Privacy Notice

Last updated: 26 September 2026

This Privacy Notice explains how MergeScope ("we", "us", or "our") collects, uses, and protects information when you use the MergeScope mobile application and web service ("Service"). We are committed to handling your data responsibly and transparently.

1. Data Controller

MergeScope is the data controller for personal data processed in connection with the Service. You can contact us at hello@mergescope.io with any privacy-related queries.

2. Data We Collect

Category Data Purpose
Account Email address, name (from Google Sign-In) Authentication and account management
Payment Subscription status, transaction ID (via Paddle) Billing and plan entitlement
Usage App crash reports, anonymous feature usage Service stability and improvement
Device Push notification token Delivering push notifications
Provider connection GitLab / GitHub instance URL, the list of projects you choose to monitor, and your access credentials (personal access token, or OAuth access and refresh tokens) Connecting to your GitLab or GitHub account so MergeScope can monitor your projects
Repository activity A cache of merge request / pull request data for the projects you monitor (for example titles, descriptions, authors, status, and pipeline and approval state), plus a log of recent activity events Real-time updates and push notifications about your merge requests

Your access credentials. When you connect a GitLab or GitHub account, your credentials are sent to our servers and stored so that MergeScope can keep monitoring your projects and send push notifications while the app is closed. They are encrypted at rest using Supabase Vault and are never stored in plain text. They are not written to your device's local storage. Access is restricted to your own signed-in account and to our server-side processes that act on your behalf, and the credentials are used only to call the GitLab or GitHub API for your connected projects. You can revoke a token at any time from your GitLab or GitHub account settings.

Your merge request data. Merge request and pull request data is retrieved from your GitLab or GitHub instance. To deliver real-time updates and notifications, we register webhooks on the projects you choose to monitor and keep a cache of this data, together with a log of recent activity events, in our database. This data is used only to power your own feed and notifications, is visible only to your account, and is deleted when you delete your account.

3. How We Use Your Data

4. Legal Bases for Processing (GDPR)

Where GDPR applies, we process your data on the following legal bases:

5. Third-Party Services

Paddle — Payment processing. Paddle acts as the Merchant of Record for all transactions. When you make a purchase, Paddle collects payment and billing information directly. Paddle's privacy policy is available at paddle.com/legal/privacy.

Supabase — Authentication and user account data (email, name) is stored securely on Supabase infrastructure hosted in the EU.

Google — If you sign in with Google, Google's authentication service processes your login. See Google's Privacy Policy.

Firebase Cloud Messaging (Google) — Push notification delivery. Your device's push token is used by Google's Firebase Cloud Messaging to deliver notifications to your device. See Google's Privacy Policy.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g. financial records).

7. Your Rights

Depending on your location, you may have the right to:

To exercise any of these rights, contact us at hello@mergescope.io.

8. Security

We use industry-standard security practices including HTTPS for all data in transit, encryption at rest (Supabase Vault) for the GitLab and GitHub access credentials you connect, row-level access controls so each account can only read its own data, and access controls on our infrastructure. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

9. Children

The Service is not directed at children under 18. We do not knowingly collect personal data from anyone under 18.

10. Changes to This Notice

We may update this Privacy Notice from time to time. We will post the updated notice on this page with a revised date. For material changes we will notify you via email or in-app notice.

11. Contact

For privacy-related questions or to exercise your rights, contact us at hello@mergescope.io.