Privacy Policy
Last updated: August 2026
Draft note: we're rewriting this policy ahead of launch and it has not had a legal review yet. Please don't treat it as final, and tell us if anything here looks wrong or needs filling in.
This policy explains what data we collect, why, and what your rights are, in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data controller
The controller of your data is [Company name], reg. no. [__________], with its registered office in [address]. You can contact us at contact@changeloop.dev.
2. What data we collect
Account data (name, email address, and email via GitHub OAuth where you use it to sign in); GitHub integration data (installation ID, repository metadata, and the titles and bodies of merged pull requests, used to draft changelog entries; we do not store your source code); billing data (invoices and subscription status from Stripe, for paid Team plan accounts); technical usage data (logs, cookies, including the session cookie that keeps you logged in). If you enable the embeddable feedback widget on your own site, we also collect data from your visitors who submit feedback through it, on your behalf (see section 6 below).
3. Purposes of processing
We use the data to draft and publish changelog entries from your merged pull requests, manage your account and subscription, provide support, improve the service, and, where a customer has enabled the feedback widget, to record their visitors' submissions and create the corresponding issue in that customer's GitHub repository.
4. Legal basis
Processing is based on the performance of the contract (providing the service), on your consent where applicable, and on the legitimate interest of securing and improving the platform. Feedback submitted through the widget is processed under our contract with the customer who enabled it, and on the basis that the person submitting it chose to do so voluntarily.
5. GitHub access
To provide the service we access your repository metadata and the titles and bodies of merged pull requests through your GitHub App installation, in order to draft changelog entries. We use short-lived installation tokens, not long-lived personal access tokens, and we do not store your source code.
6. Feedback widget data (visitors to our customers' sites)
If one of our customers enables our feedback widget on their own website, a visitor to that site can submit a short message and an email address through it. We store both, together with a randomly generated submission reference and, once one exists, the GitHub issue it results in. Before the message is used to classify the submission or included in that issue, we automatically remove the submitter's email address from it, so the resulting GitHub issue and our AI classification provider never see it; only the message text does, with the email address stripped out. For this data we act as a processor on behalf of the customer whose widget was used; that customer is the controller, and a request about this data should usually go to them, though we are happy to help too. The person who submitted the feedback can check its status using the private link they were given at submission time. We do not currently send status emails ourselves.
7. Storage and security
Data is stored on secure servers and protected by reasonable technical and organisational measures. Access is limited to the purposes described above.
8. Data sharing
We do not sell your data. We may share it only with service providers (for example hosting, email) acting as processors, under appropriate safeguards, or where the law requires it.
9. Retention period
We keep data for as long as it is needed for the purposes described above (for account data, typically for as long as you have an active account), or as required by law. Afterwards, we delete or anonymise it.
10. Your rights (GDPR)
You have the right of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw your consent. To exercise them, write to contact@changeloop.dev. You also have the right to lodge a complaint with your local data protection supervisory authority. If you submitted feedback through a customer's embedded widget rather than holding an account with us, that customer is usually the right party to contact, since they are the controller for that data; you are welcome to write to us as well and we will help.
11. Cookies
We use essential cookies for the platform to function and, optionally, analytics cookies to understand how the site is used.
12. Changes and contact
We may update this policy; changes will be published here. For any question regarding your data: contact@changeloop.dev.