Appearance
Personal Data Protection & Privacy Policy
Effective 4 October 2026.
This policy explains the personal and GitHub-account data EasyMerge processes while providing the service. It applies when you install the GitHub App, sign in, access a dashboard, receive a review, configure repositories or contact support. Data and privacy contains the detailed technical description.
Data we process
EasyMerge processes data needed to authenticate users, operate the GitHub App, show reviews and support you. That can include:
| Category | Examples | Purpose |
|---|---|---|
| GitHub account data | display name, username, email where GitHub provides it, installation permissions | sign-in and access control |
| Pull-request data | repository, PR number, title, description, author, branches | performing and showing a review. Diffs and commits are processed in memory only and are never persisted to our database |
| Service results | findings, comments, skipped files and project-status results | showing review history and context |
| Support data | ticket messages, replies, attachments and repository/review context | answering and resolving support requests |
| Configuration data | organisation and repository settings, display mode | applying your choices |
We do not ask you to send passwords, access tokens or other secrets in support tickets. Do not include them in a message or attachment.
We process only the information needed to operate the service and the features you enable. The exact information available to EasyMerge depends on the GitHub App permissions, the repositories selected during installation, your GitHub role and the actions you take in the service. We do not intentionally collect special-category personal data, and you should avoid including it in pull requests, support tickets or attachments.
How we use data
We use data to provide reviews; authenticate and authorise users; maintain the service's security and reliability; support you; and comply with legal obligations where applicable. We do not use your repository content for a purpose unrelated to providing EasyMerge.
The diff is sent to the model selected for the installation to create a review. Anthropic Claude is the default and DeepSeek is a supported alternative. The Security & Code Privacy Policy sets out exactly what may leave GitHub.
We operate a zero-retention policy for your source code. Pull request diffs are sent directly to the model provider via API, processed in memory to generate the review, and are not saved in our database.
We may also process limited technical information, such as timestamps, browser or device characteristics, log entries, error reports and actions taken in the service. We use this information to diagnose faults, prevent abuse, investigate security incidents, measure performance and improve the reliability and usability of EasyMerge.
We do not sell repository content or personal data. We do not use repository content to advertise to you or to train a general-purpose model for an unrelated purpose. We use it only to operate, maintain, secure and improve the EasyMerge features you choose to use.
Who can see data
Within an installation, signed-in people whom GitHub says still have access can see installation data according to their role. The EasyMerge support team may access data needed to operate the service and answer tickets. Everyone linked to an installation may view and download that installation's support tickets and attachments.
Review comments posted to GitHub are subject to your repository's own GitHub retention and visibility rules. GitHub and model providers process data under their own applicable terms and policies when delivering their part of the service.
We share data with service providers only where needed to provide EasyMerge, such as GitHub for the GitHub App integration, the model provider selected for a review, hosting and infrastructure providers, and providers that help us operate support or security functions. Those providers are permitted to process data only for their role in providing the relevant service and under their applicable agreements and policies.
We may disclose information if we reasonably believe disclosure is necessary to comply with applicable law, enforce our terms, respond to a valid legal request, protect the rights or safety of EasyMerge, users or the public, or investigate fraud or a security incident.
Retention and deletion
An attachment uploaded but never sent is deleted after 24 hours. To delete an installation's data, uninstall the GitHub App on GitHub. That stops reviews, revokes access and removes the installation data EasyMerge stores: repositories, reviews, findings, project-status results, support tickets and their attachments.
Removing one repository from an installation is not deletion; its data can reappear if you add the repository again. Comments posted on GitHub are not removed automatically. We automatically delete review findings and project-status metadata based on your configured Data retention (days) setting (for example, after 30 days). We maintain a strictly zero-retention policy for your source code: pull request diffs are processed entirely in memory and are never saved to our database. See the full retention explanation.
Deletion from EasyMerge does not delete information independently stored by GitHub, a model provider, your organisation or another third party. For example, review comments posted to GitHub remain subject to your repository's GitHub retention and visibility settings. Backups may retain limited data for a short period before being overwritten as part of normal disaster-recovery processes.
We may retain information longer where needed to meet a legal obligation, resolve a dispute, enforce an agreement, prevent abuse or protect the security of the service. When retention is no longer necessary for one of these purposes, we will delete or anonymise the information in accordance with our operational processes.
Security
We use reasonable technical and organisational measures designed to protect data against unauthorised access, alteration, disclosure and loss. These measures include access controls, authentication checks, monitoring and processes for investigating security issues. No internet service or storage system can be guaranteed completely secure, and you should maintain your own security controls and backups.
You are responsible for protecting your GitHub account, managing repository permissions and selecting only repositories that you are authorised to connect. If you suspect unauthorised access to an installation or support ticket, contact us through Help & Support promptly. Security vulnerabilities should be reported through the vulnerability disclosure process.
International processing
EasyMerge and its providers may process data in countries other than the country where you live or work. Those countries may have data-protection laws that differ from the laws in your jurisdiction. Where we transfer personal data, we will use appropriate safeguards required by applicable law.
Your rights and requests
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection or a copy of your personal data. To begin a request, create an Account or Other ticket in Help & Support, naming the installation, GitHub account and request. We may need to verify your authority before acting.
We will consider requests in accordance with applicable law. Your rights may be limited in some circumstances, for example when fulfilling a request would reveal another person's information, interfere with a legal obligation or affect the security of the service. If we cannot fulfil a request, we will explain the reason where the law requires us to do so.
If you are acting for an organisation, make sure that you are authorised to make the request for the relevant installation. We may ask for information to verify your identity and authority before making changes, disclosing information or deleting data.
Policy changes
For a material policy change, we will update the effective date and notify you on this page or in the app. We encourage you to review this policy periodically. Your continued use of EasyMerge after the updated policy takes effect means that you acknowledge the updated policy.
If your organisation has a separate data-processing agreement with us, that agreement takes priority where it conflicts with this policy. The Terms of Service also apply to your use of EasyMerge.