Levr and Qinetic Privacy Policy
Effective date: 21 July 2026 Last updated: 21 July 2026
This Privacy Policy explains how BitModern, Inc. ("BitModern", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with Levr and Qinetic (together, the "Services"), the levr.one website, and related applications, APIs, MCP interfaces, CLIs, and integrations.
Capitalized terms not defined here have the meaning given in the Terms of Service.
In short:
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- We do not use your Customer Data to train, fine-tune, or improve any machine-learning model — ours or a third party's.
- You own your Customer Data. You can export it and delete it.
1. Our two roles
The Services handle two different categories of data, and our role differs for each.
a) Account and website data — we are the controller. Information about you as a visitor, prospect, account holder, or billing contact: your name, email, company, plan, support conversations, and how you use the Services. We decide how this is processed and this Policy governs it.
b) Customer Data — we are a processor. The content that you, your Users, and your Agents put into a Workspace: issues, requirements, acceptance criteria, plans, tests, runs and results, comments, attachments, repository and code context, agent transcripts and traces, agent configuration, and prompts. Customer Data may contain personal information about your own employees, customers, or third parties. Your organization is the controller of that data. We process it only on your organization's instructions, as set out in the Terms of Service and any data processing addendum ("DPA") between us.
If you are an individual whose personal information appears in a customer's Workspace, please direct your privacy requests to that organization; we will support them in responding.
2. Information we collect
2.1 Information you give us
| Category | Examples | Why |
|---|---|---|
| Account | Name, email address, password hash, profile image, workspace and team names, role | Create and secure your account |
| Organization | Company name, team size, industry, role | Provision your Workspace, support, and account management |
| Billing | Billing contact, billing address, tax identifiers, plan and subscription details, last four digits and card brand | Process subscriptions and comply with tax and accounting law |
| Support and sales | Messages, tickets, early-access requests, survey and demo-request responses | Respond to you, provide support |
| Marketing preferences | Newsletter opt-in status | Send communications you asked for |
| Customer Data | Everything you or your Agents submit to a Workspace (see Section 1(b)) | Provide the Services on your instructions |
We do not collect payment card numbers. Payments are processed by our payment processor; card data goes to them directly.
2.2 Information we collect automatically
- Authentication and device data — IP address, browser and device type, operating system, session and device identifiers, timestamps of sign-in and sign-out, and OAuth or SSO provider identifiers.
- Usage and product telemetry — pages and features used, API and MCP calls, request volumes, latency and error rates, job and worker outcomes, and which Agent or human performed an action.
- Agent and integration telemetry — which Agent or harness connected, model and token usage, run durations, and outcomes, so we can meter plans and operate the Services.
- Diagnostics — logs, crash reports, and stack traces.
- Cookies and similar technologies — see Section 8.
2.3 Information from third parties
- Identity providers — if you sign in with GitHub, Google, or another SSO provider, we receive your name, email address, and account identifier from them.
- Connected Services — if you connect GitHub, Jira/Atlassian, Slack, a CI provider, or another integration, we receive data from it within the scope you authorize.
- Bot and abuse protection — we use reCAPTCHA on public forms such as sign-up. reCAPTCHA collects hardware and software information and sends it to Google for analysis. Its use is subject to the Google Privacy Policy and Google Terms of Service.
- Business contact sources — limited publicly available or vendor-supplied business contact information used for sales outreach, where permitted by law.
3. How we use information
We use personal information to:
- Provide the Services — create and administer accounts and Workspaces, authenticate users, execute the operations you and your Agents request, run integrations, and store your work.
- Secure the Services — detect and prevent fraud, abuse, credential compromise, and attacks; enforce rate limits and tenancy isolation; maintain audit and attribution trails.
- Support you — respond to requests, diagnose problems, and communicate about incidents and changes.
- Bill and administer — process subscriptions, meter plan usage, collect fees, and meet tax and accounting obligations.
- Improve the Services — analyze aggregated, de-identified usage and performance data to fix defects, plan capacity, and prioritize features. This does not include training models on Customer Data (Section 4).
