01
Information we collect
- Account information, such as your name, email address, company, role, and authentication details.
- GitHub information you authorize us to access, including your profile, organisations, repositories, issues, pull requests, and installation metadata.
- Product content, including bug reports, prompts, comments, repository context, generated changes, run logs, and preview results.
- Billing information and subscription status. Payment card details are handled by Stripe and are not stored by Mergent.
- Technical information, such as IP address, browser and device data, timestamps, diagnostic logs, and security events.
- Messages you send through our contact forms or support channels.
02
How we use information
- Provide, maintain, secure, and improve the service.
- Authenticate users, connect authorised repositories, run agents, create previews, and prepare pull requests.
- Process subscriptions, communicate service updates, and respond to support requests.
- Detect abuse, investigate incidents, enforce our terms, and comply with legal obligations.
- Analyse service performance using aggregated or de-identified information.
03
AI processing
Repository context, bug reports, and instructions may be sent to our AI provider, currently OpenAI, to generate and evaluate code changes. We limit the information sent to what is needed for a run. Do not submit secrets or personal information that is unnecessary for the task.
04
Service providers
We use service providers to operate Mergent, including GitHub for source control, OpenAI for model inference, Supabase and database infrastructure for authentication and storage, Vercel for hosting and previews, Stripe for billing, and Resend for transactional email. They process information under their own terms and our contractual instructions where applicable.
05
Retention and deletion
We retain information while your account is active and as needed to provide the service, resolve disputes, meet legal obligations, and protect the service. Retention varies by data type. You may request account or personal-data deletion; some records may be retained where legally required or necessary for security and fraud prevention.
06
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to withdraw consent. You may also complain to your local data-protection authority. We may need to verify your identity before completing a request.
07
International transfers
Our providers may process information outside your country. Where required, we use recognised safeguards for international transfers, including contractual protections.
08
Contact and changes
To ask a privacy question or exercise your rights, use the contact form linked below. We may update this policy as the service changes. Material updates will be posted here with a revised effective date.
Questions?
Contact us about this document or request a signed DPA.
Contact Mergent