessment of Level Up Labs's role (for example, provider or deployer) and risk classification under the EU AI Act (Regulation (EU) 2024/1689), including consideration of whether the Service or any of its AI components falls within a high-risk category under Annex III, with corresponding transparency, documentation, and human-oversight measures implemented where applicable; this assessment is reviewed periodically as guidance and case law develop and is cross-referenced in the Terms of Service (AI-generated outputs).
Software Bundle inference
Inference that runs inside the Software Bundle against a customer-configured language-model endpoint (local by default) is the Customer's processing. This AI Policy does not grant Level Up Labs rights in those local payloads.
9. Service Outputs and Reliability
Service Outputs generated by AI systems — including assistance, recommendations, and related Hosted Account Service features — are provided for informational and productivity purposes. Level Up Labs does not warrant that Service Outputs are complete, error-free, or a substitute for professional engineering or operational judgment.
Customers are responsible for reviewing, validating, and making decisions based on Service Outputs. Level Up Labs is not liable for actions taken in reliance on Service Outputs without appropriate human review.
Software Bundle playbook and automation outputs generated on the Customer's host are likewise not a substitute for the Customer's change control, testing, and approval processes. Crane (Beta) is a deterministic Configuration-as-Code compiler; Crane exports are not AI-authored Service Outputs and are not used for AI/ML training.
10. Changes to This Policy
We may update this AI Policy as our AI/ML practices evolve, regulatory requirements change, or we introduce new features. If we make material changes, we will notify you via email or in-service notice at least thirty (30) days before the changes take effect.
11. Contact
Questions regarding this AI Policy should be directed to:
Level Up Labs (a DBA of Level Up Technology LLC)
Email: hello@leveluplabs.ai
Support: support@leveluplabs.ai
21300 Victory Blvd, Third Floor
Woodland Hills, CA 91367
United States
Website: https://backlogzero.ai
Level Up Technology LLC d/b/a Level Up Labs. Privacy questions: hello@leveluplabs.ai. 21300 Victory Blvd, Third Floor, Woodland Hills, CA 91367, United States.