Public register · legal record
Privacy Policy
Last updated June 2026. This policy describes how MergeAttest handles customer data for teams governing AI-assisted pull requests on GitHub.
What we process
MergeAttest stores organization membership, connected repository metadata, pull request metadata, changed file paths, risk signals, rule violations, approvals, review notes, AI review job metadata, repository AI settings, audit events, billing identifiers, and usage records needed to operate the product.
We do not need to store full source file contents for the current workflow. AI review guardrails may process GitHub pull request diffs during processing, but integrations should remain scoped to metadata unless a customer explicitly opts in to broader retention.
Credentials and secrets
OpenRouter API keys and similar customer-provided credentials are encrypted before storage. Webhook secrets, API keys, billing identifiers, and generated audit exports must not appear in diagnostics, review packets, or application logs.
Third-party sub-processors
MergeAttest relies on a small set of service providers to operate. Each receives only the data needed for its function:
- GitHub — the source of pull request metadata; MergeAttest connects as a GitHub App scoped to the repositories you authorize.
- Vercel — application hosting and cookieless web analytics for public pages.
- Resend — delivery of transactional email (sign-in, verification, and team invitations).
- OpenRouter — used only if you connect your own key for the advisory AI review layer. Model execution stays off during early access, so no diff is sent to OpenRouter unless you enable it.
- Lemon Squeezy — payment and subscription processing. It is dormant during the free early-access launch and stores only billing identifiers when paid plans are enabled.
- A managed PostgreSQL database provider — durable storage for the organization, governance, and audit data described above.
Retention
Audit event retention depends on your plan. During the free early-access launch, audit history is retained for seven days unless your plan specifies otherwise. Usage records and billing identifiers may be kept longer to support billing disputes, compliance reviews, and support obligations.
Cookies, analytics, and tracking
MergeAttest uses Vercel Web Analytics on public marketing pages to understand aggregate traffic patterns. It does not set tracking cookies or build cross-site advertising profiles, so no cookie consent banner is required. Authentication uses a first-party session cookie that is strictly necessary to keep you signed in. Product telemetry is limited to operational logging required to run the service securely.
Your choices and data requests
You can export audit evidence and compliance reports from the product at any time, and disconnect the GitHub App to stop further processing. To request access to, correction of, or deletion of your workspace data, contact support using the address below; we will respond within a reasonable period.
Contact
For privacy questions or data requests, contact the support mailbox configured for your deployment or email support@mergeattest.com.