Privacy policy

Your data has one job.

Pull Tally uses your data to show your personal merged pull request history, operate the beta, and keep the service safe. It does not sell personal data or use your GitHub activity for advertising.

Effective: 10 September 2026

Who is responsible

The data controller for Pull Tally is Stein J. Gran in Norway. For privacy questions or requests, email support@pulltally.com.

This policy covers the invite-only Pull Tally beta at pulltally.com.

Data Pull Tally processes

GitHub identity and access

Pull Tally receives your numeric GitHub user ID, current login, avatar URL, and authorization status. It stores protected GitHub access and refresh tokens while your account is active.

It also stores the minimum installation state needed to explain coverage. This includes installation and account IDs, owner login, repository selection, installation URL, and current state.

Pull request details

Pull Tally reads repository names, pull request numbers, titles, links, authorship, and merge times from GitHub. It keeps these details only in server memory for up to five minutes and does not save them in its database.

Account and beta records

When you join the waiting list, you verify your GitHub account and Pull Tally requests your email addresses using GitHub's read-only Email addresses account permission. The API can return multiple addresses; we select and store only your primary verified email and discard the other addresses without logging them. If no suitable address is available, you can enter one. You can also choose a different contact address after signup. Pull Tally stores that address with your GitHub identity, the collection time, and the version of the notice shown. The selected GitHub address may be private on your profile. Manually entered addresses are not independently verified. Email is never used to authenticate you or grant access, and is not continuously synchronized from GitHub.

Authorized beta operators can see your email to contact you about your beta application and invitation. It is not displayed publicly, included in page analytics or operator push notifications, or used for marketing. Providing it is part of the online waitlist request. You can later ask us to remove it without losing approved beta access.

Pull Tally stores your beta access state, session digest and expiry, waitlist or invitation state, and coded service events. These events record actions such as sign-in success, a completed tally, a failure category, or account closure.

If you answer an offer or research prompt, Pull Tally stores the selected code and the version of the question. It does not need free-text answers for these prompts.

Cookies, logs, and page analytics

Pull Tally uses secure, HTTP-only cookies for sign-in and request protection. These cookies are necessary for the service and are not advertising cookies. After GitHub verification, a protected contact-management cookie lasts for 20 minutes so you can view a masked address or change it without beta admission. It contains no email or GitHub credentials.

The service keeps limited operational and security logs. It avoids logging credentials, cookie values, request bodies, GitHub IDs, repository names, and pull request content.

Pull Tally uses Vemetric for basic page-view analytics when its project token is enabled. Vemetric receives the page, referrer, device information, approximate location, IP address, and browser user agent. It creates an anonymous visitor hash with a salt that changes daily and does not set an analytics cookie by default.

Pull Tally does not identify signed-in users to Vemetric. It does not send custom product events or track outbound links through Vemetric.

Why the data is used

Provide the service you request
To verify your account, manage beta access, read GitHub data, and show your tally.
Keep Pull Tally safe and reliable
For authentication, abuse prevention, fault diagnosis, backup, recovery, and security response.
Contact you about beta access
To follow up on the application you submit and contact you when access is approved. We rely on our legitimate interest in administering the requested beta application (GDPR Article 6(1)(f)). You can object to this use and ask us to remove your email at any time.
Understand basic service use
To review anonymous page traffic and coded service outcomes without building an employee or activity profile.
Record an optional answer
Only when you choose to answer an offer or research prompt. You can remove these answers at any time.

The first purpose is necessary to provide the service or take steps you request. Safety, reliability, and limited analytics support Pull Tally's legitimate interests in operating a dependable service. Optional answers rely on your choice and can be withdrawn without losing beta access.

Pull Tally does not use automated decision-making or profiling to decide your access, price, or treatment.

Service providers and locations

  • GitHub provides identity, authorization, installation, and pull request data. GitHub operates globally.
  • Hetzner hosts the application and database in Nuremberg, Germany.
  • Vemetric processes cookieless page analytics on servers in the European Union when analytics is enabled.

Pull Tally shares data with a provider only for the service described here. It may also disclose data when the law requires it or when this is necessary to protect users and the service.

How long data stays

  • Pull request details leave the server-memory cache within five minutes.
  • Signed-in sessions end after eight idle hours and have a 24-hour maximum.
  • GitHub webhook delivery IDs are kept for seven days to reject duplicate deliveries.
  • Account and beta records stay while your account or waitlist request is active, unless a shorter expiry applies.
  • Your waitlist email and its collection metadata are removed from the live database by the regular cleanup after 180 days from your latest submission, or earlier when your request is rejected, your account is restricted or deleted, or your removal request is handled. Approval does not restart this period.
  • Optional offer and research answers stay until you remove them, delete your account, or the beta no longer needs them.
  • Encrypted recovery copies expire after 14 days.

After restriction or deletion, Pull Tally keeps a keyed deletion marker for up to 14 days. This prevents an old backup from restoring access. The marker then loses its account link.

Pull Tally may keep a record longer when the law requires it or a live security incident needs it. It will limit that record to the necessary purpose.

Your choices and rights

Signed-in users can use Account controls to:

  • open a machine-readable export;
  • remove the waitlist email and optional offer and research answers;
  • restrict the account and end access; or
  • delete eligible live account data.

You can also ask for access, correction, deletion, restriction, portability, or an objection by email. Pull Tally may need to verify that the GitHub account belongs to you before acting.

If you are still waiting for access, email support@pulltally.com to correct or remove your address, obtain your data, or delete your waiting-list request. You do not need an approved account to make a request. We will verify the request against your GitHub identity. Removing the address means we cannot contact you there about approval; you can still sign in with GitHub once approved.

You can complain to the Norwegian Data Protection Authority or your local data protection authority.

Changes to this policy

Material changes will appear here with a new effective date before they apply. Pull Tally will give active users a clear notice when a change affects how their data is used.

Pull Tally lost its connection. Reload

Reconnecting…

Connection interrupted. We’re trying to reconnect.

Displayed results may be out of date. Actions are paused until you reconnect.