Legal · Effective August 16, 2026 · v2026-08-16
Privacy Policy
Effective Date: August 16, 2026
This Privacy Policy describes how Level Up Technology LLC, a California Limited Liability Company, doing business as Level Up Labs, collects, uses, discloses, and protects personal information in connection with the BacklogZero Hosted Account Service.
See also the Terms of Service · Payment Processing Policy · AI & ML Data Use · Cookie Policy.
1. Who We Are
Level Up Technology LLC, doing business as Level Up Labs ("Level Up Labs," "we," "us," or "our"), operates the BacklogZero® Hosted Account Service at https://backlogzero.ai, including this website, customer portal, downloads, licensing, billing, and related APIs. Our principal place of business is in the State of California, United States.
BacklogZero also includes a Software Bundle: self-hosted software you download and run in a Customer Environment you control. This Privacy Policy covers personal information Level Up Labs processes. It does not govern cookies, logs, or ticket/Git/playbook content that remain solely on infrastructure you operate, except where you transmit that material to us.
Privacy inquiries and requests should be directed to hello@leveluplabs.ai. Support: support@leveluplabs.ai.
2. Our Core Data Commitment
Level Up Labs is committed to privacy by design. Hosted Account Service data follows two distinct paths, described in our AI & Machine Learning Data Use Policy and in our Technical and Organizational Measures (TOMs) document (available upon request).
Path 1 (Service Delivery Data) includes Account Records and other account-linked data needed to provide the Hosted Account Service; this data is NOT anonymized and is personal data, handled as described in Sections 3 and 7 below. Path 2 (AI/ML Training Data) is a separately aggregated dataset derived from Hosted Account Service usage that is genuinely anonymized — aggregated across Customers and time periods sufficient to prevent attribution to any individual or Customer — before any use in training our AI/ML models, as described in Section 5 below.
The Software Bundle's local ITSM tickets, Git contents, playbooks, RAG indexes, and local inference payloads are not Path 1 or Path 2 unless you (or derived metadata) transmit them to the Hosted Account Service. We do not access Customer's raw code repositories as part of ordinary Hosted Account Service operation.
Separately, we collect limited personal information necessary to operate accounts, process payments, and communicate with you, as described below. That personal information, together with Path 1 Service Delivery Data, is kept distinct from the Path 2 anonymized dataset. Level Up Labs will never sell your personal information. Your identifiable personal information and Path 1 data are used only to operate, secure, and improve your experience using the Hosted Account Service; they are not used to train our AI/ML models, which are trained exclusively on the genuinely anonymized Path 2 dataset, as described in Section 5 below and in the AI & Machine Learning Data Use Policy.
3. Information We Collect
We collect the following categories of personal information in connection with the Hosted Account Service.
3.1 Account and registration information
When you create a Hosted Account Service account, we collect work email address and credentials (password, stored hashed locally or by Amazon Cognito when that identity provider is enabled). We do not collect GitHub account identifiers. Checkout, quotes, and related forms may also collect name and company or organization name.
3.2 Payment information
All card and Stripe-invoice transactions are handled by Stripe, Inc. We do not store full payment card numbers or sensitive financial data. We receive from Stripe limited information such as the last four digits of your card, card type, expiration date, billing name and address, transaction identifiers, and payment status, as further described in the Payment Processing Policy.
3.3 Usage and log data
We automatically collect certain technical information when you use the Hosted Account Service, including IP address and approximate geographic location (country/region); browser type and version and operating system; pages visited, features accessed, and timestamps; and error logs and diagnostic data from this website and portal. We do not currently operate a first-party analytics cookie on backlogzero.ai.
3.4 Account Records and Software Bundle data
Account Records are Path 1 Service Delivery Data. They include identity, organization membership, download and entitlement history, billing metadata we receive, support threads, and any diagnostics or operational metadata transmitted to that account. Account Records are account-linked, are NOT anonymized, and are personal information used to provide the Hosted Account Service.