- Communicate — send service, security, and administrative messages (which you cannot opt out of while you have an account), and marketing messages where you have opted in or as otherwise permitted, with an unsubscribe link in every marketing email.
- Comply with law — respond to lawful requests, establish or defend legal claims, and enforce our Terms.
Legal bases (EEA/UK). We rely on: performance of a contract (1, 3, 4); legitimate interests in operating, securing, and improving a business service (2, 5, 6, and business outreach); consent (marketing emails where required, non-essential cookies); and legal obligation (4, 7).
4. We do not train models on your data
We do not use Customer Data to train, fine-tune, or otherwise improve any machine-learning model, whether ours or a third party's. We contractually require the model providers we engage to process Customer Data on a no-training, no-retention-beyond-processing basis.
When you connect your own Agent or harness — for example Claude Code, Codex, or Cursor — that tool communicates with its own model provider under your agreement with them. Those providers' data practices are outside our control. Review their terms before connecting them to a Workspace containing sensitive material.
Qinetic's self-improvement features analyze your Workspace's own history to improve your Workspace's agents, routing, and configuration. Nothing learned in your Workspace is transferred to another customer's Workspace or into a shared model.
We may derive aggregated, de-identified statistics — for example, "median issue cycle time across all workspaces" or "p95 API latency" — to operate, secure, and improve the Services. These contain no personal information and nothing identifying you, your Users, or your projects, and we do not attempt to re-identify them.
5. How we disclose information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose it only as follows.
5.1 Service providers (sub-processors)
We engage vendors who process data on our behalf under written contracts that restrict them to our instructions and require appropriate safeguards. Current categories:
| Category | Purpose |
|---|---|
| Cloud infrastructure and hosting | Run the Services and store data |
| Database, cache, and analytics data stores | Operate the application and reporting |
| AI and model providers | Power AI features you invoke, on a no-training basis |
| Payment processing | Subscriptions and invoicing |
| Email and messaging delivery | Transactional and, where opted in, marketing email |
| Error monitoring and observability | Diagnose defects and outages |
| Product analytics | Understand feature usage |
| Bot and abuse protection | Protect public forms and endpoints |
A current list of named sub-processors — each one's name, purpose, and location — is maintained at [Sub-processors](https://levr.one/subprocessors). We give at least ten (10) days' notice before a new sub-processor begins processing customer personal data; subscribe to that notice at privacy@bitmodern.com. Objection and termination rights are set out in Section 6 of the Data Processing Addendum.
5.2 At your direction
We disclose Customer Data to Connected Services and Agents you configure, in the scope you authorize. You control these connections and can revoke them.
5.3 Within your Workspace
Content you or your Agents submit is visible to other Users of your Workspace according to its permission settings, and Workspace administrators can access, export, and delete it. Activity is attributed to the human or Agent that performed it.
5.4 Legal and safety
We may disclose information if required by law, subpoena, or other lawful request, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of BitModern, our customers, or the public, or to investigate fraud or a security incident. Where lawful and practicable, we will notify the affected customer before disclosing Customer Data and will seek to narrow or challenge overbroad requests.
5.5 Corporate transactions
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to continuing protection under a policy no less protective than this one. We will notify you of any change in control affecting your personal information.
6. International transfers
We are based in the United States and process data there and in other countries where our sub-processors operate. If you are in the EEA, UK, or Switzerland, your information may be transferred outside your jurisdiction. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) together with supplementary technical and organizational measures. These are set out in our Data Processing Addendum, which applies automatically without signature. For a countersigned copy, contact privacy@bitmodern.com.
7. Retention
- Customer Data — if you ask us to delete it: deletion begins without undue delay and is complete in active systems within seven (7) days. There is no waiting period. Export before deleting — deletion is irreversible.
- Customer Data — on termination you did not initiate (lapsed subscription, termination for breach, withdrawal of a Beta Service): retained for thirty (30) days so you can export it, then deleted. You can end that window early by requesting immediate deletion.
- Backups: deleted data is purged from backups on our standard rotation, within thirty-five (35) days of deletion from active systems.
