Levr

Levr and Qinetic Privacy Policy

Effective date: 21 July 2026 Last updated: 21 July 2026

This Privacy Policy explains how BitModern, Inc. ("BitModern", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with Levr and Qinetic (together, the "Services"), the levr.one website, and related applications, APIs, MCP interfaces, CLIs, and integrations.

Capitalized terms not defined here have the meaning given in the Terms of Service.

In short:


1. Our two roles

The Services handle two different categories of data, and our role differs for each.

a) Account and website data — we are the controller. Information about you as a visitor, prospect, account holder, or billing contact: your name, email, company, plan, support conversations, and how you use the Services. We decide how this is processed and this Policy governs it.

b) Customer Data — we are a processor. The content that you, your Users, and your Agents put into a Workspace: issues, requirements, acceptance criteria, plans, tests, runs and results, comments, attachments, repository and code context, agent transcripts and traces, agent configuration, and prompts. Customer Data may contain personal information about your own employees, customers, or third parties. Your organization is the controller of that data. We process it only on your organization's instructions, as set out in the Terms of Service and any data processing addendum ("DPA") between us.

If you are an individual whose personal information appears in a customer's Workspace, please direct your privacy requests to that organization; we will support them in responding.


2. Information we collect

2.1 Information you give us

CategoryExamplesWhy
AccountName, email address, password hash, profile image, workspace and team names, roleCreate and secure your account
OrganizationCompany name, team size, industry, roleProvision your Workspace, support, and account management
BillingBilling contact, billing address, tax identifiers, plan and subscription details, last four digits and card brandProcess subscriptions and comply with tax and accounting law
Support and salesMessages, tickets, early-access requests, survey and demo-request responsesRespond to you, provide support
Marketing preferencesNewsletter opt-in statusSend communications you asked for
Customer DataEverything you or your Agents submit to a Workspace (see Section 1(b))Provide the Services on your instructions

We do not collect payment card numbers. Payments are processed by our payment processor; card data goes to them directly.

2.2 Information we collect automatically

2.3 Information from third parties


3. How we use information

We use personal information to:

  1. Provide the Services — create and administer accounts and Workspaces, authenticate users, execute the operations you and your Agents request, run integrations, and store your work.
  2. Secure the Services — detect and prevent fraud, abuse, credential compromise, and attacks; enforce rate limits and tenancy isolation; maintain audit and attribution trails.
  3. Support you — respond to requests, diagnose problems, and communicate about incidents and changes.
  4. Bill and administer — process subscriptions, meter plan usage, collect fees, and meet tax and accounting obligations.
  5. Improve the Services — analyze aggregated, de-identified usage and performance data to fix defects, plan capacity, and prioritize features. This does not include training models on Customer Data (Section 4).
  6. Communicate — send service, security, and administrative messages (which you cannot opt out of while you have an account), and marketing messages where you have opted in or as otherwise permitted, with an unsubscribe link in every marketing email.
  7. Comply with law — respond to lawful requests, establish or defend legal claims, and enforce our Terms.

Legal bases (EEA/UK). We rely on: performance of a contract (1, 3, 4); legitimate interests in operating, securing, and improving a business service (2, 5, 6, and business outreach); consent (marketing emails where required, non-essential cookies); and legal obligation (4, 7).


4. We do not train models on your data

We do not use Customer Data to train, fine-tune, or otherwise improve any machine-learning model, whether ours or a third party's. We contractually require the model providers we engage to process Customer Data on a no-training, no-retention-beyond-processing basis.

When you connect your own Agent or harness — for example Claude Code, Codex, or Cursor — that tool communicates with its own model provider under your agreement with them. Those providers' data practices are outside our control. Review their terms before connecting them to a Workspace containing sensitive material.

Qinetic's self-improvement features analyze your Workspace's own history to improve your Workspace's agents, routing, and configuration. Nothing learned in your Workspace is transferred to another customer's Workspace or into a shared model.

We may derive aggregated, de-identified statistics — for example, "median issue cycle time across all workspaces" or "p95 API latency" — to operate, secure, and improve the Services. These contain no personal information and nothing identifying you, your Users, or your projects, and we do not attempt to re-identify them.


5. How we disclose information

We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose it only as follows.

