Privacy Policy
Last updated: 2026-07-18
This policy explains what personal data AfterMerge ("we", "us") collects when you use the service, why, how long we keep it, and the rights you have over it under India's Digital Personal Data Protection Act, 2023 (DPDPA).
1. What we collect
- Account identity — your name, email address, and profile image, provided by whichever sign-in method you use (Google, GitHub, or a passkey registered to your device).
- Repository data — metadata and source code from repositories you connect, used to build the analysis graph you request.
- Chat history — the conversations you have with the in-app assistant, stored so you can revisit a thread later.
- Connection credentials — access tokens for services you connect (GitHub/GitLab/Bitbucket, AI providers, Jira/Slack), always encrypted at rest and never displayed back to you in full.
- Billing & usage — your organization's plan, usage counters, and (if applicable) billing contact details.
- Operational data — an audit trail of actions taken in your account/organization, and standard request metadata (IP address, user agent) captured for security purposes.
2. Cookies & similar technology
We set exactly one cookie today: a strictly-necessary, first-party session cookie used to keep you signed in. It is not used for advertising or cross-site tracking, so no cookie-consent banner is shown. Two other mechanisms are worth disclosing even though neither sets a browser cookie:
- Error monitoring & session replay — used to diagnose bugs; may record in-app interactions when an error occurs.
- Bot/abuse protection — uses device/browser signals to distinguish real sign-ins from automated abuse.
3. Who else processes your data (subprocessors)
We use trusted service providers to operate AfterMerge, each limited to processing your data solely to provide their specific function for us. Some are located outside India; where personal data is processed abroad, it is solely in connection with providing you the service. A full list of subprocessors and their locations is available on request from our Grievance Officer (see below).
- Cloud database & infrastructure hosting
- Background job processing
- AI/language-model providers — power analysis, chat, and search
- Transactional email delivery (e.g. org invitations)
- Cloud object storage for uploaded documents
- AI observability/quality monitoring
- Sign-in providers (for Google/GitHub OAuth, if you use them)
- Error monitoring & session replay
4. How long we keep data
We retain your data for as long as your account is active. When you request deletion of your account or organization, data is deactivated immediately and permanently erased within 30 days (a short recovery window in case the request was made by mistake). Data belonging to an account that has been inactive for 12 months is also erased, consistent with the DPDPA's requirement to erase data once its purpose is served.
5. Your rights as a Data Principal
Under the DPDPA, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or outdated data.
- Erase your data once it's no longer needed.
- Withdraw consent at any time (in practice, this means closing your account — the service cannot function without the baseline account data described above).
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
- Raise a grievance if you believe we've mishandled your data (see below).
Self-service tools for access and erasure are being added to your account settings. Until then, contact us using the details below and we will action your request manually.
6. Grievance Officer
If you have a privacy concern or complaint, contact our Grievance Officer:
Saurabh Singh
Email: saurabh@aftermerge.dev
7. Changes to this policy
If we make a material change to this policy, we'll update the "Last updated" date above and, where required, ask for your consent again.