Privacy notice
This notice explains which personal data Mergelay processes, why, on what legal basis, who receives it and how long it is kept. It covers the website, the product and the emails Mergelay sends. It is written in English; the operator is French and a French version is available on request.
EffectiveWho is responsible
The controller is Alexis Wychowaniak EI (entrepreneur individuel — sole trader under French law), 180 B rue de Charenton, 75012 Paris, France, SIREN 907 906 085, contact hello@mergelay.com. The full publisher identity is on the legal notice. No data protection officer is appointed: Mergelay does not meet any of the three conditions of art. 37(1) GDPR. The address above is the privacy contact.
Mergelay is the controller for accounts, authentication, billing status, support, security and optional analytics. For the content a customer connects or uploads — repository data, drafts, contact lists, delivery recipients — the customer is the controller and Mergelay is its processor. Those roles, instructions and safeguards are set out in the data processing agreement.
Data we process
- Account and workspace. Email address, display name, verification state, password hash or the identifier returned by Google, GitHub or Microsoft sign-in, workspace name and slug, membership role.
- Session records. Every signed-in session stores your IP address and user agent alongside the session token, for the life of the session. Sign-in and sign-up rate limits are keyed on the client IP address, and the API logs the request method, a redacted URL and the calling address.
- Repository content. Metadata for the merged pull requests and releases you select, and sanitised diffs. Before anything reaches the model provider, email addresses are replaced with
[REDACTED_EMAIL], credentials and high-entropy tokens with[REDACTED], and sensitive paths and file types are excluded. The model provider is Anthropic. A self-hosted deployment may instead point at an OpenAI-compatible gateway; none is configured in the hosted product today. - Contact lists and delivery recipients. A customer can import accounts with contact names and email addresses, and configure email digest recipients. Delivery records keep the recipient address, the provider message id and the send time. This is third-party personal data provided by the customer; Mergelay acts as its processor — see the DPA.
- Drafts, approvals and audit. Update titles, summaries, draft bodies, revisions, who approved what and when, and an append-only audit trail with the acting user identifier and model token counts.
- Connected credentials. Webhook URLs, GitHub connection data, and social posting credentials — OAuth access and refresh tokens, or a Bluesky app password. These are stored encrypted (AES-256-GCM) and deleted when you remove the destination.
- Billing status. The Polar customer and subscription identifiers, plan, interval and X credit balance. Mergelay never receives your card details. Polar’s webhooks carry your customer record; Mergelay reads only the workspace link and stores only Polar’s customer and subscription identifiers — see “Recipients” below.
- Support. Whatever you write to us by email.
Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Creating and running your account and workspace; analysing selected changes; generating, storing and publishing approved Updates; sending transactional email | Performance of the contract, art. 6(1)(b) |
| Keeping the service secure and available: session records with IP address and user agent, rate limiting, abuse and fraud prevention, audit trail, backups | Legitimate interests, art. 6(1)(f) — our interest in protecting accounts from takeover, keeping a single-tenant-per-workspace boundary intact, and being able to reconstruct who approved a publication |
| Support, and answering questions about an account or an invoice | Performance of the contract, art. 6(1)(b); legitimate interests, art. 6(1)(f), for people who write to us without an account |
| Optional product and page analytics | Consent, art. 6(1)(a) — refused by default, withdrawable at any time without affecting the lawfulness of prior processing |
| Keeping accounting and tax records | Legal obligation, art. 6(1)(c) — art. L. 123-22 of the French commercial code |
| Processing repository content, contact lists and delivery recipients for a customer | On the customer’s documented instructions, art. 28 — the customer determines the basis in its own notice |
We do not sell personal data, do not use repository content for advertising, and do not use customer content to train models.