A separate, genuinely anonymized Path 2 dataset derived from Hosted Account Service usage (including aggregated account and download workflow signals, with all direct and reasonably reversible identifiers removed) may be used to train and improve our AI/ML models, as described in Section 5 below and in the AI & Machine Learning Data Use Policy. Account Records and Software Bundle ticket, Git, and playbook content are never used for AI/ML training in non-anonymized form.
Software Bundle ITSM, Git, playbook, RAG, local LLM, and Crane Configuration-as-Code data remain in the Customer Environment unless you choose to send them (for example as support attachments). Optional cloud LLM providers you configure inside the Software Bundle (for example Anthropic or OpenAI) receive inference traffic under your credentials and those providers' terms; Level Up Labs does not receive those payloads unless you separately share them.
3.5 Communications
If you contact us for support or otherwise communicate with us, we retain records of those communications, including any personal information you voluntarily provide.
3.6 Cookies and tracking technologies
We use cookies and similar tracking technologies to operate the Hosted Account Service. Please see our Cookie Policy for details.
3.7 Contact form
If you use the public contact or demo-request form, we collect name, work email, company, and any notes you submit. Submissions may be stored in operational tools we use to respond.
3.8 Red Hat entitlement validation
If you request a validated co-term subscription, we collect Red Hat organization account identifiers, AAP contract identifiers, claimed managed-node counts, and anniversary dates that you provide, and we may contact Red Hat as you authorize, solely to validate and administer the BacklogZero subscription.
4. How We Use Your Information
We use the personal information we collect for the following purposes:
- To create and manage your account and provide the Hosted Account Service under our Terms of Service.
- To process payments and manage subscriptions through Stripe.
- To send transactional communications such as receipts, account notifications, download availability, and security alerts.
- To respond to support inquiries, contact-form submissions, and provide customer assistance.
- To validate AAP entitlement when you authorize contact with Red Hat.
- To send product updates, newsletters, or promotional content when you opt in at registration or on your account page (with your consent where required by law). You can change this setting at any time; it does not affect subscription-management messages.
- To monitor and analyze Hosted Account Service usage and performance to improve that service.
- To generate product recommendations for you based on your account-linked (Path 1) usage patterns, which you may opt out of at any time (see Section 5 below and our AI & Machine Learning Data Use Policy).
- To detect, investigate, and prevent fraudulent transactions, abuse, and security incidents.
- To comply with applicable legal obligations.
Legal bases under applicable law (including GDPR) include: contract performance (operating your account, processing payments, delivering downloads you are entitled to), legitimate interests (security, service improvement, Hosted Account Service personalization unless you opt out), legal obligation, and consent (marketing communications where required).
5. Anonymized Data for AI/ML Training
The genuinely anonymized Path 2 dataset derived from Customer use of the Hosted Account Service is used by Level Up Labs to train, test, evaluate, and improve the AI and machine learning models that underlie the Hosted Account Service and related BacklogZero capabilities. This use is a core and integral function of the Hosted Account Service. Path 1 Service Delivery Data, including Account Records, is not used for AI/ML training and is not within the scope of this Section. Use of the Software Bundle without creating a hosted account does not, by itself, contribute data to Path 2.
Because the Path 2 dataset is genuinely anonymized and does not constitute personal data under applicable privacy laws (including the GDPR, CCPA/CPRA, and similar frameworks), it is not subject to rights of access, deletion, portability, or opt-out that apply to personal data. There is no opt-out right with respect to our use of the Path 2 anonymized dataset for AI/ML training and testing.
Separately from Path 2 AI/ML training, Level Up Labs may use your organization's own Path 1 account-linked usage data — which is NOT anonymized — to generate product recommendations directed to your account (for example, suggesting features, download channels, or integrations that may benefit your team based on observed Hosted Account Service activity). Because this personalization feature uses account-linked personal data, you may opt out of it at any time by contacting hello@leveluplabs.ai, without affecting your ability to use the Hosted Account Service or our separate use of the Path 2 anonymized dataset for AI/ML training.
For full details of our anonymization standards and AI/ML data practices, please see our AI & Machine Learning Data Use Policy.
