← mergesafe.ai

Privacy

Last updated 23 September 2026.

MergeSafe is not open to the public yet, and this site collects nothing from you. There is no form on it, no account to create and nothing to submit. This page says what that means, and what the server unavoidably sees when you load a page.

Who is responsible

Z Squared Technologies LLC, a limited liability company registered in Ohio, United States, is the controller of the personal data described here. For anything on this page, write to privacy@mergesafe.ai.

What we collect

Nothing. There is nothing to type into, and we do not keep access logs: request logging is not switched on for this site, so we hold no record of who visited it or when.

Your browser still has to reach a server, and Amazon — who serve the page for us — process that request to deliver it, under their own operational terms. We do not receive, store or analyse it.

What we do not collect

No analytics, no advertising or marketing trackers, no third-party scripts, and no cookies. These pages load nothing from any other domain, which you can check in your browser's network tab — so no third party learns you were here. Amazon still serve the page and therefore see the request, as described above; the claim is that nobody else is invited in, not that the request reaches us by magic.

Why we are allowed to hold it

The question does not really arise: we are not holding personal data about you, so there is no consent to give or withdraw and no legitimate interest to weigh. If that changes — and it will, when the product opens — this page changes first.

What we use it for

Nothing, because we have nothing. We do not build profiles, we do not sell or rent anything, and there is no mailing list to be on.

Who else touches it

Amazon Web Services only, as our hosting provider. The site is served from AWS in the United States (us-east-1), and AWS processes the request on our instructions and for no other purpose.

How long we keep it

Nothing is kept, because nothing is collected. There is no record to delete and no retention period to state.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable form — and you can object to us holding it at all. Depending on where you are, these may be rights under the UK and EU GDPR, or under California law, but we apply them to everyone rather than checking your location first.

Write to privacy@mergesafe.ai and we will act within 30 days. If you are in the UK or EU and think we have handled this badly, you can also complain to your national data protection authority.

When the product launches

MergeSafe reviews source code, which means the product — once you connect a repository to it — will process a good deal more than an email address, including your code and the contents of your pull requests. None of that happens today, and none of it is covered by this page. A fuller policy covering the product and its subprocessors will be published before anyone can connect a repository.

What we can already commit to is how long that data lives: we keep a connected repository’s data until you ask us to delete it, or until the repository has been inactive for 30 days, whichever comes first. Source code itself is checked out only for the duration of a review and is deleted when the review finishes; we do not keep a copy of your repository.

Changes

If this page changes we will update the date at the top. If a change materially affects what we do with an address we already hold, we will email you rather than quietly amending this page.