PR Marmot privacy policy
PR Marmot collects nothing. What the apps store on your device, the one service they talk to, and how to reach us.
What this covers
This policy covers PR Marmot for macOS and Linux, the prmarmot-cli terminal tool that ships inside it, and PR Marmot for iPad. They are published by IdeaX, s.r.o., Vavrinca Ottmayera 3, 010 04 Žilina, Slovakia.
Privacy questions go to oliver@ideax.sk.
Effective 2026-09-20. It applies to every version of each app that is available while it is in force.
What we collect: nothing
The apps collect no data about you. There is no analytics, no crash or diagnostic reporting, no advertising, and no tracking of you across other apps or websites. Nothing asks you for an App Tracking Transparency permission, because there is nothing to track.
There is no PR Marmot account and no server of ours. We cannot see what repositories you open, which pull requests you look at, or that you use the app at all. In App Store terms, that is Data Not Collected.
This section is about the apps. The website you are reading is described further down, and it is not the same thing.
What stays on your device
The apps need a GitHub credential and some state to be useful. All of it stays on the device that created it.
PR Marmot for iPad. The GitHub token is kept in the device Keychain, on that device, and is not synced to iCloud. Cached boards, your settings, and your watch and snooze state live in the app's own container.
Disconnect removes the token, the cached boards, your watches and snoozes, the account file, the items the app put in Spotlight, and every setting that names your repositories: the repository list, pins, per-repository reviewers and scope. Preferences that say nothing about your account stay — appearance, density, refresh interval, and whether notifications are on.
Deleting the app removes its container, which holds the caches, settings, watches and account file. It does not remove the Keychain item, because iOS keeps those when an app is deleted. Disconnect is what removes the token, so use it first if you want the credential gone from the device.
Desktop and CLI. PR Marmot uses the GitHub CLI login you already have, or a token you sign in with. On macOS that token is kept in your login keychain under the service dev.prmarmot.auth; on Linux, and on macOS if you ask for it, in a file readable only by you. Preferences live in config.toml under your configuration directory, and watches, snoozes and change markers under your state directory. Settings → Disconnect, or prmarmot-cli auth logout, removes the token from that machine; deleting those two directories removes the rest.
Removing the token here does not revoke PR Marmot's access at GitHub. That is a separate step you take at your GitHub applications settings, and it has to be, because doing it from the app would require a client secret that PR Marmot does not have.
Who the apps talk to
One service: GitHub. The apps only ever contact the GitHub host you signed in to, because every request URL is built from that host — github.com, or your GitHub Enterprise Server host. They use your own credential, on your behalf. There is no other server and no backend of ours.
What you do at GitHub is covered by GitHub's own terms: see the GitHub General Privacy Statement. Links you open from the apps — a pull request, a check, a settings page on that host — open in your browser and leave the app behind. One link is fixed rather than built from your host: Settings offers the open-source desktop repository on github.com.
The desktop app also checks for its own updates: on launch and at most once a day it reads the latest stable release information from GitHub, and nothing else. The iPad app has no update check of its own; the App Store handles that.
Notifications and search
Notifications are produced on your device by the app itself, from data it has already fetched for you. They are not push notifications from a server of ours, because there is no server of ours.
Anything the iPad app contributes to Spotlight is indexed on the device and stays there.
Children
No data is collected from anyone, children included. Nothing in these apps is directed at children, and they contain no advertising, no social features and no user-generated content of their own.
PR Marmot for iPad is rated 4+ in the App Store.
This website
Separate from the apps: prmarmot.dev measures page views with Plausible, which is cookieless and aggregate. It sets no cookies, stores nothing on your device, and does not build a profile of you or follow you to other sites. The one event beyond page views records that an install command was copied, and which of the three it was — not who copied it.
The site is served by Cloudflare, which processes the request your browser makes, as any web host does. There is no account, no login, and no form on this site.
Your rights, and the law
IdeaX, s.r.o. is established in the European Union, at Vavrinca Ottmayera 3, 010 04 Žilina, Slovakia, company registration number 50822136. For the purposes of the GDPR it would be the controller of any personal data these apps processed about you.
It processes none. Because nothing about you reaches us, there is no file of yours to access, correct, export, restrict or erase, and no consent to withdraw. The data the apps hold is on your own device, under your control, and the section above says how to remove it.
The data you read through the apps is your own GitHub data, and your rights in it are exercised with GitHub. If you believe otherwise, or want any of this explained, write to oliver@ideax.sk. You also have the right to complain to your national data protection authority.
Changes to this policy
This policy is effective 2026-09-20. Changes are published on this page, with a new effective date. There is no mailing list to notify, because we do not have your address.