Data Protection Statement
Last updated: August 2026
Draft note: we're rewriting this statement ahead of launch and it has not had a legal review yet. Please don't treat it as final, and tell us if anything here looks wrong or needs filling in.
This statement explains how Changeloop collects, uses, and protects personal data, in accordance with Regulation (EU) 2016/679 (GDPR).
What is the GDPR?
The GDPR (Regulation (EU) 2016/679) is the European data protection regulation. It governs how organisations may collect, use, and store the personal data of people in the European Union, and what rights those people have over their data.
What data does Changeloop store?
We store your account data and the data from your GitHub integration (installation ID, repository metadata, and the titles and bodies of merged pull requests, used to draft changelog entries; we do not store your source code), which you can view by logging into your account. We also store the invoices issued for each payment, for accounting purposes. If you use our feedback widget on your own site, we also store data submitted by your visitors through it; see the next question.
Do you collect data about my customers' visitors too?
Yes, if you use our feedback widget on your own site. When one of your visitors submits feedback through it, we store their email address and message, a randomly generated submission reference, and, once one is created, the GitHub issue it results in. We automatically remove the visitor's email address from their message before it is used to classify the submission or included in the GitHub issue we create in your repository, so neither your issue tracker nor our AI classification provider ever sees it. For this data we act as your processor, and you are the controller; please treat any request from your own visitor about their submission the way you would any other data request about your site, and we're happy to help. Your visitor can check the status of their own submission using the private link they were given when they submitted it; we do not currently send them status update emails ourselves.
Why does Changeloop store this data?
We use this data for account login, drafting and publishing changelog entries from your merged pull requests, managing your subscription, and, where you have enabled the feedback widget, for processing your visitors' feedback submissions on your behalf as described above.
How to reach us?
You can write to us at any time at contact@changeloop.dev for anything regarding your data.
How to withdraw your consent?
If you would like to withdraw your consent for us processing your data, write to us at contact@changeloop.dev and we will action your request.
Where do we have your data from?
Most of the data we hold was provided to us by you:
- when you created your account on the Changeloop platform;
- when you connected your repositories through the GitHub App.
Why are you emailing me?
The emails you receive from us are:
- notifications about your account and the changelog entries you publish;
- emails about the subscription you have with us.
How do I request access to my data?
To request access to your data:
- log into your account;
- go to your account details, the "Request my data" section;
- click "Request data";
- or go directly to https://changeloop.dev/request-my-data and submit the request.
Who are the sub-processors that Changeloop uses?
To provide the service, we work with the following sub-processors:
- Stripe: secure payment processing;
- Amazon AWS: secure hosting and storage of data and invoices;
- OpenAI: drafting changelog entries from your merged pull requests, and classifying feedback-widget submissions by type and priority (message text only; the submitter's email address is removed before it is sent to OpenAI);
- our email provider: sending notifications and transactional messages.
Who is the Data Protection Officer for Changeloop?
For any request regarding the protection of personal data, you can contact us at contact@changeloop.dev.