Privacy Policy
Last updated: 16 September 2026
How Happo LLC collects, uses, and shares information when you use Merrykat. These practices go with our Terms of Service.
Who we are
Merrykat is operated by Happo LLC, a limited liability company organized under the laws of the State of Delaware, United States (registered office: 850 New Burton Rd, Suite 201, Dover, DE 19904). In this policy, “Happo”, “we”, and “us” mean Happo LLC.
This policy covers merrykat.dev, app.merrykat.dev, and the Merrykat service. It does not cover third-party sites or services we link to, including your source-control provider and our payment processor.
For personal data we collect to operate Merrykat as a product — accounts, billing, the website, support — Happo is the controller. For Customer Content an organization uploads so we can run the Service for it (Storybook builds, diffs, screenshots, run results), that organization is the controller and Happo processes the data on its behalf. If you use Merrykat through an organization, some privacy requests should go to that organization first.
Information we collect
We collect the kinds of information listed below. We do not collect government identifiers, payment card numbers, or other sensitive personal information as a product feature, and we ask that you not put that kind of data in Customer Content.
From you, your organization, and your source-control provider
- Identity and account details needed to sign you in and show who is using a workspace: a user identifier, display name, avatar, and any email the provider supplies.
- Installation details: which source-control account Merrykat is connected to, which repositories it covers, and who connected it.
- Review metadata needed to comment on a review and report a status: for example titles, numbers, commit identifiers, and author logins.
- Payment and billing details, handled by our payment processor. We do not store card numbers.
- What you send us in support, security, or other email, including attachments.
Customer Content
To provide the Service we process what you upload from CI and what we derive from it: static Storybook builds, the git diff of the pull request under review (unless you turn that off), screenshots of stories that differed, comparison and accessibility results, and the text of comments and statuses we post back. Unchanged screenshots are not kept. Stories are rendered in isolation. The browser that takes the screenshot has no network access, except to hosts you have allowlisted.
Information collected automatically
- Logs: browser type, IP address, timestamps, pages viewed, and similar technical data, as recorded by the Service and our hosting provider.
- Product usage: runs, plan changes, and similar records a workspace’s billing page already shows its owners.
- Analytics on the website and application, used to understand how the Service is used, not to advertise to you on other sites.
How we use information
We use information to:
- provide, maintain, secure, and support the Service;
- create and administer workspaces, sign-in, and access control;
- process payments and keep billing records;
- communicate about the Service, including security and support;
- monitor abuse, debug, and protect the Service and our users;
- understand usage in aggregate so we can improve Merrykat;
- comply with law and enforce our Terms.
We do not use Customer Content to train models. When AI features are on, selected screenshots, metrics, and (unless you disable it) excerpts of a change are sent to a third-party model provider so the Service can shortlist and explain visual changes. That provider receives only what the feature needs for that run. You can turn the feature off in configuration.
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you. Model output is for human review of UI changes; it does not decide employment, credit, or similar matters.
Legal bases (EEA, UK, and Switzerland)
Where those laws apply, we process personal data on these bases:
- Contract. To provide the Service you have asked for, including sign-in, runs, comments, statuses, and billing.
- Legitimate interests. To secure and improve the Service, prevent abuse, and understand how it is used, in ways that do not override your interests or rights.
- Legal obligation. When we must keep or disclose information to comply with law, a regulator, or a valid legal process.
- Consent. Where we ask for it. You can withdraw consent at any time without affecting processing that already happened.
When we process Customer Content for an organization, we do so on that organization’s instructions, under our Terms and any data processing agreement with them.
How we share information
We share personal information only as follows:
- Service providers who help us operate Merrykat, under contracts that limit their use of it. That includes hosting and storage, source-control integration (authentication, events, comments, and statuses), payment processing, AI features when they are enabled, analytics, and error monitoring.
- Your source-control provider, when the Service posts comments and statuses on a review. Visibility follows that provider’s own access rules.
- Legal and safety. If we believe disclosure is reasonably necessary to comply with law, enforce our Terms, or protect Happo, our users, or the public from harm.
- Business transfers. In connection with a merger, financing, or sale of all or part of our business, subject to this policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We may share aggregated or de-identified information that does not identify you.
International transfers
Happo is established in the United States, and the Service is operated from there. If you use Merrykat from the EEA, UK, Switzerland, or another region with transfer rules, your information is transferred to the United States and to other countries where our providers operate. Where required, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms.
Retention
We keep information for as long as a workspace is active and as needed to provide the Service, then delete or anonymize it when it is no longer required — except where we must keep it longer for billing, security, dispute resolution, or legal obligations.
Different kinds of data are kept for different periods. Builds, screenshots, and diffs are kept only as long as they are useful for comparison and review, then removed. Account, workspace, and billing records last for the life of the workspace and for a limited time afterwards as the law requires.
Uninstalling Merrykat marks the installation as deleted. Related stored objects are kept for a short grace period in case the uninstall was accidental, then removed. Uninstalling does not cancel a paid subscription or delete billing records; contact support@happo.io to close a workspace and its billing as well.
Security
We take reasonable technical and organizational measures to protect personal information against loss, misuse, and unauthorized access. Customer Content is stored per installation and is not made public. Diffs are encrypted at rest. Payment cards are handled by our payment processor, not by us. No method of transmission or storage is completely secure.
Suspected vulnerabilities should go to security@happo.io, not to a public issue tracker.
Cookies and similar technologies
The only cookie Merrykat sets is the session cookie, when you sign in. It is required to keep you signed in and to check that you still have access to a repository. It lasts until it expires or you sign out. If you block cookies, sign-in will not work.
We use privacy-oriented analytics that does not set an advertising cookie. Some product analytics may use local browser storage so a reload is not counted twice.
Your choices and rights
You may sign out at any time. You may uninstall Merrykat from the installation settings on your source-control provider. You may disable AI features, or limit what they receive, in configuration. You may opt out of promotional email using the link in those messages; we may still send messages about your account or the Service.
EEA, UK, and Switzerland
If those laws apply, you may have the right to request access to, correction of, deletion of, or a copy of personal information we hold about you; to restrict or object to certain processing; and to withdraw consent. To make a request, email support@happo.io. We will need enough information to verify that the request is yours.
United States
Depending on the US state you live in, you may have similar rights, including to know what personal information we collect, to request deletion or correction, to obtain a copy, and to appeal a refusal. We will not discriminate against you for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, so there is no “do not sell or share” opt-out to apply.
If we process your data for an organization that uses Merrykat, we may direct you to that organization.
Changes
We may update this policy. Changes take effect 30 days after we post them (the date at the top of this page). Continued use after that date is acceptance of the revised policy. If a change is material, we will provide a more prominent notice.
Contact
Privacy questions: support@happo.io. Postal correspondence: Happo LLC, 850 New Burton Rd, Suite 201, Dover, DE 19904, United States.