BACK TO HOME
mergify

mergify

General Servicemergify.com

Privacy Conclusion

"Mergify presents a moderate privacy risk (38/100) primarily driven by automatic data transfer to acquiring companies without consent, retention of developer credentials (GitHub OAuth tokens), and vague data retention practices tied to prescription periods. The service avoids advertising tracking and provides reasonable opt-out mechanisms for marketing, but lacks transparency on subprocessor identities and maintains indefinite carve-outs for accounting/legal data. Users of a developer-focused service should be aware that acquisition scenarios could transfer sensitive repository access credentials without their approval."

Risk Score
38
STANDARD

Take Action

7 Privacy Improvements Available

View Actions

mergify Privacy Concerns & Scorecard

Privacy Risk Analysis
Third-Party SharingHIGH

Automatic data transfer to acquiring company without explicit user consent in acquisition scenario. Users cannot prevent this sharing despite sensitivity of developer credentials.

Data CollectionMEDIUM

Partial credit card data (last 4 digits) retained beyond immediate payment processing needs, extending exposure window.

Retention & ControlMEDIUM

Carve-out for commercial accounting and legal obligations means data is never fully deleted, only eventually minimized.

Transparency & RightsLOW

Marketing contact requires express agreement, but policy lacks clear opt-in UI/process documentation.

Tracking & AdsLOW

No third-party advertising tracking or behavioral retargeting detected. Only technical cookies for session management.

Recommended Actions

Data processing restriction

  1. 1Email support@mergify.com requesting restriction of processing of your personal data, specifying the grounds for your request (e.g. data accuracy dispute, unlawful processing, etc.).
  2. 2Include proof of identity with your request.
  3. 3Await Mergify's response within one month confirming the restriction has been applied.
Access Settings

Data portability request

  1. 1Email support@mergify.com requesting a copy of your personal data in a portable format, citing your right to data portability under GDPR.
  2. 2Include proof of identity with your request.
  3. 3Await Mergify's response within one month providing the data export.
Access Settings

Data subject rights request

  1. 1Prepare an email to support@mergify.com requesting the specific right you wish to exercise (access, rectification, erasure, portability, restriction, or objection).
  2. 2Include proof of identity with your request.
  3. 3Send the email and await Mergify's response, which they are legally obligated to provide within one month.
  4. 4If Mergify fails to respond or you are unsatisfied, file a complaint with the CNIL (the French data protection authority) online or by post.
Access Settings

Automate your privacy

Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.

Data Collection & Tracking

Personal Information Collected

Identity Data

Account creation, communication, and service delivery

Payment Data

Payment processing and billing

Developer Credentials

Integration with GitHub repositories for CI/CD automation

Session & Usage Data

Service operation, user support, and functionality

Cross-Platform Tracking

Tracking Methods:

Session Cookies

Mandatory technical cookies for maintaining logged-in session state and chatbox functionality

AI & Data Training

mergify does not train AI on your content

Based on their public policy, your content is not used to train AI models.

How to Object

No opt-out available

This service does not currently provide a public way to opt out of AI training.

Why We Analyzed mergify

TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.