Appearance
Security & Code Privacy Policy
Effective 4 October 2026.
EasyMerge is designed to review pull-request changes, not to copy your entire repository. This policy describes the current scope; Data and privacy records the data stored by the product in more detail.
What EasyMerge reads and sends
For an AI review, EasyMerge sends the model:
- added, removed and surrounding context lines in the diff GitHub provides;
- the corresponding file paths; and
- the pull request's title and description.
EasyMerge does not clone your repository or read unchanged files, repository history, issues or GitHub secrets. A file matching an exclude pattern is neither read nor stored. Binary, oversized and undiffable files are not reviewed either.
Anthropic Claude is the default model and DeepSeek is a supported alternative. Your EasyMerge administrator may choose the model. Do not place a secret in a diff on the assumption that a tool will detect or redact it.
Project status is separate
Project status runs only when a user selects Scan project. It reads the file structure and a fixed list of documentation and configuration files on the status branch; it does not read application source or send file contents to the model. Dependency names and versions can be checked against a public vulnerability database, without file contents or repository name. See what Project status reads.
GitHub permissions and access limits
The GitHub App has read access to code and write access limited to pull-request comments and check runs. It cannot push commits, create or delete branches, change settings or merge pull requests. Your GitHub access token is stored encrypted.
GitHub determines dashboard access, which is checked again when the dashboard opens. Once GitHub no longer gives you access, you can no longer access that installation in EasyMerge.
Storage, display and deletion
EasyMerge processes pull request diffs entirely in memory and never saves them to its database. It stores findings and metadata needed to display a review in the dashboard; some review comments are also posted to GitHub. Installation deletion, data retention and support-attachment handling are described in the Privacy Policy and Data and privacy.
No security control eliminates all risk. Use exclude patterns for files you do not want included in a review, apply least-privilege GitHub access, and revoke or uninstall the app when you no longer use it.
Reporting a security incident
To report suspected unauthorised access, code exposure or a vulnerability, follow the vulnerability disclosure process. Do not put secrets or an exploit payload in an ordinary support ticket.