- Account and billing records — retained while your account is active and afterwards for as long as needed to meet legal, tax, accounting, and dispute-resolution obligations (typically up to seven years for financial records).
- Security and audit logs — retained for a limited period appropriate to detecting and investigating incidents.
- Marketing contacts — retained until you unsubscribe or ask us to delete them.
You may request deletion at any time under Section 10. We will honor it except to the narrow extent retention is required by law, or is necessary to resolve a dispute or enforce our agreements — and then only for that purpose and duration.
8. Cookies and similar technologies
We use:
- Strictly necessary — authentication, session management, security, load balancing, CSRF protection, and bot protection on public forms. These cannot be disabled; blocking them will break sign-in.
- Preferences — remember settings such as theme and language.
- Analytics — understand aggregate feature usage and performance.
Marketing site (levr.one). Our marketing site uses optional analytics and behaviour-analytics tools, including heatmaps of how visitors interact with a page. How they behave depends on where you are:
- In the EEA, the UK, and Switzerland, they are off by default and load only after you accept them.
- Elsewhere, they are on by default and you are told on your first visit, with opt-out available immediately.
Either way you can change your choice at any time using the Cookie preferences link in the site footer, and rejecting or opting out has no effect on your use of the site. Your choice is remembered for 12 months, after which we ask again. We store it in your browser's local storage rather than in a cookie, so it stays on your device and is not transmitted to us. See Sub-processors for the tools involved.
Levr and Qinetic applications. The applications themselves set no analytics or advertising cookies. Product analytics within the applications operate on usage events and pseudonymous identifiers rather than on tracking cookies.
We do not use advertising cookies and we do not permit cross-site tracking for advertising purposes. Most browsers let you block or delete cookies. We honor Global Privacy Control (GPC) signals where applicable law requires.
9. Security
We maintain administrative, physical, and technical safeguards appropriate to the risk, including encryption in transit, encryption at rest for stored data, tenancy isolation enforced at the data layer, role-based access control, least-privilege internal access, credential rotation, logging and monitoring, and vendor security review.
No system is completely secure. You are responsible for securing your side: strong credentials and MFA, careful scoping of Agent permissions and API tokens, prompt revocation of access for departing Users, and considered choices about what data you allow Agents and Connected Services to reach.
If we become aware of a breach affecting your personal information, we will notify you without undue delay and as required by law.
10. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information;
- port your information to another provider;
- object to or restrict certain processing;
- withdraw consent at any time, without affecting prior processing;
- opt out of sale or sharing — we do neither; and
- be free from discrimination for exercising these rights.
To exercise a right, email privacy@bitmodern.com or use the in-product account settings. We will verify your identity before acting and will respond within the time required by applicable law (generally 30 days under GDPR, 45 days under the CCPA/CPRA, extendable where permitted). An authorized agent may submit a request on your behalf with proof of authorization.
If your data is in a customer's Workspace, we will refer your request to that organization, which controls the data, and support them in responding.
EEA/UK residents may lodge a complaint with their supervisory authority. California residents: we have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve months, and we do not knowingly collect or sell the personal information of minors under 16. The categories we collect, our purposes, and our disclosures are described in Sections 2, 3, and 5.
11. Children
The Services are business tools intended for users 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@bitmodern.com and we will delete it.
12. Third-party sites and services
The Services link to and integrate with third-party sites and products, including Connected Services and model and agent providers. This Policy does not cover their practices. Review their privacy policies before connecting them or sharing data with them.
13. Changes to this Policy
We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, provide at least thirty (30) days' notice by email to the address associated with your account or by prominent notice in the Services before the change takes effect. Continued use after the effective date constitutes acceptance.
14. Contact us
BitModern, Inc. 8921 Northlake Hills Drive Jonestown, Texas 78645, USA
- Privacy requests and questions: privacy@bitmodern.com
- Security: security@bitmodern.com
- General support: support@bitmodern.com
- Legal notices: legal@bitmodern.com
See also Terms of Service, Data Processing Addendum and Sub-processors. Questions? Email legal@bitmodern.com.
