Legal · Effective 2026-06-01 · v2026-06-01
AI & Machine Learning Data Use Policy
Effective Date: June 1, 2026
1. Overview and Scope
This AI & Machine Learning Data Use Policy ("AI Policy") describes how Level Up Labs (a DBA of Level Up Technology LLC) uses data in connection with the artificial intelligence and machine learning systems that underlie the Factimonious platform (the "Service"). This AI Policy is incorporated by reference into the Factimonious Terms of Service and Privacy Policy and should be read in conjunction with those documents.
Factimonious is a software engineering intelligence platform that analyzes AI-assisted code repository activity, semantic code changes, and software engineering signals to generate trustworthy daily standups, grounded weekly retrospectives, and verifiable codebase confidence metrics. The quality, accuracy, and trustworthiness of these outputs depend on the ongoing training and evaluation of our AI/ML models using anonymized data derived from Service usage.
This AI Policy applies to all users and Customers of the Service, globally.
2. Two-Path Data Architecture
Factimonious data follows two distinct paths, described in detail in Section 10 of our Technical and Organisational Measures (TOMs) document. Path 1 – Service Delivery Data: data needed to deliver the Service to a specific Customer account, including Session Results (the engineering-activity analysis, standups, retrospectives, and confidence metrics generated for that account), is retained on an account-linked basis, is NOT anonymized, and is personal data governed by our Privacy Policy and Data Processing Agreement (DPA). Path 2 – AI/ML Training Data: a separate, aggregated dataset is subjected to genuine anonymization – aggregation across Customers and time periods sufficient to prevent attribution to any individual or Customer, with all direct and reasonably reversible identifiers removed – before any use in training, testing, or evaluating our AI/ML models. This AI Policy governs only Path 2 data; Path 1 data is addressed in the Privacy Policy and DPA.
Path 2 anonymized data – data from which all direct and reasonably reversible identifiers have been removed and which cannot reasonably be re-linked to an individual or a specific Customer – is not personal data under applicable privacy laws, including the GDPR, CCPA/CPRA, and similar frameworks. Path 1 Service Delivery Data, including Session Results, IS personal data, is not anonymized, and is not within the scope of this AI Policy’s anonymization commitments.
3. What Data Is Used for AI/ML
The following categories of anonymized data may be used to train, test, evaluate, benchmark, and improve the AI and machine learning models that power the Service:
Anonymized code activity signals derived from Customer-authorized repository integrations (e.g., commit frequency, file change patterns, branch activity — with all identifiers removed);
Anonymized semantic code change indicators derived from repository activity (structural and syntactic patterns only, not code content);
Anonymized software engineering workflow signals (e.g., pull request lifecycle patterns, review cadence, merge frequency — with no attribution to individuals);
Anonymized interaction and usage data (feature engagement patterns, report generation frequency, session metadata);
Aggregated performance signals used to evaluate model output quality.
We do NOT use the following for AI/ML training under any circumstances:
Non-anonymized code content or repository data;
Individual user identifiers, names, or email addresses;
Payment or billing information;
Authentication credentials or secrets;
Any data marked as confidential or sensitive by the Customer.
4. How Anonymized Data Is Used
Anonymized data is used for the following AI/ML purposes:
Training and fine-tuning the underlying models that generate daily standup summaries, weekly retrospective reports, and codebase confidence scores;
Evaluating model accuracy, relevance, and trustworthiness;
Detecting and mitigating model bias, safety issues, or quality regressions;
Benchmarking model performance across diverse engineering environments;
Developing and testing new AI-powered features and capabilities;
Generating aggregate benchmark insights that compare a Customer’s engineering signals against broader, cross-Customer industry benchmarks, where the benchmark dataset is genuinely anonymized under Path 2 and no individual Customer or account is identifiable in, or re-derivable from, the comparison set.
Legal basis (Path 2 only): Because data used for AI/ML training and the benchmark insights described above is genuinely anonymized under Path 2 and does not constitute personal data, it is not subject to legal basis requirements under the GDPR, CCPA/CPRA, or similar frameworks. Our use of such data is consistent with Article 5(1)(b) of the GDPR (further processing for compatible purposes) and GDPR Recital 26 (anonymized data is outside scope). The same anonymization-based analysis applies under other comparable frameworks, including Canada's PIPEDA, Brazil's LGPD (Article 12), Australia's Privacy Act 1988, and Switzerland's nFADP, each of which similarly excludes properly anonymized data from personal-data obligations.
