This Policy explains how Level Software, Inc. (“Level,” “we,” “us,” or “our”) handles information that identifies or can reasonably be linked to a person or household (“Personal Information”). It applies to Level’s websites, accounts, endpoint-management platform, support, events, sales, communications, and AI features. A third-party service or integration may have its own notice.
Level designs and markets the Services for businesses and professionals but permits personal home-lab use on devices the user owns or is authorized to manage. The Services are not directed to children or marketed as a family monitoring product.
1. Level’s Privacy Roles
Level generally acts as a controller or “business” for information used to operate its website and company, administer accounts, bill customers, communicate, prevent fraud and abuse, secure the Services, and improve products.
Level generally acts as a processor or “service provider” for Customer Content, endpoint information, scripts, logs, remote-management information, and other data processed under a customer’s instructions. The customer decides why and how to use Level and is responsible for its notices, permissions, and lawful basis. Individuals whose information is managed through a customer’s account should usually contact that customer first.
Level may act as a controller for proportionate processing needed to protect Level and the wider Services, evaluate account risk, investigate cross-account threats, enforce policies, and comply with law. Level does not use customer-controlled Endpoint information for unrelated advertising.
Data Processing Addenda for internal IT teams and MSPs are available through support@level.io.
2. Information We Process
The information depends on the product, configuration, Endpoint, and interaction.
Accounts, billing, and communications
Level may process names, business contact details, company and job information, profile images, account identifiers, workspace membership, roles, permissions, authentication and login records, preferences, subscription and transaction history, invoices, tax information, refunds, and payment status. Our payment processor handles full payment-card details; Level generally receives limited card information such as brand, expiration, and last four digits.
Level also processes emails, chats, tickets, call notes, meeting information, support files, surveys, and feedback. Level provides notice and obtains consent where required before recording a call or meeting. If a user requests SMS alerts, Level processes the phone number, consent, configuration, delivery records, and messages needed to provide them. Level does not share mobile opt-in information for another party’s marketing.
Website and network activity
Level may process IP address, approximate location derived from IP, browser, operating system, device type, language, referring page, pages and features used, links selected, timestamps, session duration, performance data, cookie or local-storage identifiers, and security signals.
Endpoint and product activity
Depending on configuration, Level may process:
- Endpoint identifiers, hostnames, serial numbers, architecture, operating system, network information, tags, enrollment, hardware, storage, memory, software, services, processes, patches, and system state.
- Alerts, health and performance data, event and error records, availability, users, and account information available from the Endpoint.
- Scripts, commands, automations, monitors, inputs, outputs, exit codes, logs, execution history, and remediation results.
- File names, paths, directory information, registry or configuration values, and other information a customer chooses to access.
- Remote-session connection, approval, file-transfer, and audit metadata, plus screen, clipboard, keystroke, or file content transmitted when an authorized user interacts with it.
Level stores device and account metadata, operational records, and customer-uploaded software packages. Level does not make a general archive of the documents, photos, mailboxes, or disk images stored on managed devices. Remote-session content may pass through the Service when used but is distinct from the activity and connection logs Level retains.
APIs, integrations, and AI
Level may process API and token metadata, service-account identity and scopes, requests, responses, errors, source address, rate limits, integration configuration, and actions submitted through the API, CLI, integrations, workflows, or agents.
When a customer uses an AI feature, Level may process prompts, instructions, files, outputs, relevant Customer Content, approvals, edits, execution and feedback records, and safety or diagnostic information. Level may use aggregated or de-identified information and feedback to improve the Services. Level does not use Customer Content to train a generally available model unless Customer expressly opts in.
Other sources
Level may receive information from a user’s employer, administrator, or MSP; payment, identity, referral, resale, integration, fraud-prevention, and security providers; public business sources; and people who communicate with Level.
3. Why We Use Information
Level uses Personal Information to:
- Provide, configure, maintain, secure, and support the Services and carry out customer instructions.
- Administer accounts, permissions, subscriptions, payments, taxes, credits, and refunds.
- Monitor reliability, performance, capacity, and errors.
- Detect and investigate fraud, abuse, compromise, unauthorized access, and policy violations.
- Provide support, communications, AI features, and permitted marketing.
- Analyze and improve products, documentation, and customer experience.
- Comply with law, protect rights and safety, enforce agreements, and handle corporate transactions.
Level may use automated rules, risk scoring, cross-account signals, reports, and staff review for security and abuse prevention. Level does not ordinarily make a material account-level enforcement decision based only on one shared identifier or relationship. Where safety and law permit, a customer may request human review and restoration under the Abuse and Restricted Use Policy.
Where law requires a legal basis, Level relies on contract, legitimate interests, legal obligation, or consent as appropriate. A customer determines the legal basis when Level acts only as its processor.
4. How We Disclose Information
Information in a workspace may be visible to its owner, administrators, MSP, and authorized users according to customer-controlled permissions.
Level uses providers for infrastructure, payments, analytics, communications, support, security, and AI. The current providers, their roles, update history, and notice-subscription instructions are in the Subprocessor Registry. A Data Processing Addendum may provide additional notice and objection rights.
Level also discloses information:
- To an integration, webhook, model, or other recipient a customer enables or directs.
- To affiliates, insurers, auditors, attorneys, accountants, and advisers with appropriate duties.
- When reasonably necessary to comply with law, enforce agreements, investigate security or abuse, or protect rights, property, or safety.
