Appearance
Data and privacy
What is sent to the model
The diff of the files in a pull request, after exclusions — nothing else. Specifically:
- added, removed, and surrounding context lines of each changed file, as GitHub provides them;
- the file paths those changes belong to;
- the pull request's title and description.
What is not sent: files you did not change, files matched by an exclude pattern, files GitHub gives no diff for, your repository history, issues, or secrets stored in GitHub.
EasyMerge never clones your repository. The one thing that reads outside a pull request diff is the project status scan, which you start by hand and which uses no model at all.
TIP
The reliable way to keep something away from the model is an exclude pattern. An excluded file is never read and its contents are never stored.
Which model
An Anthropic Claude model by default; DeepSeek is the supported alternative. Ask your EasyMerge administrator which one handles your code.
The project status scan
Project status is the only feature that looks outside a pull request, and it runs only when someone presses Scan project.
On the repository's status branch it reads the file and folder listing, and the contents of a fixed set of documentation and configuration files — README files, dependency manifests and lockfiles, test and tooling configuration, CI workflows, deployment files. The full list is on the guide page.
Your application source is never read. Nor are files that look like secrets: .env files, .pem, .key, .p12 and id_rsa are never fetched, even though a committed .env file is noticed in the listing and reported.
None of this reaches the model. The one thing that leaves EasyMerge is the name and version of each dependency found in a manifest or lockfile, which is looked up in a public vulnerability database to see whether a published advisory covers it. No file contents, no repository name and no code are sent with that lookup.
What is stored
| Data | Notes |
|---|---|
| Pull request metadata | Repository, PR number, title, description, author, branches |
| Diffs and commits | Processed in memory only; never persisted to the database |
| Findings | File, line range, severity, comment body, suggestion |
| Skipped files | Path and skip reason; no content |
| Project status results | The status, its signals, the commit scanned, and the paths of the files inspected and skipped — no file contents |
| Your display mode | Developer or Builder, against your own account |
| Your GitHub access token | Stored encrypted |
| Support tickets | Subject, description, category, every message on the ticket, and the repository or review it was filed against |
| Support attachments | The files you attach to a ticket or a reply, kept with the message. A file you upload but never send is deleted after 24 hours |
Findings are also posted to GitHub as review comments, where they follow your repository's own retention and visibility rules.
A support ticket is what you type into it, so keep secrets out of it: the form says so, and so does the attachment field. Everyone linked to the installation can read the ticket and download its files, and so can the EasyMerge support team. Attachments are checked for malware before they can be sent; a file that fails is refused and never reaches the ticket.
Who can see it
Only people who have signed in and whom GitHub reports as having access to the installation. GitHub decides this, not EasyMerge, and it is re-checked every time someone opens the dashboard. Losing access on GitHub means losing access in the dashboard.
Within an installation, admins and members see the same reviews; the difference is that only admins may change settings, and only admins may change other people's roles. Being made an admin grants no extra visibility into code or reviews.
Deleting your data
Uninstalling the GitHub App on GitHub is the way to delete your data. It stops all reviews for that account immediately, revokes EasyMerge's access to your code, and removes everything stored for that installation — its repositories, pull requests, reviews, findings, project status results, and its support tickets with their attachments. The dashboard will no longer show them.
Removing a single repository from the installation is not a deletion. It disappears from the dashboard along with its reviews, but its pull requests, reviews, findings and project status results are kept, and reappear if you add the repository back. Uninstall the app to delete them.
Review comments already posted to your pull requests belong to your repository, and are not removed. Delete them on GitHub if you want them gone.
Data retention
We automatically delete review findings and project-status metadata based on your configured Data retention (days) setting (for example, after 30 days). We maintain a strictly zero-retention policy for your source code: pull request diffs are processed entirely in memory and are never saved to our database. See Organization settings.
Permissions EasyMerge holds
Read access to code, and write access limited to pull request comments and check runs. It cannot push commits, create or delete branches, change settings, or merge anything. See Install the GitHub App for the full list.