Recipients
Sub-processors process data on our instructions and under art. 28 contracts. The versioned list, with each provider’s location, purpose and transfer mechanism, is published at /subprocessors and changes there with 30 days’ notice.
| Sub-processor | What it receives |
|---|---|
| Vercel Inc. | Web hosting: all web requests, IP addresses, request logs |
| Railway Corporation | API compute, PostgreSQL and the workspace file store: identity records and all workspace content |
| Plus Five Five, Inc. (Resend) | Email delivery: recipient address, subject and body, including verification, reset and review-link emails |
| Anthropic | Redacted repository patches and metadata, product context, draft text |
| PostHog, Inc. (EU Cloud) | Optional product analytics only, after consent: a pseudonymous user:<uuid> identifier and allow-listed event names and low-cardinality properties |
| GitHub, Inc. | Repository reads and webhook intake for the repositories you connect, through the Mergelay GitHub App |
Independent controllers decide their own purposes; their own notices apply and we cannot act on your behalf with them.
| Recipient | Why |
|---|---|
| Polar Software, Inc. | Merchant of record. It collects your name, email and payment instrument on its own checkout; Mergelay sends it only the workspace identifier and the plan metadata, and stores back only its customer and subscription identifiers. Polar is the controller for payment, invoicing, tax and fraud data. |
| Google, GitHub, Microsoft | Sign-in, when you choose to use them |
| Google Ads | Optional advertising attribution and conversion measurement, only after you allow analytics. Google receives the Ads click attribution and the confirmed workspace or subscription event, not repository or draft content. |
| Slack, Microsoft Teams, your own automation endpoint, X, LinkedIn, Bluesky, your Mastodon instance | Destinations you configure and approve. Content goes there on your instruction, under that network’s or endpoint’s own terms. |
Social publishing
Nothing is ever posted without an explicit approval decision, and that decision is never automatic: it is made by a person, in Mergelay or through a one-time review link, or by an agent the workspace explicitly authorises with an operator-scope access token, for which the customer is responsible. Once a post is approved, the consequences belong to the network, not to Mergelay:
- A published post is public and permanent on that network, indexable and freely redistributable by third parties. Mergelay has no unpublish, retract or delete function for any network. Removal must be done in the network’s own interface, and copies already made by others cannot be recalled.
- Posting credentials are stored encrypted and removed when you disconnect the destination. For X, Mergelay also asks X to revoke the stored token as a best effort before removing the destination; for every other network, disconnecting removes the credential from Mergelay without revoking it at the provider. Revoke the app in the network’s own settings as well. A Bluesky app password is a full-account credential — treat it like one and rotate it in Bluesky after disconnecting.
- A post may contain names, handles or pull-request titles taken from the change. Review the exact text before approving.
- The link to the change is attached only for public repositories, so a private repository’s identity is not disclosed to a public timeline.
- The connected network’s own terms and privacy notice apply to you and to the post.
Review links and public asset URLs
The “Update ready to review” email can carry a one-time review link. That link is a credential: whoever holds it can read the drafts and approve them without signing in. It works once, expires after 72 hours, and is visible to the web tier’s request logs, the hosting platform’s logs and the reader’s browser history. It is never included in the automation webhook. Do not forward the email.
A logo uploaded as a brand asset is served from an unauthenticated, immutable URL so that email clients can render it. The URL is derived from the file contents; anyone holding it can fetch the image. Do not upload an image you would not publish.
Cookies
| Cookie | Purpose | Lifetime |
|---|---|---|
__Secure-mergelay.session_token | Strictly necessary. Keeps you signed in. HttpOnly, Secure, SameSite=Lax. Named mergelay.session_token on a local http deployment. | 30 days, renewed daily while you use the product |
mergelay.analytics-consent | Records your optional-analytics choice. Its value is only the policy version and granted or denied. | 180 days |
mergelay.acquisition | Optional, and created only after consent. Links the campaign or referring site that brought you to later setup, Update and subscription events. It contains a random first-party visitor id, normalized UTM dimensions, the landing route and the advertising network when a click parameter is present. Raw advertising click ids are never stored. | 30 days |
Google Ads first-party conversion cookies (for example _gcl_*) | Optional, and available to the Google tag only after consent. Stores the ad click identifier needed to attribute a confirmed workspace or subscription to the campaign that brought you to Mergelay. | Up to 90 days |
The session and consent-choice cookies are exempt from consent under the CNIL’s guidelines — one authenticates you, the other stores your refusal. The acquisition cookie is not: it is written only after you allow analytics and removed when you withdraw that choice. Session storage prevents duplicate conversion events until the tab closes. PostHog’s own persistence stays disabled and Vercel Web Analytics remains cookieless. The Google Ads tag and its conversion cookies are completely blocked before consent and are used only for campaign attribution and confirmed conversions. No repository content, draft text or session replay is sent.
