DeployBell

Privacy Policy

Last updated:

DeployBell is a macOS app for reviewing GitHub deployment approvals, receiving notifications, and generating optional AI change assessments. This policy describes app processing separately from visits to this website and support requests.

Operator and privacy contact

app.limit UG (haftungsbeschränkt)
Bonhoefferstraße 24/2, D-73760 Ostfildern, Germany

For privacy questions or requests concerning your personal data, contact support@mevodo.com.

Operator details

Local file processing

DeployBell stores account metadata, configuration, approval history, and saved AI assessments in a local SwiftData database. Decisions can include the actor, date, comment, and a copy of the assessment available at the time.

Account configuration, approval history, and saved assessments can synchronize through Apple’s private CloudKit container. AI agent selections stay on this Mac.

Clipboard access

When you choose to copy the GitHub sign-in code, DeployBell writes that code to the clipboard so you can paste it on GitHub.

Temporary files and cleanup

Optional AI assessments run the selected CLI in an isolated temporary working directory. Temporary input and output are cleaned up after execution; this does not guarantee secure deletion or cleanup after a crash.

Saved assessments contain the assessment text, ratings, explanations, comparison basis, limitations, and a technical lookup key. Raw patches, prompts, workflow job payloads, and raw CLI output are not saved in the CloudKit-backed assessment database.

Keychain access

GitHub credentials and push device signing keys are stored in the macOS Keychain on this Mac. GitHub credentials use non-synchronizing Keychain entries and are not included in CloudKit configuration synchronization.

Analytics

No dedicated analytics SDK was found in the DeployBell app source and package dependencies reviewed for this policy. This finding does not describe logging by external services.

Advertising

No advertising SDK was found in the DeployBell app source and package dependencies reviewed for this policy.

Telemetry

No dedicated telemetry SDK was found in the DeployBell app source and package dependencies reviewed for this policy. GitHub, Apple, the push service, update hosts, and any selected AI provider receive technical request information when their services are used.

Accounts

DeployBell connects to GitHub through GitHub App sign-in or a personal access token. It requests repository, workflow, deployment, and reviewer information to show pending approvals. Approving an eligible environment sends your decision and any comment to GitHub. Token-connected accounts use background polling and local notifications; remote push requires GitHub App sign-in and separate activation.

Cloud processing

DeployBell uses GitHub APIs and Apple’s private CloudKit synchronization. Optional push activation sends your GitHub access token to the configured DeployBell push service for identity verification; the service implementation uses it transiently rather than persisting it. The Bunny-backed push service processes GitHub webhook and approval metadata and stores the GitHub user ID, device public key, and encrypted Apple Push Notification service (APNs) token. Apple receives notification delivery and routing metadata, including account, repository, and workflow run identifiers; the push payload contains no code diffs or AI summaries. Disabling push revokes the registration and removes its APNs token, but does not imply deletion of every service record. Optional AI assessments pass available code changes and workflow results to your selected, signed-in Codex or Claude Code CLI, which may send this data to its external AI provider under your provider account and settings. DeployBell does not include GitHub credentials in the assessment prompt. Monitoring and manual approvals work without AI enabled.

Updates and distribution

Direct download — available version

The direct-download version uses Sparkle with an update feed and release downloads hosted on GitHub. Update checks and downloads send network requests to the receiving services, including your IP address and technical request information. Automatic update checks can be managed in Settings.

Website hosting and downloads

This website is delivered through Bunny Storage and Bunny CDN. Loading pages involves network requests to the hosting service, including your IP address and the requested resource. The website source does not include analytics scripts, advertising trackers or application cookies. Fonts and images are served with the website.

On product pages with a GitHub download button, your browser automatically requests the latest release information from GitHub’s API. GitHub receives your IP address and the technical request information. Following a release or download link also connects you to GitHub. These website requests are separate from the app’s update checks and document processing.

Support requests

If you email us, your message, sender address and any attachments you choose to include are provided to us for handling your request. This is separate from processing documents in the app. Only include information needed to explain your question; avoid sending confidential documents or private keys.