Linear AI

Does Linear AI train on your issues? No training by default, and its narrow scope means less of your business is exposed to it than to a general productivity tool.

Plain-English risk rating: 2 of 5

Linear's AI features are designed for software engineering workflows (issue triage, sprint planning, automated status updates, agent-assisted PR review). They inherit Linear's broader privacy and security posture. Linear maintains a no-training default with its AI subprocessors, holds SOC 2 Type II, and is GDPR-compliant. The risk picture is similar to Asana AI and Notion AI — dominated by the category-level prompt-injection risk for any AI with access to workspace content rather than Linear-specific concerns.

Linear's appeal for engineering-focused SMBs is its tight scope (issue tracking and sprint management rather than a general productivity workspace), which structurally limits the blast radius of any AI-feature compromise compared with a broader product like Notion or Microsoft 365 Copilot. The platform's user base skews toward software-engineering-first organisations, which means the security expectations are typically higher (and the patch tolerance lower) than for general-purpose SaaS — a useful tailwind for Linear's security posture.

Recommended for

  • Sole proprietor (engineering): Linear's free tier with light AI usage is acceptable. Standard at $10/user/month enables fuller AI features.
  • Small team (2-10 developers): Business at $14/user/month for advanced controls. Linear's focus on engineering workflows produces less collateral exposure than broader productivity tools.
  • Regulated industry: Enterprise tier with SAML SSO and audit logging. For US healthcare, evaluate Linear's BAA availability with your account team — it is not a default position.
  • The honest answer for most 1-10 employee software businesses: Linear AI is one of the lower-risk Embedded Productivity AI products in this database. Its narrow scope (engineering workflow) makes it structurally easier to reason about than a broader productivity workspace. For teams already on Linear, the AI features are a reasonable addition; for teams choosing between Linear, Jira/Atlassian Rovo, and GitHub Projects with Copilot, the decision is usually driven by feature preference and ecosystem commitment rather than privacy posture.

Critical pre-deployment warning (agentic PR-review capabilities)

Linear has progressively added agentic features that can comment on pull requests, assign issues, and update status fields autonomously. These features put Linear in the same agentic-AI category as Microsoft 365 Copilot and Salesforce Agentforce — the same prompt-injection class risk applies in principle. The mitigation pattern for engineering teams: scope agent permissions to specific projects rather than workspace-wide; treat agent-generated PR comments and status updates as suggestions requiring human acknowledgement rather than authoritative outputs; review the agent activity log weekly during initial deployment.

Data retention default

  • Standard Linear data lifecycle for AI feature output
  • Third-party AI subprocessors under Linear's contractual no-training arrangements
  • Zero data retention is required of AI subprocessors generally, not just at Enterprise. Linear’s AI Services Addendum requires its AI subprocessors to process Customer Data in a zero-data-retention manner where that is commercially available and technically supported by the subprocessor — so the ceiling is set by what each provider supports, not by which plan you are on. A previous version of this profile said 30-day provider retention on standard tiers with zero retention only at Enterprise. That was not supported; corrected 11 August 2026.
  • Agent activity logged for audit purposes

Training opt-out

NO TRAINING ON CUSTOMER DATA BY DEFAULT across plan tiers. Linear does not use customer data to train models; subprocessor agreements prohibit the same. This is the structurally-correct default for an engineering workflow tool where issue content frequently includes proprietary technical detail, internal architecture discussions, and security-relevant context.

Zero Data Retention availability

  • Required of AI subprocessors across the board by the AI Services Addendum, subject to the subprocessor technically supporting it. Not a paid upgrade, but also not an absolute guarantee — the qualifier is doing real work and you cannot tell from outside which providers meet it.

Plan tiers and pricing (as of early 2026)

TierPrice (USD)AI featuresSuitable for
Free$0Limited AIPersonal projects; small teams up to 10 users
Standard$10/user/monthStandard AI featuresSmall to mid-size engineering teams
Business$14/user/monthFull AI features + advanced controlsGrowing engineering orgs
EnterpriseCustomFull AI + SAML, audit, advanced securityLarger orgs with compliance requirements

Jurisdiction

  • Primary processor: Linear Orbit, Inc., San Francisco, California, USA
  • Cloud infrastructure: AWS
  • Third-party AI subprocessors: named on Linear’s trust center, which lists 32 subprocessors and is the authoritative source. We no longer name specific model providers here, because the Addendum lets Linear substitute models and providers at any time, so any list we print is a snapshot. Check the trust center for the current position.
  • SOC 2 Type II certified; GDPR-compliant; EU Data Residency available at Enterprise

Breach history (public incidents)

No major direct breach of Linear infrastructure publicly disclosed as of May 2026.