Optional analytics
If product analytics is configured, Mergelay uses PostHog Cloud EU to understand which campaign or referring site leads to signup, setup, a first Update, checkout and an active subscription, and whether core actions succeed or fail. If page analytics is configured, Mergelay uses Vercel Web Analytics for page views. If Google Ads measurement is configured, its site-wide tag attributes an ad click to two confirmed outcomes: a new workspace and an active paid subscription. All three stay off until you allow them, and refusing changes nothing about the product.
Events and properties are limited by server-side allow-lists and string values are truncated. Before signup, the identifier is the random visitor id from the first-party attribution cookie; after authentication it is joined to user:<uuid>, never your email address. Query strings and fragments are stripped and dynamic path segments normalised before a PostHog or Vercel event leaves the browser, so a review-link URL can never become a page view. Server-side captures disable IP-based geolocation. The consented Google Ads tag can read its own ad-click identifier and receives a conversion name, value, currency and query-free page path. Repository names, pull-request titles, source code, diffs, draft text, email addresses, recipients, webhook URLs, secrets and raw error messages are never sent to any analytics provider.
How long we keep data
| Data | Retention |
|---|---|
| Session record, with IP address and user agent | 30 days; revoked immediately on password reset |
| Email verification and password reset links | 1 hour |
| One-time review links | 72 hours, single use |
| OAuth and app-installation states | 10 minutes |
| Workspace content: analyses, drafts, approvals, deliveries, imported contacts, audit trail, brand assets | For the life of the workspace. There is no automatic expiry today; deletion is the way these are removed. |
| Backups — workspace file store | Railway volume backups of mergelay-api-volume, on a daily, weekly and monthly schedule since 30 August 2026, retained by Railway for 6 days, 1 month and 3 months respectively. A backup restores only inside the same Railway project and environment; no copy is held off the platform. |
| Backups — identity database | Accounts, sessions and sign-in records live in a Railway-managed PostgreSQL database on its own volume, covered by the same Railway volume backup schedule as the row above: daily, weekly and monthly, retained 6 days, 1 month and 3 months. There is no point-in-time recovery. |
| Accounting and tax records | 10 years, art. L. 123-22 of the French commercial code |
| Optional analytics events | PostHog’s retention for the EU project; no longer than 25 months |
| Optional acquisition attribution | 30 days in the first-party cookie; duplicate-event keys until the tab closes |
| Google Ads conversion attribution | First-party conversion cookies for up to 90 days; conversion records follow the retention configured in the Mergelay Google Ads account |
Backups are never selectively edited. Both regimes are the same Railway mechanism, so one outer bound covers the scheduled copies: a deleted workspace can persist in them for up to three months, the retention of the monthly copy, before the last copy containing it expires. That bound does not cover a manual backup taken outside the schedule: Railway attaches no expiry to one, so it is retained until the operator deletes it. Two manual backups exist today, one per volume, both taken on 30 August 2026 when the schedules were put in place; they will be deleted once a full cycle of scheduled backups has run, and this notice will be updated when they are.
Deletion and export
Being straightforward about this: there is no self-serve delete or export button yet. Email hello@mergelay.com from the address on the account and we will delete or export the workspace manually, within 30 days of your request, then confirm in writing. That 30-day window is our response time to a request; the separate windows that run from termination of the contract — export on request within 30 days, deletion within 60 days — are in the Terms and the DPA. Scheduled backups expire on the retention above, and a deleted workspace can persist in them for up to three months, plus the two manual backups of 30 August 2026, which are retained until the operator deletes them. You can remove a connected repository, a destination or a brand asset yourself at any time. Content already delivered to Slack, an email recipient or a social network must be removed with that provider — Mergelay cannot retract it. A self-serve deletion and export flow is on the roadmap; this notice will be updated when it ships.
