Skip to content
OHCAYGOMERGE PROOF
HomeTerms

OHCAYGO / MERGE PROOF

Privacy Policy

Effective September 16, 2026

OHCAYGO operates Merge Proof, a service that provides independent exact-state merge evidence for GitHub pull requests. This policy describes the information processed by our website and hosted service. Contact [email protected], or [email protected] if support is unreachable.

Information we process and why

  • GitHub identity and access: account identifiers, login names, App installations, repository access and authentication/session information needed to connect your account, check authorization and operate the service.
  • Repository and pull-request evidence: repository/PR identifiers, file paths, commit SHAs, GitHub actor identifiers, check conclusions and available execution records, approvals, and branch protection/rules metadata needed to produce and refresh receipts. Repository metadata can be sensitive; this is customer data.
  • Billing: if you subscribe, Stripe processes checkout and payment details. We process customer, subscription, invoice/payment status and observed active-developer information to administer your subscription. Card entry takes place on Stripe-hosted checkout.
  • Service operation and support: request and security information, product events and information you send when asking for help. We use these to run, protect and troubleshoot the service, respond to requests and understand the connection-to-proof journey.

GitHub permissions and source text

Contents read is a real GitHub permission. The hosted collector projects GitHub responses to metadata; compare responses may contain patch text in transit, which is discarded rather than stored, rendered, logged or sent to a model. The hosted collector does not clone a repository tree or execute customer code. Stored evidence includes paths, identifiers, SHAs and normalized checks and rules. No AI model decides the verdict.

The free local CLI and GitHub Action operate in the environment where you run them. You control the repositories and generated reports in that environment; GitHub also processes data when you use its Actions service.

Private receipts, access and retention

Private hosted receipts require current authorized repository access, which is rechecked for each hosted request. Uninstalling the App revokes hosted receipt access while preserving its history. Uninstalling is not a deletion request.

Records are subject to product retention and capacity limits. We do not promise permanent receipt availability or a fixed retention period for every record. Information may also need to be retained to administer billing, meet applicable legal obligations, resolve disputes or protect the service.

Providers that help run Merge Proof

We use GitHub for account authorization and repository evidence, Stripe for subscriptions and payments, Cloudflare Pages and Cloudflare services for the public site and network delivery, and DigitalOcean for the hosted backend. These providers process information needed to deliver their services under their own policies and our service arrangements.

Cookies and analytics

Hosted sign-in uses necessary session cookies. We record limited first-party product events and a coarse acquisition channel such as X, other or direct; the landing-page attribution code does not retain advertising click IDs or arbitrary query text.

The public site includes Cloudflare Web Analytics for traffic and performance measurement. No X advertising pixel or similar advertising pixel is installed in the current site. GitHub, Stripe and our hosting providers may use cookies or similar technologies on their own services for authentication, security and service operation.

Your requests and questions

Email [email protected] to ask about your information or request access, correction or deletion. Use [email protected] if support is unreachable. Tell us which account or repository your request concerns; do not send passwords, access tokens or private keys. We may need to verify your identity and authority before acting. Any required retention or limits affecting your request will be explained in our response.

We will update this page when these practices change and identify the effective date above.

OHCAYGOPROVE THE MERGE.
PrivacyTerms[email protected]