Effective 17 August 2026
MergeTap has no server of its own. It runs entirely on your device and talks directly to Azure DevOps and Microsoft Entra using credentials you supply.
We operate no backend and collect no analytics. Nothing you do with your pull requests, builds or deployments is transmitted to the provider of this application.
Two exceptions: buying a subscription, handled by Apple or Google and by RevenueCat, who tell us whether a subscription is active — never who you are or what you reviewed — and a crash report, sent only if the app crashes, to a self-hosted error-tracking instance the provider of this application runs themselves.
Responsible for data processing within the meaning of Article 4 (7) GDPR is Nicolas Mehlei, whose full details are in the imprint.
Because the application performs no processing on our systems, that responsibility is limited to the application as supplied to you. Your use of Azure DevOps is governed separately by Microsoft, who acts as controller for the data held in your organization.
The following is written to storage on your device and nowhere else:
Requests go to Microsoft-operated endpoints authenticated with your own credentials, to RevenueCat if you buy a subscription, and to our own self-hosted crash-reporting instance if the app crashes:
If the app crashes or hits an unhandled error, a report is sent to Bugsink, a crash-reporting instance the provider of this application runs and controls themselves — it is not a third-party service, and no data from it is shared with anyone else. The app uses the Sentry SDK to send these reports, configured to point at Bugsink rather than at Sentry's own service.
A crash report includes the error message, the code location it occurred at, the app version, and basic device/OS information needed to diagnose it. Personal access tokens and Microsoft Entra tokens are stripped before the report leaves your device.
Nothing is sent unless the app actually crashes or hits an unhandled error — there is no routine or background reporting.
Payment is taken by Apple's App Store or Google Play, never by this application. We never see or handle your card details.
Purchases are managed through RevenueCat, a subscription service that validates the store's receipt and tells the app whether a subscription is active.
Stated explicitly, because these are the things users most often have to assume about an application:
Processing on your device serves solely to provide the functions you have asked for, and rests on Article 6 (1) (b) GDPR — performance of a contract and steps taken at your request.
Storing credentials in the operating system's secure store is technically necessary to provide the service and is likewise covered by Article 6 (1) (b) GDPR.
Processing a subscription — validating a store receipt and keeping track of whether it is active — is performance of the contract you enter when you buy it, also Article 6 (1) (b) GDPR.
Data stored by the application remains on your device until you remove it. Removing an account deletes its stored credentials. Uninstalling the application removes everything the application has stored.
We hold nothing, so there is nothing for us to retain or delete on your behalf.
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21).
Because the provider of this application holds no data about you, these rights are exercised directly against the operator of the Azure DevOps organization you connect to, and against Microsoft. Requests concerning the application itself can be sent to the contact address in the imprint.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in the member state of your residence, place of work, or the place of the alleged infringement.
Notifications — used only to alert you locally about pull requests and approvals awaiting you. Declining this permission leaves every other function intact.
Network access — required to reach Azure DevOps.
Azure DevOps Services and Microsoft Entra ID are operated by Microsoft. Your use of them is subject to Microsoft's own terms and privacy statement, available at https://privacy.microsoft.com/privacystatement.
Depending on your organization's configuration, Microsoft may process data outside the European Union. That processing is outside our control and is governed by Microsoft's agreements with your organization.
This notice was last updated on 17 August 2026. Where the application changes what it stores or whom it contacts, this notice is updated in the same change.