Privacy Policy
Last updated: February 21, 2026
This Privacy Policy describes how Gorilli ("we", "us", or "our") collects, uses, and protects your personal information when you use the Engammo platform (the "Service"). We are committed to protecting your privacy and handling your data transparently.
1. Information We Collect
Account Information
When you sign up through GitHub OAuth, we receive your GitHub profile information including your name, email address, username, and avatar URL. We use this information to create and manage your Engammo account.
Repository and Pull Request Data
When you connect repositories to Engammo, we access pull request data from those repositories including PR titles, descriptions, labels, timestamps, author information, and commit messages. This data is used to generate release notes.
We process pull request diffs in memory during AI analysis. Diffs are not persisted to disk or stored in our database. Only the generated release note content and PR metadata are stored.
Usage Data
We collect basic usage analytics including pages visited, features used, and session duration. This data helps us understand how the Service is used and improve the user experience. We do not use third-party advertising trackers.
What We Do Not Collect
- Source code files or full repository contents
- Private keys, tokens, or secrets from your codebase
- Data from repositories not explicitly connected to Engammo
- CI/CD pipeline data or deployment artifacts
- Browser fingerprinting data
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Generate AI-powered release notes from your pull request data
- Manage your account and subscription
- Send transactional emails (account notifications, billing receipts)
- Respond to support requests
- Analyze usage patterns to improve the product
We do not use your pull request data or generated release notes to train AI models. Your data is used exclusively to provide the Service to you.
3. Data Storage and Security
Your data is stored on servers provided by industry-leading cloud infrastructure providers. All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
Access to production systems is restricted to authorized personnel through multi-factor authentication and role-based access controls. We conduct regular security reviews and follow industry best practices for data protection.
4. Data Sharing
We do not sell your personal information or share it with third parties for marketing purposes. We may share data with:
- Infrastructure providers: Cloud hosting, database, and CDN services that process data on our behalf under strict data processing agreements.
- AI processing services: We use third-party AI services to generate release note summaries. Only the PR data necessary for generation is sent. These services do not retain your data after processing.
- Legal compliance: We may disclose data if required by law, court order, or governmental regulation.
5. Data Retention
We retain your account data and generated release notes for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for reactivation, after which it is permanently deleted.
You may request immediate deletion of your data at any time by contacting us at [email protected]. We will process deletion requests within 30 days.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict certain processing of your data
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at [email protected]. We will respond to requests within 30 days.
7. Cookies
We use essential cookies to maintain your session and remember your authentication state. We use analytics cookies to understand how the Service is used. You can disable non-essential cookies in your browser settings without affecting core functionality.
8. International Data Transfers
Your data may be processed in countries outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses approved by relevant data protection authorities.
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
11. Contact
For questions about this Privacy Policy or our data practices, contact us at [email protected].