Personalization Features (Path 1 Account Data)
Separately from the Path 2 AI/ML training uses described above, Level Up Labs uses a Customer’s own Path 1 Service Delivery Data – including that Customer’s Session Results and account-linked usage patterns, which are NOT anonymized – to generate product recommendations directed to that specific Customer account (for example, suggesting features, integrations, or configuration options that may benefit that Customer based on its own observed activity). Because this feature operates on account-linked personal data, it is governed by the Privacy Policy and DPA rather than this AI Policy’s anonymized-data provisions. Legal basis: legitimate interest in improving the Service for the Customer and, where applicable, performance of the contract with the Customer (GDPR Art. 6(1)(b) and (f)); a comparable basis applies under CCPA/CPRA and other frameworks. Customers and authorized users may opt out of this personalization feature at any time through account settings or by contacting factimoniousprivacy@factimonious.ai, as described in the Privacy Policy; opting out does not affect Path 2 AI/ML training, which remains governed by Section 5 below.
5. No Opt-Out for Path 2 Anonymized Data Use
Because the use of genuinely anonymized Path 2 data for AI/ML training and testing is a core and non-severable function of the Service – essential to maintaining the accuracy, trustworthiness, and improvement of Service Outputs – there is no right to opt out of this Path 2 use. This no-opt-out rule does NOT apply to the Path 1 personalization feature described in Section 4 above, which Customers and authorized users may opt out of as described there and in the Privacy Policy.
This is a deliberate design choice. The commitment Level Up Labs makes in return is strict: Path 2 AI/ML training is conducted exclusively on genuinely anonymized, aggregated information, and that anonymized dataset is never re-linked to an individual or a specific Customer account.
This approach differs from AI/ML training practices that involve personal or identifiable data, which would require separate consent and are not a practice of Level Up Labs with respect to Path 2 training. Customers who require a zero-Path-2-training environment that is technically incompatible with the Service’s architecture should not use the Service; Customers may, however, opt out of the Path 1 personalization feature in Section 4 without affecting their ability to use the Service.
6. What We Never Do
Level Up Labs makes the following firm commitments:
We will never use non-anonymized Customer Data for AI/ML training;
We will never sell anonymized data to third parties for AI training;
We will never use Customer data to train models that are made available to other Customers in a manner that could expose Customer-specific information;
We will never use AI/ML data practices beyond those described here without updating this AI Policy and providing advance notice;
We will never retaliate or degrade Service quality based on a Customer's use of any applicable privacy right.
7. Anonymization Standards
Level Up Labs applies rigorous anonymization standards to all data used for AI/ML purposes:
All direct identifiers (names, email addresses, user IDs, account numbers) are removed or replaced with non-reversible tokens prior to any AI/ML use;
Repository and code metadata is processed to remove strings, variable names, comments, or other content that could identify an individual or organization;
Aggregation thresholds are applied to ensure that no dataset used for training can be traced to a single user or Customer account;
Anonymization processes are reviewed against the "reasonably likely to re-identify" standard consistent with GDPR Recital 26 and applicable guidance;
Internal access to pre-anonymization data is restricted to authorized personnel under the principle of least privilege.
8. AI Model Governance
Level Up Labs maintains internal AI governance practices to ensure responsible use of AI in the Service, including:
Model evaluation and quality review prior to production deployment;
Ongoing monitoring of model outputs for accuracy, relevance, and potential bias;
Human review capabilities for flagged outputs;
Documentation of training data sources, model versions, and evaluation results;
An internal assessment of Level Up Labs’s role (e.g., provider or deployer) and risk classification under the EU AI Act (Regulation (EU) 2024/1689), including consideration of whether the Service or any of its AI components falls within a high-risk category under Annex III, with corresponding transparency, documentation, and human-oversight measures implemented where applicable; this assessment is reviewed periodically as guidance and case law develop and is cross-referenced in Terms of Service Section 7 (AI-Generated Outputs).
9. Service Outputs and Reliability
Service Outputs — including daily standup summaries, weekly retrospective reports, and codebase confidence scores — are generated by AI systems and are provided for informational and productivity purposes. Level Up Labs does not warrant that Service Outputs are complete, error-free, or a substitute for professional engineering judgment.
Customers are responsible for reviewing, validating, and making decisions based on Service Outputs. Level Up Labs is not liable for actions taken in reliance on Service Outputs without appropriate human review.
10. Changes to This Policy
We may update this AI Policy as our AI/ML practices evolve, regulatory requirements change, or we introduce new features. If we make material changes, we will notify you via email or in-app notice at least thirty (30) days before the changes take effect.
11. Contact
Questions regarding this AI Policy should be directed to:
Privacy Team: factimoniousprivacy@factimonious.ai
Website: https://factimonious.ai
Contact: factimoniousprivacy@factimonious.ai