Note on category-level risk: Linear AI inherits the prompt-injection class of risk that affects any AI-with-workspace-access product. The narrower scope (issue tracking) reduces blast radius compared with broader productivity tools but does not eliminate the underlying class. Engineering teams should treat AI-generated issue content as potentially-influenced by content within issues from external contributors (especially relevant for public bug bounty programmes or external contractor workflows where issue content originates from outside the trusted team).

What this means in plain English for SMB owners

Three honest takeaways:

  1. Linear AI's narrow scope is a structural privacy advantage. Compared with broader productivity tools, an AI feature that operates only on engineering issues has less collateral exposure.
  1. The no-training default plus standard SOC 2 certification makes Linear AI a reasonable choice for engineering teams that already use Linear. No separate AI add-on cost; features bundle into existing tiers.
  1. For engineering teams handling proprietary code, the Business or Enterprise tier is the right floor. The marginal cost over Standard is small ($4/user/month difference), the additional controls are meaningful, and the audit logging is useful for any team that needs to demonstrate AI-feature governance. The agentic PR-review features are useful productivity additions but benefit from explicit configuration of agent permissions and human review of agent-suggested actions.

The AI terms are a separate contract

Since 9 June 2026 Linear’s AI features are governed by a dedicated AI Services Addendum, not the general terms. It is worth knowing because it is unusually specific, and mostly in the customer’s favour:

  • Your prompts and outputs are your Confidential Information and you retain ownership of them.
  • No training, stated twice over: Linear will not use your data to train its own models, and its agreements with third-party providers require the same of them.
  • Opt-outs stick. If you disable an AI feature through admin controls, Linear will not re-enable it unless you do, or authorise it in writing. That is a better term than most vendors offer and it is worth having in writing.
  • IP indemnity for outputs, capped at the greater of US$3 million or five times your fees. Rare at this end of the market — though it carries ten separate carve-outs, and does not cover claims arising from your prompts.
  • But: Linear disclaims all liability for bias or discrimination in output. If you are using AI features anywhere near hiring, performance or customer treatment, that risk is entirely yours.
  • The models can change at any time, at Linear’s sole discretion. If your AI policy names approved providers, this product will quietly fall out of step with it.
  • The AUP flows through to subprocessors: your use must also comply with each AI subprocessor’s own acceptable use policy, and where they conflict, the more restrictive one applies. So your obligations can tighten because a company you have no contract with changed its rules. The AUP also defines High-Risk Use Cases — legal interpretation or decisions, medical diagnosis or treatment — which are restricted.

Watch the billing, not just the data

This is a cost-control point rather than a leakage one, but it is new and it can bite a small business. Some AI features are now Metered AI Services billed in Credits, pooled per workspace, and drawn down by any authorised user — so one person can spend the team’s balance. Three terms deserve attention before you enable them:

  • Auto-recharge is a standing authority to charge your card whenever the balance falls below a threshold you set. Linear is not obliged to notify you of individual transactions.
  • Your balance can go negative. Linear may allow an overage to finish a task in progress, and if it is not cleared within 60 days it may charge your card for the outstanding amount.
  • Credits expire and are forfeited. Purchased credits last twelve months; entitlement credits do not roll over between subscription years or across plan changes; and all unused credits are irrevocably forfeited if the workspace is deleted or the agreement ends.

None of that is unusual for metered AI, and Linear documents it clearly. But if you enable metered features, set the auto-recharge threshold deliberately and check the credit ledger — which Linear makes available to admins in real time — rather than discovering the pattern on a card statement.

Sources

  • Linear AI Services Addendum: https://linear.app/legal/ai-addendum (effective 9 June 2026; verified 2026-08-11) – the governing document for AI features.
  • Linear Acceptable Use Policy: https://linear.app/legal/aup (verified 2026-08-11) – defines High-Risk Use Cases and the subprocessor flow-through.
  • Linear security documentation: https://linear.app/security (verified 2026-08-11)
  • Linear Trust Center subprocessor list: https://trust.linear.app/subprocessors (32 subprocessors listed; verified 2026-08-11)
  • Linear AI feature documentation
  • Linear Trust Center for current certifications and subprocessor list
  • General Embedded Productivity AI category analysis

Related on AI Leakage