6. Sharing and Disclosure of Information
We do not sell your personal information. We may share your personal information in the following circumstances:
6.1 Service providers and sub-processors
We engage trusted third-party service providers to assist in operating the Hosted Account Service, including Amazon Web Services (cloud infrastructure, object storage for entitled downloads, and Amazon Cognito when enabled for identity), Google (contact-form delivery to a spreadsheet when that integration is configured, and YouTube embeds on marketing pages), and email or operational tools we use to respond to you. These providers are contractually obligated, where applicable, to process personal data only on our instructions and to maintain appropriate data protection standards.
6.2 Payment processor
Your payment information is shared with Stripe, Inc. as necessary to process transactions. Stripe's handling of payment data is governed by Stripe's own Privacy Policy.
6.3 Legal and regulatory requirements
We may disclose personal information where required by applicable law, regulation, legal process, or government request, or where necessary to enforce our Terms of Service, protect the rights, property, or safety of Level Up Labs, our users, or others.
6.4 Red Hat (co-term validation)
If you authorize it, we may share identifiers you provided with Red Hat solely to verify your organization's current Ansible Automation Platform subscription entitlement for administering your BacklogZero subscription.
6.5 Business transfers
In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, personal information may be transferred to the successor entity. We will provide prior notice of such transfer and the resulting changes to this Privacy Policy.
6.6 With your consent
We may share personal information for other purposes with your express consent.
7. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, and as required by applicable law. Our standard retention periods for Hosted Account Service data are:
- Account data: retained for the duration of your account, plus three (3) years after account closure.
- Account Records (Path 1 account-linked data): duration of account plus three (3) years, consistent with any DPA we execute.
- Usage and log data: ninety (90) days rolling.
- Billing records: seven (7) years as required by applicable tax law.
- Support and contact-form communications: three (3) years.
- Anonymized service data: retained as long as operationally necessary for the AI/ML systems that power the Hosted Account Service.
Software Bundle data that never left the Customer Environment is not retained by Level Up Labs. You may request earlier deletion of personal data we hold at any time, subject to legal retention requirements. Requests should be directed to hello@leveluplabs.ai.
8. Your Privacy Rights
Depending on your location, you may have certain rights with respect to your personal information. These may include:
- Access: Request a copy of personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information ("right to be forgotten"), subject to legal retention obligations.
- Portability: Receive your personal information in a portable, machine-readable format.
- Restriction: Request that we limit processing of your personal information.
- Objection: Object to processing based on legitimate interests.
- Non-discrimination: We will not discriminate against you for exercising your privacy rights.
Anonymized data, by its nature, cannot be attributed to you and is therefore not subject to the above rights.
To exercise any right, please contact us at hello@leveluplabs.ai. We will acknowledge your request within five (5) business days and respond within thirty (30) days (or up to forty-five (45) days where permitted by law). EU/UK/Swiss users may also lodge complaints with their local Data Protection Authority.
8.1 California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, use, disclose, or sell; the right to delete personal information; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of personal information. We do not sell personal information. The right to opt out does not apply to our use of the Path 2 anonymized dataset for AI/ML training, which does not constitute personal information under the CCPA/CPRA. We recognize the Global Privacy Control (GPC) signal as a valid opt-out preference signal for purposes of any sale or sharing of personal information under the CCPA/CPRA where applicable.
8.2 EEA and UK residents (GDPR)
Residents of the European Economic Area and United Kingdom have the rights described above under the General Data Protection Regulation (GDPR) and applicable national implementing legislation. Where we process personal data based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
8.3 Canada residents (PIPEDA / Québec Law 25)
If you are located in Canada, your personal information is also subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, if you are located in Québec, Québec's Law 25. In addition to the rights described above, you have the right to access and request correction of your personal information, and to file a complaint with the Office of the Privacy Commissioner of Canada or, for Québec residents, the Commission d'accès à l'information du Québec (CAI).
8.4 Brazil residents (LGPD)
If you are located in Brazil, your personal data is also subject to Brazil's Lei Geral de Proteção de Dados (LGPD). In addition to the rights described above, you have the right to confirmation of the existence of processing, information about the entities with which we have shared your data, and the right to request anonymization, blocking, or deletion of unnecessary or excessive data. You may also lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD).
