Merge & Tell
PrivacyTerms

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how John Farrell (“we”, “us”) collects, uses, and shares information when you use Merge & Tell (the “Service”), a tool that watches your merged GitHub pull requests and drafts marketing content from them for you to review and publish.

1. Information we collect

  • Account information. Your email address, which you use to sign in via a one-time “magic link”. We do not ask for or store a password.
  • Connected-platform data. When you connect an external account, we access the data described in Connected platforms below and store an access token so the Service can act on your behalf.
  • Content you create. The pull requests we analyze, the draft posts we generate, your edits and approvals, personas, schedules, and related settings.
  • Connection activity. A log of connection events — connect, test, publish, disconnect, and tokens going stale — shown to you in the app’s Activity feed. Secrets are redacted from these records.
  • Technical data. Standard server and security logs (e.g. IP address, timestamps, error diagnostics) generated when you use the Service.

2. How we use information

  • To provide the Service — analyze your PRs and draft content.
  • To publish the posts you approve to the platforms you connect.
  • To authenticate you and keep your account secure.
  • To operate, debug, and improve the Service.
  • To communicate with you about your account and support requests.
  • To process payments for paid plans and prevent abuse.

We do not sell your personal information, and we do not use your pull-request content or generated drafts to train our own models.

3. Connected platforms

The Service only works by connecting to other platforms. You choose which to connect, and you can disconnect any of them at any time.

  • GitHub. We read your merged pull requests — titles, descriptions, and code diffs — to draft content from them.
  • X, Bluesky, Mastodon & LinkedIn. When you connect an account we store an access token so we can publish the posts you approve and read back their status. We only post what you approve.

4. Service providers (subprocessors)

We share data with a small set of vendors who process it on our behalf to run the Service. Each is bound to use it only for that purpose.

  • Anthropic — AI drafting. Pull-request titles, descriptions and diffs are sent to Anthropic’s Claude API to draft the marketing copy. Anthropic processes this as our subprocessor.
  • Supabase — Database, authentication & secret storage. Hosts the application database, sends the magic-link sign-in emails, and stores your connection tokens encrypted in Supabase Vault.
  • Netlify — Application hosting. Serves the application and runs its server-side functions.
  • Stripe — Payments. Processes subscription payments for paid plans. Card details go to Stripe directly; we never see or store them.

We update this list when our providers change. Material changes are reflected in the “last updated” date above.

5. How we store and protect your data

Connection tokens are stored encrypted in a dedicated secrets vault and are only ever used server-side — they are never exposed to your browser, the Activity feed, or any URL. We restrict access to production data and rely on our hosting and database providers’ security controls. No system is perfectly secure, but we treat credential handling as the most sensitive part of the Service.

6. Data retention

We keep your information for as long as your account is active. When you disconnect a platform, its stored token is deleted. When you delete your account, we delete or de-identify your personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements.

7. Your rights and choices

You can access and update much of your information directly in the app, disconnect any connected platform, and request deletion of your account. Depending on where you live, you may also have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email johnefarrell@gmail.com. We will respond within the time required by applicable law.

8. Children

The Service is not directed to anyone under 16, and we do not knowingly collect personal information from children.

9. International transfers

Our providers may process and store data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for such transfers.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “last updated” date and, for material changes, take reasonable steps to notify you.

11. Contact

John Farrell is the controller of your personal data. For any privacy question or request, contact johnefarrell@gmail.com.

Questions about these terms? Email johnefarrell@gmail.com.

Privacy Policy · Terms of Service · Sign in