Privacy policy
This policy explains, in plain language, what MergeBell reads from your GitLab account, where it goes, and how to get rid of it.
Who we are
MergeBell is an iPhone app for working with your own GitLab account — on gitlab.com or on a GitLab instance you or your company run. It is built and operated by Melih Toksari,an independent software developer, who is the data controller for the purposes of the UK and EU GDPR. You can reach a human at [email protected].
MergeBell is an independent app. It is not affiliated, endorsed, sponsored, or approved with or by GitLab Inc.
The short version
- The app talks to GitLab directly from your phone. Merge requests, diffs, comments, pipelines and issues are requested by the app, shown to you and cached on the device. They never pass through a server we run.
- Your GitLab token stays on your phone, in the iPhone Keychain. It is never sent to us — not even when you turn on alerts.
- Alerts use a separate, read-only key. Push alerts have to be checked while your phone is asleep, so turning them on gives our alert server a second key of its own that can only read. The server refuses any key that could write to GitLab.
- We never sell your data, never use it for advertising, and never use it to train any AI or machine-learning model.
- You can delete everything yourself, from inside the app or by followingthe public deletion page, without emailing anyone.
How the app signs in, and what it can do
On gitlab.com you sign in on GitLab’s own page, in a system browser sheet, using OAuth 2.0 with PKCE — never an embedded web view — so your GitLab password is typed into GitLab and is never visible to the app. On a self-managed instance (and optionally on gitlab.com) you paste a personal access token you created yourself.
Either way the app asks for GitLab’s api scope, because reviewing code means writing to GitLab on your behalf. The app only does what you tap:
| The app reads | The app writes, only when you ask |
|---|---|
| Your GitLab profile (id, username, name, avatar), your To-Dos, the projects you are a member of or have starred, merge requests, diffs, comments and threads, approvals, pipelines, jobs and their logs, issues, and files in a repository you open | Comments, replies and review drafts; resolving threads; approving, unapproving and merging; applying suggestions; retrying, cancelling and playing jobs; creating, editing, closing and commenting on issues; marking To-Dos done; and — only if you turn on Instant mode for a project — adding a webhook to that project |
Everything in that table goes directly between your phone and your GitLab instance. We never see your code, your merge requests or your comments.
Where your data is stored
On your phone
- Your GitLab tokens, one per instance, in the iOS Keychain with the
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnlyprotection class, so they are not included in backups and do not sync to your other devices. - A local cache (SQLite) of what you have already looked at, so the app opens instantly and works offline: lists for a few minutes, and the last 20 merge requests you opened until they change. Job logs are never cached.
- Queued actions — comments, approvals and other actions you took while offline — until they are posted.
- A small shared store for widgets, holding the handful of values a Home Screen or Lock Screen widget needs to draw itself.
Signing out of an instance deletes its token, cache, queue and alert key. Deleting the app deletes everything above.
On our alert server — only if you turn on alerts
Alerts are off until you turn them on. Before anything is sent, the app explains what follows and asks you to create a second, read-only key just for alerts — on gitlab.com through GitLab’s sign-in page with the read_api scope, on a self-managed instance as aread_api personal access token. Your sign-in token is never sent.
Our alert server (relay.mergebell.app) is our own machine, in Germany — a virtual server we rent from Hetzner and administer ourselves. It is not a third-party backend service: the software and the database are ours, and your data is processed inside the EU. With alerts on, it holds:
- The read-only key, encrypted before it is written. The encryption key is kept in a file on the server, never in the database, so a copy of the database on its own cannot be decrypted. The server refuses any key whose scopes go beyond
read_apiandread_user. - Your instance address and GitLab user id, so the key is used against the right account.
- Your device’s push token, so a notification can be delivered.
- An anonymous subscriber id from RevenueCat, used to check whether you are on Pro and how often to check. It is not your email address and not your GitLab account.
- Your alert settings — which kinds of events you want, muted projects, quiet hours and pipeline watches — and the position of the last To-Do already notified, so nothing is sent twice.
- Alert records — the id and kind of each notification sent, not its title. The notification text is composed in memory and cleared once it has been delivered.
- If you use Instant mode, the id of each webhook and a hash of its secret. The webhook only rings a doorbell: its content is discarded unread.
