Privacy policy

Last updated 30 September 2026

This policy explains, in plain language, what MergeBell reads from your GitLab account, where it goes, and how to get rid of it.

Who we are

MergeBell is an iPhone app for working with your own GitLab account — on gitlab.com or on a GitLab instance you or your company run. It is built and operated by Melih Toksari,an independent software developer, who is the data controller for the purposes of the UK and EU GDPR. You can reach a human at [email protected].

MergeBell is an independent app. It is not affiliated, endorsed, sponsored, or approved with or by GitLab Inc.

The short version

  • The app talks to GitLab directly from your phone. Merge requests, diffs, comments, pipelines and issues are requested by the app, shown to you and cached on the device. They never pass through a server we run.
  • Your GitLab token stays on your phone, in the iPhone Keychain. It is never sent to us — not even when you turn on alerts.
  • Alerts use a separate, read-only key. Push alerts have to be checked while your phone is asleep, so turning them on gives our alert server a second key of its own that can only read. The server refuses any key that could write to GitLab.
  • We never sell your data, never use it for advertising, and never use it to train any AI or machine-learning model.
  • You can delete everything yourself, from inside the app or by followingthe public deletion page, without emailing anyone.

How the app signs in, and what it can do

On gitlab.com you sign in on GitLab’s own page, in a system browser sheet, using OAuth 2.0 with PKCE — never an embedded web view — so your GitLab password is typed into GitLab and is never visible to the app. On a self-managed instance (and optionally on gitlab.com) you paste a personal access token you created yourself.

Either way the app asks for GitLab’s api scope, because reviewing code means writing to GitLab on your behalf. The app only does what you tap:

The app readsThe app writes, only when you ask
Your GitLab profile (id, username, name, avatar), your To-Dos, the projects you are a member of or have starred, merge requests, diffs, comments and threads, approvals, pipelines, jobs and their logs, issues, and files in a repository you openComments, replies and review drafts; resolving threads; approving, unapproving and merging; applying suggestions; retrying, cancelling and playing jobs; creating, editing, closing and commenting on issues; marking To-Dos done; and — only if you turn on Instant mode for a project — adding a webhook to that project

Everything in that table goes directly between your phone and your GitLab instance. We never see your code, your merge requests or your comments.

Where your data is stored

On your phone

  • Your GitLab tokens, one per instance, in the iOS Keychain with thekSecAttrAccessibleAfterFirstUnlockThisDeviceOnly protection class, so they are not included in backups and do not sync to your other devices.
  • A local cache (SQLite) of what you have already looked at, so the app opens instantly and works offline: lists for a few minutes, and the last 20 merge requests you opened until they change. Job logs are never cached.
  • Queued actions — comments, approvals and other actions you took while offline — until they are posted.
  • A small shared store for widgets, holding the handful of values a Home Screen or Lock Screen widget needs to draw itself.

Signing out of an instance deletes its token, cache, queue and alert key. Deleting the app deletes everything above.

On our alert server — only if you turn on alerts

Alerts are off until you turn them on. Before anything is sent, the app explains what follows and asks you to create a second, read-only key just for alerts — on gitlab.com through GitLab’s sign-in page with the read_api scope, on a self-managed instance as aread_api personal access token. Your sign-in token is never sent.

Our alert server (relay.mergebell.app) is our own machine, in Germany — a virtual server we rent from Hetzner and administer ourselves. It is not a third-party backend service: the software and the database are ours, and your data is processed inside the EU. With alerts on, it holds:

  • The read-only key, encrypted before it is written. The encryption key is kept in a file on the server, never in the database, so a copy of the database on its own cannot be decrypted. The server refuses any key whose scopes go beyond read_api andread_user.
  • Your instance address and GitLab user id, so the key is used against the right account.
  • Your device’s push token, so a notification can be delivered.
  • An anonymous subscriber id from RevenueCat, used to check whether you are on Pro and how often to check. It is not your email address and not your GitLab account.
  • Your alert settings — which kinds of events you want, muted projects, quiet hours and pipeline watches — and the position of the last To-Do already notified, so nothing is sent twice.
  • Alert records — the id and kind of each notification sent, not its title. The notification text is composed in memory and cleared once it has been delivered.
  • If you use Instant mode, the id of each webhook and a hash of its secret. The webhook only rings a doorbell: its content is discarded unread.

