MergeTap
What it doesAccountsPricingPrivacy

Privacy notice

Effective 17 August 2026

The short version

MergeTap has no server of its own. It runs entirely on your device and talks directly to Azure DevOps and Microsoft Entra using credentials you supply.

We operate no backend and collect no analytics. Nothing you do with your pull requests, builds or deployments is transmitted to the provider of this application.

Two exceptions: buying a subscription, handled by Apple or Google and by RevenueCat, who tell us whether a subscription is active — never who you are or what you reviewed — and a crash report, sent only if the app crashes, to a self-hosted error-tracking instance the provider of this application runs themselves.

Controller

Responsible for data processing within the meaning of Article 4 (7) GDPR is Nicolas Mehlei, whose full details are in the imprint.

Because the application performs no processing on our systems, that responsibility is limited to the application as supplied to you. Your use of Azure DevOps is governed separately by Microsoft, who acts as controller for the data held in your organization.

What is stored on your device

The following is written to storage on your device and nowhere else:

  • Access credentials — personal access tokens, and tokens obtained through Microsoft sign-in — held in the operating system's secure credential store (Android Keystore, iOS Keychain).
  • Account and organization settings you have configured.
  • Notification preferences, and the identifiers of commits you have already reviewed, so the app can tell you when a pull request has changed since you last looked at it.
  • Pull request, build and approval data fetched from Azure DevOps, held only for as long as the screen showing it is open.

What leaves your device, and to whom

Requests go to Microsoft-operated endpoints authenticated with your own credentials, to RevenueCat if you buy a subscription, and to our own self-hosted crash-reporting instance if the app crashes:

  • api.revenuecat.com
  • dev.azure.com
  • vssps.dev.azure.com
  • vsrm.dev.azure.com
  • app.vssps.visualstudio.com
  • login.microsoftonline.com
  • bugsink.hapi.nm-hosts.de

Crash reporting

If the app crashes or hits an unhandled error, a report is sent to Bugsink, a crash-reporting instance the provider of this application runs and controls themselves — it is not a third-party service, and no data from it is shared with anyone else. The app uses the Sentry SDK to send these reports, configured to point at Bugsink rather than at Sentry's own service.

A crash report includes the error message, the code location it occurred at, the app version, and basic device/OS information needed to diagnose it. Personal access tokens and Microsoft Entra tokens are stripped before the report leaves your device.

Nothing is sent unless the app actually crashes or hits an unhandled error — there is no routine or background reporting.

If you buy a subscription

Payment is taken by Apple's App Store or Google Play, never by this application. We never see or handle your card details.

Purchases are managed through RevenueCat, a subscription service that validates the store's receipt and tells the app whether a subscription is active.

  • RevenueCat receives an anonymous identifier for your installation, the store receipt, and technical details of the device needed to validate it.
  • It does not receive your Azure DevOps credentials, your pull requests, or anything else this app shows you — those never leave your device except to Microsoft.
  • If you never open the subscription screen and never buy anything, no purchase data is created.
  • RevenueCat acts as a processor on our behalf. Its own privacy notice is at https://www.revenuecat.com/privacy.

What we do not do

Stated explicitly, because these are the things users most often have to assume about an application:

  • No analytics, usage tracking, or behavioural measurement of any kind.
  • No crash or error reporting to any third party — crash reports go only to our own self-hosted instance, see Crash reporting above.
  • No advertising, and no advertising identifiers.
  • No push notifications. Notifications are generated on your device; no push service is contacted and no device token is registered anywhere.
  • No sale of personal data, and no sharing of it for advertising.
  • No linking of purchase data to your Azure DevOps identity or your work.

Legal basis

Processing on your device serves solely to provide the functions you have asked for, and rests on Article 6 (1) (b) GDPR — performance of a contract and steps taken at your request.

Storing credentials in the operating system's secure store is technically necessary to provide the service and is likewise covered by Article 6 (1) (b) GDPR.

Processing a subscription — validating a store receipt and keeping track of whether it is active — is performance of the contract you enter when you buy it, also Article 6 (1) (b) GDPR.

Retention and deletion

Data stored by the application remains on your device until you remove it. Removing an account deletes its stored credentials. Uninstalling the application removes everything the application has stored.

We hold nothing, so there is nothing for us to retain or delete on your behalf.

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21).

Because the provider of this application holds no data about you, these rights are exercised directly against the operator of the Azure DevOps organization you connect to, and against Microsoft. Requests concerning the application itself can be sent to the contact address in the imprint.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in the member state of your residence, place of work, or the place of the alleged infringement.

Permissions the app requests

Notifications — used only to alert you locally about pull requests and approvals awaiting you. Declining this permission leaves every other function intact.

Network access — required to reach Azure DevOps.

Third-party services

Azure DevOps Services and Microsoft Entra ID are operated by Microsoft. Your use of them is subject to Microsoft's own terms and privacy statement, available at https://privacy.microsoft.com/privacystatement.

Depending on your organization's configuration, Microsoft may process data outside the European Union. That processing is outside our control and is governed by Microsoft's agreements with your organization.

Changes to this notice

This notice was last updated on 17 August 2026. Where the application changes what it stores or whom it contacts, this notice is updated in the same change.

Stop being the bottleneck.

The review that blocks your colleague, and the deployment that blocks your release, both fit in the time it takes to make a coffee.

Get it on Google PlaySee pricing
MergeTap

Pull requests and deployment approvals from Azure DevOps, on your phone. Built by one developer who kept missing approvals while away from a desk.

Product

What it doesAccountsPricing

Legal

Privacy noticeImprint

Contact

Email support
© 2026 Nicolas Mehlei · Wedel, GermanyNo account required. Your credentials never leave your device.