"Mergify presents a moderate privacy risk (38/100) primarily driven by automatic data transfer to acquiring companies without consent, retention of developer credentials (GitHub OAuth tokens), and vague data retention practices tied to prescription periods. The service avoids advertising tracking and provides reasonable opt-out mechanisms for marketing, but lacks transparency on subprocessor identities and maintains indefinite carve-outs for accounting/legal data. Users of a developer-focused service should be aware that acquisition scenarios could transfer sensitive repository access credentials without their approval."
Take Action
7 Privacy Improvements Available
mergify Privacy Concerns & Scorecard
Automatic data transfer to acquiring company without explicit user consent in acquisition scenario. Users cannot prevent this sharing despite sensitivity of developer credentials.
Partial credit card data (last 4 digits) retained beyond immediate payment processing needs, extending exposure window.
Carve-out for commercial accounting and legal obligations means data is never fully deleted, only eventually minimized.
Marketing contact requires express agreement, but policy lacks clear opt-in UI/process documentation.
No third-party advertising tracking or behavioral retargeting detected. Only technical cookies for session management.
Data processing restriction
- 1Email support@mergify.com requesting restriction of processing of your personal data, specifying the grounds for your request (e.g. data accuracy dispute, unlawful processing, etc.).
- 2Include proof of identity with your request.
- 3Await Mergify's response within one month confirming the restriction has been applied.
Data portability request
- 1Email support@mergify.com requesting a copy of your personal data in a portable format, citing your right to data portability under GDPR.
- 2Include proof of identity with your request.
- 3Await Mergify's response within one month providing the data export.
Data subject rights request
- 1Prepare an email to support@mergify.com requesting the specific right you wish to exercise (access, rectification, erasure, portability, restriction, or objection).
- 2Include proof of identity with your request.
- 3Send the email and await Mergify's response, which they are legally obligated to provide within one month.
- 4If Mergify fails to respond or you are unsatisfied, file a complaint with the CNIL (the French data protection authority) online or by post.
Automate your privacy
Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.
Data Collection & Tracking
Personal Information Collected
Account creation, communication, and service delivery
Payment processing and billing
Integration with GitHub repositories for CI/CD automation
Service operation, user support, and functionality
Cross-Platform Tracking
Tracking Methods:
Session Cookies
Mandatory technical cookies for maintaining logged-in session state and chatbox functionality
AI & Data Training
mergify does not train AI on your content
Based on their public policy, your content is not used to train AI models.
How to Object
No opt-out available
This service does not currently provide a public way to opt out of AI training.
Why We Analyzed mergify
TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.