Privacy Policy
This policy explains what Mercury (“we”, “us”) collects when you visit www.mformercury.com or use the Mercury application, API, CLI and MCP server (the “Service”), why, who else processes it, how long we keep it, and the choices you have. It is written to be read, not skimmed; where a term is used in the Terms of Service it has the same meaning here.
1. Two roles
- Your data (we are the controller): your name, work email, company, password hash, billing details, sign-in and usage records, support messages, and the settings of your workspace.
- Your prospects’ data (you are the controller, we are your processor): the people in your audiences and leads, the LinkedIn profiles, messages and replies your senders exchange, files and notes you attach, and any enrichment results. We process this only to run the Service for you and on your instructions. You are responsible for having a lawful basis to contact these people.
2. What we collect and why
| Data | Why |
|---|---|
| Account details (name, work email, company, country, phone if given) | To open and run your workspace, invoice you, and contact you about the Service. |
| Demo requests (name, work email, company) | To email you a private link to the interactive product demo, and to know who asked to see it. |
| Payment reference (Veem invoice and payment ids, amount, status) | To know a checkout was paid and open the workspace. Card and bank details are entered on Veem, never on Mercury. |
| Connected LinkedIn senders (name, profile, provider account id, status, daily counts) | To send on your behalf, enforce limits and working hours, and show sender conditions. We never store your LinkedIn password. |
| Audiences, leads, conversations, messages, notes, files | To run campaigns and journeys, show the unified inbox and Customer 360, and produce your reports. |
| Enrichment and AI inputs and outputs | To fill AI columns, write messages and find emails when you ask for them. |
| Product analytics and error reports (page views, feature use, browser and device information, session replays with text masked, stack traces) | To understand how the Service is used, fix defects and keep it secure. |
| Support chats (your name, work email, what you type in the chat window, and the page you were on) | To answer questions in the chat on this website and inside the app, and to follow up on what you asked. |
| Server logs and security records (IP address, timestamps, sign-in attempts, API and webhook calls) | Security, abuse prevention, debugging and legal compliance. |
We do not sell personal data and do not use Customer Data to train AI models.
3. Who processes data for us
We use these providers, each under its own contract and security commitments:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, file storage and server functions. |
| Vercel | Hosting of the website and the application. |
| LinkedIn Service | Connecting LinkedIn senders and sending or receiving LinkedIn actions. |
| Veem | Invoicing and payment collection. |
| Anthropic | AI writing and AI audience columns (inputs are your prompts and the lead data you choose to include). |
| AI Ark | Find Contacts searches and email lookup. |
| PostHog | Product analytics and masked session replay. |
| Sentry | Error reporting. |
| ZeptoMail (Zoho) | Transactional email — confirmations, password resets, invitations, and the private link to the interactive demo. |
| SalesIQ (Zoho) | Live chat and the chatbot on this website and in the app. |
| CRMs and tools you connect (HubSpot, Salesforce, Attio, Zoho, Slack, Instantly, Smartlead, Email Bison, Plusvibe, Zapier, Make, n8n) | Only when you connect them, and only the data the integration describes. |
Some providers are outside the country you are in; where required we rely on their standard contractual clauses or equivalent safeguards. We may disclose data when the law requires it, or to protect the Service and its users.
4. How long we keep it
- Workspace data is kept while the workspace is active and for 60 days after a subscription lapses, then deleted.
- Deleting a lead, audience or workspace in the app deletes its data, including messages and files, immediately; backups expire within 30 days.
- Invoices and payment references are kept for as long as accounting law requires (typically 7 years).
- Analytics and error data are kept for up to 12 months; server logs for up to 90 days.
5. Security
Data is encrypted in transit and at rest, access is scoped per workspace at the database level, LinkedIn credentials are held by our connection partner rather than by us, and staff access to Customer Data is limited to support you request. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
6. Your rights and choices
- You can view and change your account details in the app, export your audiences and leads as CSV, and delete leads, audiences or your whole workspace yourself.
- Depending on where you live (including the EU/UK GDPR and India’s DPDP Act) you may have the right to access, correct, delete, restrict or port your personal data, or to object to some processing. Write to hello@mformercury.com and we will respond within 30 days.
- If you are a prospect who received a message through Mercury and want to know what a customer holds about you, tell us and we will pass the request to that customer, or tell you who they are.
- You can opt out of product analytics through your browser’s “Do Not Track” / Global Privacy Control signal, which we honour.
7. Cookies
The website sets no advertising cookies and we do not sell what it knows about you. It stores your pricing selections in your browser’s local storage, and the live chat sets its own cookies and storage so that a conversation follows you from one page to the next and an operator is not handed the same question twice. The application uses strictly necessary cookies and local storage for sign-in and your preferences, the same chat storage, and analytics identifiers as described above.
8. Children
The Service is for businesses and is not directed at anyone under 18.
9. Changes
We will post updates here and, for material changes, tell workspace admins by email or in the app at least 14 days in advance.