With that key the server reads your pending To-Dos (every five minutes on the free tier, every minute on Pro) and, for pipeline watches, the pipelines of the branch you chose. It can only call a fixed list of read-only GitLab endpoints, listed on the security page, and it cannot approve, merge, comment or push. No person at MergeBell reads your GitLab data.

Other data the app handles

Product analytics

MergeBell records anonymous usage events through Google Analytics 4, using the Firebase Analytics SDK — for example that sign-in completed, that a merge request was opened, that a review action was taken, or that the paywall was shown. Events never contain your name, email address, instance address, project, merge request or file names. No advertising identifier is read and there are no advertising SDKs in the app, so there is no App Tracking Transparency prompt. These events are processed by Google on its own infrastructure, which is not limited to the EEA. If you would rather send nothing at all, you can use the app in Demo Mode without signing in.

Crash reports

When the app crashes, Firebase Crashlytics sends a report so the bug can be found and fixed: the stack trace, device model, iOS version and app version. It never contains your token, your code or the content of your merge requests. Crashlytics is a Google service and is processed outside the EEA.

Subscriptions

Purchases are handled by Apple and mediated by RevenueCat, which tells the app whether your Pro subscription is active. Neither MergeBell nor RevenueCat ever sees your card details.

This website

mergebell.app is a set of static pages on Cloudflare Pages. It sets no cookies, runs no tracking pixels and shows no cookie banner, because it has nothing to ask you about. If you email us or join the waitlist, we hold your email address for that purpose and nothing else.

Who your data is shared with

We do not sell your data, rent it, trade it, or share it for advertising. The complete list of companies that touch any of it, and the only reason each one does:

ServiceWhat it receivesWhen
Your GitLab instance (GitLab Inc. for gitlab.com, or whoever runs yours)Your requests for your own data, and the actions you takeWhenever the app — or, with alerts on, our server — talks to GitLab
Hetzner Online GmbH — hosting onlyNothing for their own purposes. They rent us the machine in Germany on which our alert server runs, so the encrypted data described above physically sits there.Only while alerts are on
Apple (push notifications)The notification text — for example “Review requested · !42 · group/project” and the merge request title — and your device’s push tokenOnly when an alert is sent
RevenueCatAn anonymous subscriber id and your subscription statusWhen you purchase, restore, or the app checks your subscription
Google (Analytics 4 and Crashlytics, via Firebase)Anonymous product events and crash reports, as described aboveWhile you use the app
CloudflareStandard web request data for this websiteWhen you visit mergebell.app

We may also disclose data if we are legally required to, or to investigate abuse of the service — but we have no mechanism for browsing your GitLab data and no intention of building one.

How long we keep things

  • Cache on your phone: minutes for lists, and until they change for the last 20 merge requests you opened. Cleared when you sign out or delete the app.
  • Alert data on our server: for as long as alerts are on. Deleted at once when you choose Delete alert data, when GitLab tells us the key was revoked, or automatically when no device has been reachable for 7 days.
  • Alert records: 14 days.
  • Anonymous analytics events: retained in aggregate. They contain nothing that identifies you or your projects.
  • Support emails: kept while the conversation is useful, then deleted.

Where your data is processed

With alerts off, nothing of yours is processed anywhere but on your phone and your own GitLab instance. With alerts on, the data above is processed on our server in Germany.Melih Toksari, who administers the server, is resident in Türkiye and accesses it from there.

Your rights, and how to use them

Under the UK and EU GDPR you have the right to access, correct, export, restrict and delete your personal data, and to object to processing. Most of these you can exercise yourself, immediately:

  • Withdraw access: revoke MergeBell’s keys in GitLab at any time — underUser settings → Applications for sign-in through gitlab.com, orUser settings → Access tokens for a token you created. The key stops working the moment you do.
  • Delete: follow the deletion instructions. They work without an account and without contacting us.

If you would rather have a person handle it, email[email protected] and we will action it within 30 days. You also have the right to complain to your local data protection authority.

If you are in California, we do not sell or share personal information as the CCPA/CPRA defines those terms, and we do not offer financial incentives for data.

Children

MergeBell is a professional tool for people who work on software. It is not directed at children under 13 and we do not knowingly collect their data.

Changes to this policy

If this policy changes in a way that affects what we do with your data, we will update the date at the top of this page and, for anything material, say so in the app before the change takes effect.

Contact

Questions about any of this go to [email protected]. A person reads it.