Privacy Policy
Last Updated: August 15, 2026
1. Introduction & Scope
GetMerged ("we", "our", or "the Platform") helps open-source contributors discover GitHub repositories where pull requests are actually welcomed and merged. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the choices and rights you have.
This policy applies to all visitors of getmerged.abhishekco.de, the web application, and any related features, including sign-in, watchlists, contributor feedback, and AI-generated repository insights. It does not apply to the practices of GitHub, Google, or any third-party service you access through links on the Platform.
We are the "controller" of the personal data described in this policy. If you have questions, see Section 15 (Contact Us).
2. Information We Collect
We practice data minimization: we collect only what is needed to provide the service. Personal data is divided into the categories below.
a) Account Information (via OAuth)
When you sign in with GitHub or Google, we receive the following from the identity provider, scoped to the minimum needed:
- GitHub sign-in: your public GitHub profile ID, username, email address, and avatar URL. We request the
user:emailscope only - no access to your private repositories. - Google sign-in: your Google account ID, name, email address, and profile picture, via the
openid email profilescopes.
Your account record (ID, username, email, and avatar) is encrypted at rest using AES-256-GCM before it is stored.
b) Content You Submit
- Watchlist: the list of repositories you choose to track for C-Rankâ„¢ changes.
- Contributor feedback: when you rate a repository's maintainer responsiveness, review speed, and beginner-friendliness (1–5 scales), add a free-text comment, and your status as a verified contributor.
- Indexing requests: if you request that a repository be indexed, your user ID is recorded with the request.
c) Data Collected Automatically
- Analytics events: with your consent, we collect anonymized product usage events (page views, searches, filters, sign-in clicks) via PostHog. See Section 7 for details.
- Session and preference data: a short-lived authentication cookie and, in some pages, a temporary scroll position stored in your browser's session storage.
- Server logs and cache: standard technical metadata (IP address, request path, timestamps) necessary for security, rate limiting, and debugging. This data is kept in our infrastructure and cache layers.
d) Public GitHub Data
We collect public GitHub data - repository metadata, pull request and issue comment text, merge rates, and response times - to compute C-Rankâ„¢ scores. This data is publicly available on GitHub and is processed for scoring and AI-generated insights. Public comment text may include the usernames of comment authors.
3. How We Use Your Information
- To authenticate your sessions and keep you signed in across visits.
- To display and sync your watchlist, including notifications of C-Rankâ„¢ changes.
- To verify contributor status and publish community feedback alongside repository profiles.
- To generate AI-powered repository insights from public comment corpora.
- To measure and improve the Platform's usability and feature discoverability (analytics, with consent).
- To secure the Platform, prevent abuse, respond to support requests, and comply with legal obligations.
We do not sell, rent, or trade your personal information to any third party, including as "sale" or "sharing" is defined under the California Consumer Privacy Act (CCPA).
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process personal data on the following legal bases under the GDPR:
- Contract performance (Article 6(1)(b)): providing account sign-in, watchlists, and feedback features you request.
- Consent (Article 6(1)(a)): analytics cookies and events. You can withdraw consent at any time via the cookie banner or browser settings; withdrawal does not affect the lawfulness of processing before withdrawal.
- Legitimate interests (Article 6(1)(f)): platform security, abuse prevention, debugging, and product improvement, balanced against your rights and interests.
- Legal obligation (Article 6(1)(c)): where we must retain records to comply with applicable law.
5. Sharing & Third-Party Processors
We share personal data only with service providers that process it on our behalf under contractual obligations to keep it confidential and secure. The sub-processors we currently use:
| Provider | Purpose | Data |
|---|---|---|
| GitHub | OAuth authentication; public repo/PR/comment telemetry for C-Rankâ„¢ scoring | Profile fields, username; public data |
| OAuth authentication | Profile fields | |
| PostHog (US cloud) | Anonymized product analytics | Event data; GitHub ID + username for identity |
| OpenCode AI API | Generates AI repository insights | Public PR/issue comment text and author logins |
| Cloud / database / cache providers | Hosting, MySQL/SQLite storage, Valkey caching, local NLP sidecar | Encrypted user records and public telemetry |
We may also disclose personal data when required by law, legal process, or government request, or when necessary to protect the rights, property, or safety of GetMerged, its users, or the public.