5.1 Service providers (sub-processors)

We engage vendors who process data on our behalf under written contracts that restrict them to our instructions and require appropriate safeguards. Current categories:

CategoryPurpose
Cloud infrastructure and hostingRun the Services and store data
Database, cache, and analytics data storesOperate the application and reporting
AI and model providersPower AI features you invoke, on a no-training basis
Payment processingSubscriptions and invoicing
Email and messaging deliveryTransactional and, where opted in, marketing email
Error monitoring and observabilityDiagnose defects and outages
Product analyticsUnderstand feature usage
Bot and abuse protectionProtect public forms and endpoints

A current list of named sub-processors — each one's name, purpose, and location — is maintained at [Sub-processors](https://levr.one/subprocessors). We give at least ten (10) days' notice before a new sub-processor begins processing customer personal data; subscribe to that notice at privacy@bitmodern.com. Objection and termination rights are set out in Section 6 of the Data Processing Addendum.

5.2 At your direction

We disclose Customer Data to Connected Services and Agents you configure, in the scope you authorize. You control these connections and can revoke them.

5.3 Within your Workspace

Content you or your Agents submit is visible to other Users of your Workspace according to its permission settings, and Workspace administrators can access, export, and delete it. Activity is attributed to the human or Agent that performed it.

5.4 Legal and safety

We may disclose information if required by law, subpoena, or other lawful request, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of BitModern, our customers, or the public, or to investigate fraud or a security incident. Where lawful and practicable, we will notify the affected customer before disclosing Customer Data and will seek to narrow or challenge overbroad requests.

5.5 Corporate transactions

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to continuing protection under a policy no less protective than this one. We will notify you of any change in control affecting your personal information.


6. International transfers

We are based in the United States and process data there and in other countries where our sub-processors operate. If you are in the EEA, UK, or Switzerland, your information may be transferred outside your jurisdiction. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) together with supplementary technical and organizational measures. These are set out in our Data Processing Addendum, which applies automatically without signature. For a countersigned copy, contact privacy@bitmodern.com.


7. Retention

You may request deletion at any time under Section 10. We will honor it except to the narrow extent retention is required by law, or is necessary to resolve a dispute or enforce our agreements — and then only for that purpose and duration.


8. Cookies and similar technologies

We use:

Marketing site (levr.one). Our marketing site uses optional analytics and behaviour-analytics tools, including heatmaps of how visitors interact with a page. How they behave depends on where you are:

Either way you can change your choice at any time using the Cookie preferences link in the site footer, and rejecting or opting out has no effect on your use of the site. Your choice is remembered for 12 months, after which we ask again. We store it in your browser's local storage rather than in a cookie, so it stays on your device and is not transmitted to us. See Sub-processors for the tools involved.

Levr and Qinetic applications. The applications themselves set no analytics or advertising cookies. Product analytics within the applications operate on usage events and pseudonymous identifiers rather than on tracking cookies.

We do not use advertising cookies and we do not permit cross-site tracking for advertising purposes. Most browsers let you block or delete cookies. We honor Global Privacy Control (GPC) signals where applicable law requires.


9. Security

We maintain administrative, physical, and technical safeguards appropriate to the risk, including encryption in transit, encryption at rest for stored data, tenancy isolation enforced at the data layer, role-based access control, least-privilege internal access, credential rotation, logging and monitoring, and vendor security review.

No system is completely secure. You are responsible for securing your side: strong credentials and MFA, careful scoping of Agent permissions and API tokens, prompt revocation of access for departing Users, and considered choices about what data you allow Agents and Connected Services to reach.

If we become aware of a breach affecting your personal information, we will notify you without undue delay and as required by law.


10. Your rights and choices

Depending on where you live, you may have the right to:

To exercise a right, email privacy@bitmodern.com or use the in-product account settings. We will verify your identity before acting and will respond within the time required by applicable law (generally 30 days under GDPR, 45 days under the CCPA/CPRA, extendable where permitted). An authorized agent may submit a request on your behalf with proof of authorization.

If your data is in a customer's Workspace, we will refer your request to that organization, which controls the data, and support them in responding.

EEA/UK residents may lodge a complaint with their supervisory authority. California residents: we have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve months, and we do not knowingly collect or sell the personal information of minors under 16. The categories we collect, our purposes, and our disclosures are described in Sections 2, 3, and 5.


11. Children

The Services are business tools intended for users 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@bitmodern.com and we will delete it.


12. Third-party sites and services

The Services link to and integrate with third-party sites and products, including Connected Services and model and agent providers. This Policy does not cover their practices. Review their privacy policies before connecting them or sharing data with them.


13. Changes to this Policy

We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, provide at least thirty (30) days' notice by email to the address associated with your account or by prominent notice in the Services before the change takes effect. Continued use after the effective date constitutes acceptance.


14. Contact us

BitModern, Inc. 8921 Northlake Hills Drive Jonestown, Texas 78645, USA

See also Terms of Service, Data Processing Addendum and Sub-processors. Questions? Email legal@bitmodern.com.