1. Introduction
Mergegleam, Inc. ("the Company," "we," "us," or "our") operates mergegleam.com and provides an AI-based pull-request review service that analyzes code diffs submitted through the GitHub App integration and posts automated review comments on your pull requests (the "Service"). This Privacy Policy explains what information we collect when you use the Service, how we use it, and the choices available to you. It applies to information collected through mergegleam.com and through direct communications with us.
We process pull request diffs and repository metadata submitted through the GitHub App solely to generate automated code review findings. We do not use pull request content to train or fine-tune machine learning models without your explicit written consent.
The Company is based at 631 Brannan Street, Suite 200, San Francisco, CA 94107 and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide
We collect information you submit directly, including:
- Account details (name, email address, GitHub username) when you sign up or configure the Service;
- Billing information processed through our payment provider (we do not store raw card data);
- Configuration choices you make in the Mergegleam dashboard (enabled check categories, ignore rules, notification preferences);
- The content of any messages you send us through email or support channels.
2.2 Pull Request and Repository Data
When you install the Mergegleam GitHub App and a pull request is opened or updated in a connected repository, we receive and process:
- The diff (changed lines and surrounding context) of files included in the pull request;
- File paths and repository metadata necessary to understand the scope of the change;
- The pull request title and description, used to understand stated intent alongside the code change.
This content is processed in-memory to generate review findings and is not retained beyond the time required to post the review comments, unless you have enabled review history in your account settings (which stores findings for your own reference). We do not use pull request content for any purpose other than providing the review service to your account.
2.3 Information Collected Automatically
When you visit mergegleam.com, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5 and our Cookie Policy).
2.4 We Do Not Knowingly Collect Children's Data
mergegleam.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
We use the information we collect to:
- Provide the automated pull-request review service: analyzing submitted diffs and posting review findings as GitHub PR comments;
- Operate, maintain, and improve the Service, including improving the accuracy of review findings and reducing false positive rates;
- Manage your account, process billing, and send service notifications (plan changes, review summaries, security alerts);
- Send marketing communications with your consent where required by applicable law;
- Detect, investigate, and prevent abuse of the Service;
- Comply with legal obligations.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see the California section below.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (hosting infrastructure, payment processing, transactional email delivery, anonymized analytics) under contractual confidentiality terms;
- GitHub, as necessary to post review comments through the GitHub App API on your behalf;
- Authorities, when required by law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information to third parties. We do not share pull request content with any third party except the service providers necessary to operate the review pipeline.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, maintain your session, and measure aggregate usage. For details and choices, see our Cookie Policy.
6. Data Retention
We retain account information for as long as your account is active and for a reasonable period thereafter to allow reactivation. Pull request diff content processed for review is not retained after review comments are posted, unless you have enabled review history in your account settings. Review history is retained for the duration of your subscription and deleted within 30 days of account closure. Marketing-list contacts are purged after 24 months of inactivity. Server access logs are retained 90 days, then aggregated.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information and repository data, including TLS encryption in transit, restricted-access infrastructure, and least-privilege access controls for personnel. Pull request processing occurs in isolated compute environments. No system is perfectly secure; we cannot guarantee absolute security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of the Policy.
9.1 Categories We Collect
In the past 12 months, we have collected the following categories of personal information defined under Cal. Civ. Code §1798.140: identifiers (name, email, IP address, GitHub username); commercial information (subscription tier, billing history); internet activity (browsing on mergegleam.com, GitHub App usage events); professional information (repository names, pull request metadata submitted through the Service); and inferences drawn from the above for service-improvement purposes. We do not collect sensitive personal information as defined under Cal. Civ. Code §1798.140(ae).
9.2 Sources, Purposes, Disclosure
We obtain this information from you directly, through the GitHub App integration, and through automatic site instrumentation. We use it to operate and improve the Service, communicate with you, and meet legal obligations. We disclose it only to service providers under written contract and to legal authorities where required.
9.3 Your CCPA / CPRA Rights
- Right to Know: request the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: request deletion of personal information we collected from you, subject to legal exceptions.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: we do not sell personal information; we do not "share" it for cross-context behavioral advertising as defined under CPRA.
- Right to Limit Use of Sensitive PI: we do not use sensitive personal information for purposes beyond those permitted without authorization.
- Right to Non-Discrimination: we will not deny services, charge different prices, or provide a different level of service because you exercised a right.
9.4 How to Exercise
Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for us to verify you are the person whose information is the subject of the request. We respond within 45 days, with a possible 45-day extension for which we will notify you.
9.5 Authorized Agents
You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; we may also require you to verify your identity directly.
9.6 "Shine the Light"
California Civil Code §1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.
9.7 Do Not Track and Global Privacy Control
Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Mergegleam, Inc.631 Brannan Street, Suite 200
San Francisco, CA 94107
Email: [email protected]
Phone: +1 (415) 390-0164