6. International Data Transfers
Your personal data is stored on servers operated by our infrastructure providers, and some sub-processors (such as PostHog and the OpenCode AI API) operate outside the EEA/UK, including in the United States. Where personal data is transferred outside the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) adopted by the European Commission and applicable decisions for the UK, to ensure your data receives an adequate level of protection.
You may request a copy of the relevant safeguards by contacting us (see Section 15).
7. Cookies, Consent & Analytics
Essential cookies
opendoor_token- a session cookie that keeps you signed in (7-day lifetime). This is strictly necessary for authentication.opendoor_consent- records your analytics choice (accepted: 1 year; rejected: 90 days) so we can honor it across visits.- Session storage - a temporary scroll-position value used only during a session.
Analytics & consent
We use PostHog for anonymized product analytics. PostHog is initialized in memory-only mode and begins capturing events only after you accept via the cookie banner. You can:
- Accept - analytics run to help us improve the Platform.
- Reject - no analytics events are captured; core functionality, including sign-in and watchlists, is unaffected.
- Change your choice at any time by clearing the
opendoor_consentcookie (the banner will reappear) or blocking the/ingestendpoint.
We do not use advertising cookies, retargeting, or third-party ad trackers.
8. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Account data: retained while your account is active and for a reasonable period afterward to allow you to sign back in without losing your watchlist.
- Watchlist: retained until you remove a repository or delete your account; cascade-deleted when an account is removed.
- Analytics events: retained per PostHog's data retention policy for the project.
- Repository telemetry snapshots: daily score snapshots are pruned after approximately 90 days to keep scores current.
- Logs and cache: retained for security and debugging purposes for a limited period.
9. Data Security
We implement reasonable technical and organizational safeguards, including:
- Encryption at rest: user identity fields (ID, username, email, avatar) are encrypted with AES-256-GCM before storage.
- Encryption in transit: all traffic is served over HTTPS/TLS.
- Authentication: sessions use signed, expiring JSON Web Tokens (JWTs) validated by our middleware.
- Access control: internal endpoints and admin alerting are separated from public routes; sensitive operations require authentication.
No method of transmission or storage is 100% secure. While we work to protect your data, we cannot guarantee absolute security, and we will notify affected users and relevant authorities where required by law in the event of a personal data breach.
10. Your Rights & Choices
Depending on your location, you may have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data where it is no longer necessary or consent is withdrawn.
- Right to restrict processing: limit how we process your data in certain circumstances.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: withdraw analytics consent at any time.
California (CCPA/CPRA): California residents have the right to know the categories and specific pieces of personal information we collect, the right to delete it, the right to correct it, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA, and we do not use targeted advertising. California residents may exercise their rights by contacting us below.
To exercise any of these rights, contact us using the details in Section 15. We will verify your identity and respond within the timeframes required by applicable law (generally one month under the GDPR, and 45 days under the CCPA).
11. Children's Privacy
The Platform is not directed to children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will delete it promptly.
12. Third-Party Links
The Platform contains links to external sites (including GitHub). We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external service you visit.
13. Business Transfers
If GetMerged is involved in a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you and take steps to ensure it continues to be handled in accordance with this policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. Material changes will be posted on this page with an updated "Last Updated" date. Where required, we will notify you of material changes. Continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
If you have questions, concerns, or requests about this Privacy Policy or your personal data, please reach out to our maintainers:
- Open an issue or DM the maintainers on our official GitHub Organization.
- Email us directly at [email protected].
- Review the terms in our Terms of Service.
If you are an EU/UK resident and believe your data protection complaint has not been addressed, you may lodge a complaint with your local supervisory authority.