International transfers
Optional product analytics stays in the European Union: PostHog Cloud EU runs on AWS eu-central-1 in Frankfurt, Germany. Vercel, Railway (compute, PostgreSQL and the file store), Resend, Polar and GitHub are United States providers. Anthropic contracts through Anthropic Ireland, Limited for customers in the EEA, the UK and Switzerland, with inference infrastructure largely in the United States.
Transfers outside the European Economic Area rely on the European Commission’s adequacy decision of 10 July 2023 for the EU–U.S. Data Privacy Framework where the importer is certified to that framework — Vercel, Resend, PostHog, Google, Microsoft and GitHub are — and, in addition or instead, on the standard contractual clauses of Commission Implementing Decision (EU) 2021/914 together with a transfer impact assessment and supplementary measures. We do not claim Data Privacy Framework certification for Anthropic, Railway, Polar, X or Bluesky; those transfers rest on the standard contractual clauses, on the provider’s European contracting entity, or — for a post you publish yourself to a network — on art. 49(1)(b) GDPR. A copy of the safeguards is available on request at hello@mergelay.com.
If your data reached us through one of our customers
Mergelay may hold personal data about you without having collected it from you: as the author of a commit or pull request in a repository a customer connected, as a contact in a list a customer imported, or as the recipient of an email a customer sent. In those cases the categories are your name, your handle or username, and your email address; the source is the customer’s GitHub repository or the file the customer uploaded; the purpose is drafting and delivering that customer’s Update; and the customer is the controller. This notice serves as the art. 14 information. Contact the customer first, or write to hello@mergelay.com and we will route your request to them.
Automated decisions
Mergelay uses a model to analyse changes and draft text. It makes no decision producing legal effects or similarly significant effects for an individual within the meaning of art. 22 GDPR: no profiling, scoring or eligibility decision is made about anyone, and nothing the model drafts is published without an explicit approval decision.
That approval decision is never automatic. It is made by a person, in Mergelay or through a one-time review link, or by an agent the workspace explicitly authorises with an operator-scope access token — a choice the customer makes and is responsible for. The art. 22 conclusion above does not depend on who takes it: publishing a product update is not a decision about a data subject.
Security
Posting credentials, webhook URLs, GitHub connections, OAuth states and queued webhook payloads are encrypted at rest with AES-256-GCM under a per-file authenticated envelope; OAuth tokens in the identity database are encrypted and provider ID tokens are discarded; MCP access tokens are stored only as SHA-256 digests. Other workspace files — drafts, deliveries, imported contacts, the audit trail — rely on the provider’s disk encryption rather than an application-level envelope. Traffic is served over TLS with HSTS and a strict content security policy; the review-link token is stripped from API logs; web-to-API calls carry a short-lived signed credential bound to method, path and workspace; GitHub and Polar webhooks are signature-verified; uploads are restricted to PNG, JPEG and GIF verified by magic bytes. No online service can promise absolute security.
Reporting a vulnerability. Write to security@mergelay.com. The policy — what we commit to, how long disclosure takes, what is out of scope, and the safe harbour for good-faith research — is on the security page, with a machine-readable copy at /.well-known/security.txt. There is no bug bounty.
If something goes wrong. For the data Mergelay controls — your account, authentication, billing status, support correspondence — a personal data breach is notified to the Commission nationale de l’informatique et des libertés (CNIL) within 72 hours of our becoming aware of it, unless it is unlikely to result in a risk to your rights and freedoms (art. 33 GDPR), and to you directly, without undue delay, when the risk is high (art. 34). For the content a customer connects or uploads, the customer is the controller and we are its processor: we notify that customer within 48 hours of confirming the breach, as stated in section 9 of the DPA, and we do not notify an authority or the individuals on their behalf unless they ask us to in writing. Every breach is recorded internally whether or not it is notifiable.
Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. You may withdraw consent to optional analytics at any time without affecting earlier lawful processing. Write to hello@mergelay.com; we answer within one month and may ask you to confirm that you control the account or workspace concerned. You may also complain to the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — cnil.fr, or to the supervisory authority where you live or work.
Providing an email address and a password, or a third-party sign-in, is necessary to create an account: without it the service cannot be supplied.
Changes to this notice
We update the effective date on every change, and give reasonable notice by email before a material change to how existing account data is used. Sub-processor changes follow the 30 days’ notice stated on the sub-processor list.