With that key the server reads your pending To-Dos (every five minutes on the free tier, every minute on Pro) and, for pipeline watches, the pipelines of the branch you chose. It can only call a fixed list of read-only GitLab endpoints, listed on the security page, and it cannot approve, merge, comment or push. No person at MergeBell reads your GitLab data.
Other data the app handles
Product analytics
MergeBell records anonymous usage events through Google Analytics 4, using the Firebase Analytics SDK — for example that sign-in completed, that a merge request was opened, that a review action was taken, or that the paywall was shown. Events never contain your name, email address, instance address, project, merge request or file names. No advertising identifier is read and there are no advertising SDKs in the app, so there is no App Tracking Transparency prompt. These events are processed by Google on its own infrastructure, which is not limited to the EEA. If you would rather send nothing at all, you can use the app in Demo Mode without signing in.
Crash reports
When the app crashes, Firebase Crashlytics sends a report so the bug can be found and fixed: the stack trace, device model, iOS version and app version. It never contains your token, your code or the content of your merge requests. Crashlytics is a Google service and is processed outside the EEA.
Subscriptions
Purchases are handled by Apple and mediated by RevenueCat, which tells the app whether your Pro subscription is active. Neither MergeBell nor RevenueCat ever sees your card details.
This website
mergebell.app is a set of static pages on Cloudflare Pages. It sets no cookies, runs no tracking pixels and shows no cookie banner, because it has nothing to ask you about. If you email us or join the waitlist, we hold your email address for that purpose and nothing else.
Who your data is shared with
We do not sell your data, rent it, trade it, or share it for advertising. The complete list of companies that touch any of it, and the only reason each one does:
| Service | What it receives | When |
|---|---|---|
| Your GitLab instance (GitLab Inc. for gitlab.com, or whoever runs yours) | Your requests for your own data, and the actions you take | Whenever the app — or, with alerts on, our server — talks to GitLab |
| Hetzner Online GmbH — hosting only | Nothing for their own purposes. They rent us the machine in Germany on which our alert server runs, so the encrypted data described above physically sits there. | Only while alerts are on |
| Apple (push notifications) | The notification text — for example “Review requested · !42 · group/project” and the merge request title — and your device’s push token | Only when an alert is sent |
| RevenueCat | An anonymous subscriber id and your subscription status | When you purchase, restore, or the app checks your subscription |
| Google (Analytics 4 and Crashlytics, via Firebase) | Anonymous product events and crash reports, as described above | While you use the app |
| Cloudflare | Standard web request data for this website | When you visit mergebell.app |
We may also disclose data if we are legally required to, or to investigate abuse of the service — but we have no mechanism for browsing your GitLab data and no intention of building one.
How long we keep things
- Cache on your phone: minutes for lists, and until they change for the last 20 merge requests you opened. Cleared when you sign out or delete the app.
- Alert data on our server: for as long as alerts are on. Deleted at once when you choose Delete alert data, when GitLab tells us the key was revoked, or automatically when no device has been reachable for 7 days.
- Alert records: 14 days.
- Anonymous analytics events: retained in aggregate. They contain nothing that identifies you or your projects.
- Support emails: kept while the conversation is useful, then deleted.
Where your data is processed
With alerts off, nothing of yours is processed anywhere but on your phone and your own GitLab instance. With alerts on, the data above is processed on our server in Germany.Melih Toksari, who administers the server, is resident in Türkiye and accesses it from there.
Your rights, and how to use them
Under the UK and EU GDPR you have the right to access, correct, export, restrict and delete your personal data, and to object to processing. Most of these you can exercise yourself, immediately:
- Withdraw access: revoke MergeBell’s keys in GitLab at any time — underUser settings → Applications for sign-in through gitlab.com, orUser settings → Access tokens for a token you created. The key stops working the moment you do.
- Delete: follow the deletion instructions. They work without an account and without contacting us.
If you would rather have a person handle it, email[email protected] and we will action it within 30 days. You also have the right to complain to your local data protection authority.
If you are in California, we do not sell or share personal information as the CCPA/CPRA defines those terms, and we do not offer financial incentives for data.
Children
MergeBell is a professional tool for people who work on software. It is not directed at children under 13 and we do not knowingly collect their data.
Changes to this policy
If this policy changes in a way that affects what we do with your data, we will update the date at the top of this page and, for anything material, say so in the app before the change takes effect.
Contact
Questions about any of this go to [email protected]. A person reads it.