Datenschutzerklärung
Zuletzt aktualisiert: Oktober 2026
Diese Erklärung beschreibt, welche Daten wir erheben, warum wir das tun und welche Rechte Sie haben, gemäß Verordnung (EU) 2016/679 (DSGVO).
Der vollständige Text dieser Seite liegt nur auf Englisch vor, maßgeblich ist die englische Fassung.
1. Data controller
The controller of your data is LoadFocus LTD, trading as Changeloop, a company registered in England and Wales under company number 09554514, with its registered office at 4 Grayscroft Road, London SW16 5UP, United Kingdom. You can contact us at contact@changeloop.dev.
2. What data we collect
Account data (name, email address, and email via GitHub OAuth where you use it to sign in); source integration data (for a GitHub App installation, the installation ID and repository metadata; for a GitLab or Bitbucket connection, the project path, the address of your self-managed GitLab server where you use one, the branch you name and the webhook secret we issue; for every source, the titles and bodies of merged pull requests or merge requests and, if you choose push mode on Bitbucket, the messages of pushed commits, which we use to draft changelog entries and delete once drafting finishes, except that we keep the title of a change we skip or that arrives over your plan's limit, so you can review it; we also use the title and body of a GitHub issue you label for the roadmap to draft its roadmap item, and delete them once drafting finishes, whether or not the draft succeeds; we do not store your source code); billing data (invoices and subscription status from Stripe, for paid Team plan accounts); technical usage data (logs, cookies, including the session cookie that keeps you logged in). If you enable the embeddable feedback widget on your own site, we also collect data from your visitors who submit feedback through it, on your behalf (see section 6 below).
3. Purposes of processing
We use the data to draft and publish changelog entries from your merged pull requests, merge requests or pushed commits, manage your account and subscription, provide support, improve the service, and, where a customer has connected GitHub and enabled the feedback widget, to record their visitors' submissions and create the corresponding issue in that customer's GitHub repository.
4. Legal basis
Processing is based on the performance of the contract (providing the service), on your consent where applicable, and on the legitimate interest of securing and improving the platform. Feedback submitted through the widget is processed under our contract with the customer who enabled it, and on the basis that the person submitting it chose to do so voluntarily.
5. GitHub access
To provide the service we access your repository metadata and the titles and bodies of merged pull requests through your GitHub App installation, using short-lived installation tokens rather than long-lived personal access tokens. The GitHub App has no permission to read your repository's files. GitLab and Bitbucket send us the same kind of data through the webhook you configure, along with commit messages if you choose push mode on Bitbucket, and we hold no access token for them. If you use Connect with Bitbucket, Bitbucket issues us a token that can read the repository and its pull requests and manage its webhooks (Bitbucket requires the pull request permission for a webhook that reports merged pull requests); we use it within a single request to read the repository's main branch and add the webhook, and we do not store it. We do not store your source code.
6. Feedback widget data (visitors to our customers' sites)
If one of our customers enables our feedback widget on their own website, a visitor to that site can submit a short message and an email address through it. We store both, together with a randomly generated submission reference and, once one exists, the GitHub issue it results in. Before the message is used to classify the submission or included in that issue, we automatically remove the submitter's email address from it, so the resulting GitHub issue and our AI classification provider never see it; only the message text does, with the email address stripped out. For this data we act as a processor on behalf of the customer whose widget was used; that customer is the controller, and a request about this data should usually go to them, though we are happy to help too. The person who submitted the feedback can check its status using the private link they were given at submission time. We do not currently send status emails ourselves.
7. Storage and security
Data is stored on secure servers and protected by reasonable technical and organisational measures. Access is limited to the purposes described above.
8. Data sharing
We do not sell your data. We may share it only with service providers (for example hosting, email) acting as processors, under appropriate safeguards, or where the law requires it.
9. Retention period
We keep data for as long as it is needed for the purposes described above (for account data, typically for as long as you have an active account), or as required by law. Afterwards, we delete or anonymise it.
10. Your rights (GDPR)
You have the right of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw your consent. To exercise them, write to contact@changeloop.dev. You also have the right to lodge a complaint with your local data protection supervisory authority. If you submitted feedback through a customer's embedded widget rather than holding an account with us, that customer is usually the right party to contact, since they are the controller for that data; you are welcome to write to us as well and we will help.
11. Cookies
We use essential cookies for the platform to function and, optionally, analytics cookies to understand how the site is used.
12. Changes and contact
We may update this policy; changes will be published here. For any question regarding your data: contact@changeloop.dev.