8.5 Australia residents (Privacy Act 1988)
If you are located in Australia, your personal information is also subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). In addition to the rights described above, you have the right to request access to and correction of your personal information, and to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your personal information.
8.6 Switzerland residents (nFADP)
Residents of Switzerland have the rights described above under Switzerland's Federal Act on Data Protection (nFADP). Where we process personal data based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
9. International Data Transfers
Level Up Labs is based in the United States, and your personal information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
For transfers of personal data from the EEA or UK, we rely on appropriate safeguards, including (where Level Up Labs is self-certified) the EU-U.S. Data Privacy Framework and its UK extension, EU Standard Contractual Clauses (SCCs), and the UK International Data Transfer Agreement (IDTA), as applicable. For transfers of personal data from Switzerland, we rely on the EU Standard Contractual Clauses as recognized under Swiss law, the Swiss-U.S. Data Privacy Framework (where applicable), or other transfer mechanisms recognized under the Federal Act on Data Protection (nFADP). Level Up Labs's current Data Privacy Framework certification status, if any, is available at https://www.dataprivacyframework.gov. Copies of transfer safeguards are available upon request at hello@leveluplabs.ai.
10. Security
We implement and maintain appropriate technical and organizational measures designed to protect your personal information from unauthorized access, disclosure, alteration, or destruction, proportionate to the nature, scope, context, and purposes of our processing and the risks involved, as further described in our Technical and Organizational Security Measures (TOMs) document available upon request. Such measures are designed to address, as appropriate to the relevant risk profile:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256) for hosted systems we operate.
- Role-based access controls and the principle of least privilege.
- Authentication controls appropriate to the relevant system and risk profile; our key service providers, including our cloud infrastructure provider and payment processor, each maintain multi-factor authentication on their own platforms.
- Periodic vulnerability assessments commensurate with risk, maturing as the Hosted Account Service scales; periodic data protection and security awareness training for personnel with access to personal information.
- Incident response procedures and business continuity planning.
In the event of a personal data breach, we will notify affected users and relevant authorities within the timeframes required by applicable law (including within 72 hours under the GDPR where feasible).
You are responsible for securing the Software Bundle in the Customer Environment, including access control, backups, and any optional cloud LLM you enable.
11. Children's Privacy
The Hosted Account Service is not directed to individuals under the age of sixteen (16) in the EU/EEA, or under the age of thirteen (13) elsewhere. We do not knowingly collect personal information from children. Consistent with the CCPA/CPRA, we do not sell or share the personal information of California consumers we know to be under sixteen (16) years of age without opt-in consent (and, for consumers under thirteen (13), without verifiable parental consent); as noted above, we do not sell or share personal information in any event. If you believe we have inadvertently collected personal information from a minor, please contact us at hello@leveluplabs.ai and we will promptly delete it.
12. Third-Party Links and Services
The Hosted Account Service may contain links to third-party websites or integrate with third-party services, including Stripe, Red Hat, AWS Marketplace, optional Software Bundle LLM providers, and ITSM or Git systems you connect in the Customer Environment. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access.
13. Cookie Policy
We use cookies and similar technologies to operate the Hosted Account Service. For detailed information on our cookie practices, including how to manage your cookie preferences, please see our Cookie Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or prominent notice on this site at least thirty (30) days before the changes take effect. The updated Policy will be effective as of its stated effective date. Your continued use of the Hosted Account Service after the effective date constitutes your acceptance of the updated Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:
Level Up Technology LLC, d/b/a Level Up Labs
Privacy: hello@leveluplabs.ai
Support: support@leveluplabs.ai
21300 Victory Blvd, Third Floor
Woodland Hills, CA 91367
United States
Website: https://backlogzero.ai
Level Up Technology LLC d/b/a Level Up Labs. Privacy: hello@leveluplabs.ai. 21300 Victory Blvd, Third Floor, Woodland Hills, CA 91367, United States.