Trust and access

A narrow view of your own work.

Pull Tally reads GitHub data to show pull requests you authored and GitHub records as merged, and to contact you about beta access. It does not score productivity or provide employee surveillance.

Last reviewed: 10 September 2026

GitHub permissions

GitHub Apps have no permissions by default. Pull Tally asks for two read-only repository permissions, one read-only account permission for email addresses, and no write permissions.

Pull requests
Read-only
Used to find pull requests you authored and GitHub records as merged.
Metadata
Read-only
GitHub includes this permission so the App can identify connected repositories and their owners.
User authorization
No additional OAuth scopes
Used to identify your GitHub account and make read requests within both your access and the App's access.
Email addresses (account permission)
Read-only
Used during waitlist signup to select your primary verified email for beta access updates. GitHub returns a list of addresses; we retain only the selected one and discard the rest. You can choose another contact address. We do not use it for marketing.

Pull Tally does not request permission to change source code, pull requests, issues, repository settings, or organization settings. GitHub shows the requested permissions before you authorize or install the App.

What Pull Tally can see

Access is the intersection of two choices:

  • the repositories your GitHub account can access; and
  • the repositories connected through the Pull Tally GitHub App.

Public repository results can appear without an App installation for that owner. Private results require an installation that includes the repository. An installation limited to selected repositories gives partial coverage.

Pull Tally reports that coverage limit in the dashboard. It does not claim that a total covers repositories GitHub did not return.

How the service handles the data

  • Pull request details are fetched from GitHub when you load a month.
  • Those details stay in a server-memory cache for up to five minutes. They are not saved in the database.
  • GitHub access and refresh tokens are protected before they are stored.
  • Browser sessions expire after eight idle hours and never last longer than 24 hours.
  • Account controls let you export your data, remove optional responses, restrict access, or delete your account.

See the privacy policy for the complete data list, retention details, analytics, and your choices.

You remain in control

You can change or remove a GitHub App installation from GitHub's installation settings. You can also revoke user authorization in your GitHub settings.

Signed-in users can open Account controls to export or delete their Pull Tally data. Uninstalling the App and deleting a Pull Tally account are separate actions.

Pull Tally lost its connection. Reload

Reconnecting…

Connection interrupted. We’re trying to reconnect.

Displayed results may be out of date. Actions are paused until you reconnect.