- In a proposed or completed merger, financing, reorganization, bankruptcy, or sale, subject to applicable law and continuing commitments.
Level evaluates government requests for legal authority, jurisdiction, and scope, limits disclosure to responsive information, and, where legally permitted and reasonable, challenges requests it believes are invalid, unlawful, or materially overbroad. Level notifies the affected customer before disclosure where legally permitted, subject to emergencies, security needs, investigations, and temporary legal prohibitions.
Level does not maintain a government or law-enforcement backdoor into Customer Endpoints. A request for stored information does not create endpoint control. A request to modify software or create a new access capability would receive separate legal and security review.
5. Advertising, Cookies, and Choices
Level does not sell Personal Information for money. On the marketing website, analytics and advertising technologies may disclose IP address, cookie or device identifier, browser information, page URL, referrer, and interaction data to providers such as Segment, PostHog, Google, and Reddit. Depending on law and provider role, this may be considered sale, sharing for cross-context behavioral advertising, or targeted advertising.
Level may use cookies, pixels, local storage, and similar technologies to keep users signed in, remember preferences, secure the Services, measure traffic and performance, understand use, and evaluate campaigns. Where law requires consent, Level asks before loading non-essential analytics or advertising technologies and provides a way to accept or reject them. Withdrawing or rejecting consent does not disable technologies strictly necessary to provide or secure the site.
An individual may submit an applicable sale, sharing, or targeted-advertising opt-out request to support@level.io. Browser controls may also manage cookies, although blocking some technologies may affect functionality.
6. Retention and Security
Level keeps information only as long as reasonably needed for the purposes above, including service delivery, billing and tax duties, security, support, dispute resolution, and legal compliance. The period depends on the category, customer configuration, contract, and law.
Customer Content is handled after cancellation under the Cancellation Policy and applicable Data Processing Addendum. Security, audit, API, support, billing, and abuse-prevention records may remain as needed for their purpose. Marketing information remains until opt-out or it is no longer needed, subject to a suppression record. Encrypted backups are isolated from ordinary use and overwritten in Level’s normal backup cycle unless preservation is required. Level may retain aggregated or de-identified information that cannot reasonably identify a customer, person, or Endpoint.
Level uses administrative, technical, and physical safeguards designed to protect Personal Information. Data is encrypted in transit using TLS. Data at rest in Level-managed systems is encrypted at the host and storage layers, including production databases, server storage, and database backups. Highly sensitive database contents receive an additional encryption layer. No safeguard is perfect.
Level personnel may access customer-controlled information only when reasonably needed for requested support, security, fraud and abuse prevention, maintenance, or law, subject to appropriate role restrictions, confidentiality, and logging.
This access applies to information stored in Level systems. It does not create standing remote or administrative access to Customer Endpoints. Access to Level-hosted infrastructure, databases, logs, or customer metadata does not authorize and does not ordinarily enable Level personnel to initiate remote control, open a shell or terminal, execute scripts, browse or access files, or otherwise administer an Endpoint.
When troubleshooting requires interaction with an Endpoint, the customer ordinarily must explicitly grant temporary support access. That authorization is limited in scope and duration, automatically expires, and permits Level personnel to act only through the authorized customer account and the Services.
Level will provide reasonable notice if it introduces functionality that gives Level personnel standing administrative access to Customer Endpoints. Such functionality would be a material change to Level’s security model. If notice is legally prohibited, Level will provide it as soon as that prohibition ends.
7. International Transfers
Level is based in the United States, and information may be processed in the United States and countries where Level or its providers operate. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, Level uses an adequacy decision, the European Commission’s Standard Contractual Clauses, the United Kingdom transfer addendum, or another recognized mechanism, with supplementary measures where required.
8. Individual Rights
Depending on location and law, an individual may have rights to know, access, correct, delete, or obtain a copy of Personal Information; restrict or object to processing; opt out of certain sale, sharing, targeted advertising, or profiling; withdraw consent; appeal a denial; and complain to an authority. Level will not unlawfully discriminate for exercising a right.
Requests may be submitted through account controls, support@level.io, or the address below. Level verifies requests appropriately. An authorized agent may submit a request where law permits. If Level processes information only for a customer, Level may direct the request to that customer and assist it.
Residents of United States states with comprehensive privacy laws can use these methods for applicable rights. The information categories Level processes include identifiers and contacts; commercial records; internet, network, device, and application activity; approximate geolocation; professional information; support communications; inferences used for security or improvement; and credentials or other legally sensitive information. Level does not knowingly use sensitive Personal Information for a purpose that requires a California right to limit, except as directed by the responsible customer.
Individuals in the EEA or United Kingdom may also contact their local supervisory authority. Level’s AI features assist IT operators and are not intended to make solely automated employment, credit, health, housing, education, or similar high-impact decisions about individuals.
9. Children and Communications
The Services are not directed to people under 18, and Level does not knowingly collect their Personal Information directly for its own purposes. A customer managing a device used by a minor, such as a school device, is responsible for authority, notices, consent, and configuration.
Users may unsubscribe from marketing email using the link in the message or by contacting Level. Level may still send necessary service, security, billing, and legal communications.
10. Changes and Contact
Level may update this Policy and will post the new effective date. We will provide additional notice before a material change when law requires it and request consent when required for a new use.
Questions, complaints, and requests may be sent to:
Level Software, Inc.
Attn: Privacy
60 Ravenscroft Drive
Asheville, NC 28801 USA
Email: support@level.io