Legal
Privacy Policy
Last updated: 2026-08-03. Effective immediately.
What we collect
To provide email verification we store: (a) the email address you submit, hashed and cached for one hour; (b) your API keys, stored as SHA-256 hashes; (c) the team that issued the key, and the timestamp of every lookup.
What we don't collect
We don't read the contents of emails. We don't store the message body. We don't track users across the public web.
How long we keep it
Verification cache entries expire after one hour. Usage telemetry is retained for 90 days. API keys are retained until you revoke them or close your account. Audit logs are retained for 90 days.
Subprocessors
Cloudflare (hosting, KV, D1, email). Dodo Payments (billing). Better-auth (session). Each is contractually bound to data-processing terms no weaker than these.
Your rights
Export your data, delete your account, or correct mistakes by emailing privacy@mercury.example.com. We respond within 7 days.
International transfers
Data is stored in Cloudflare's global network. EU customers can request EU-only storage by emailing us.
Children
Mercury is not directed at children under 16. We don't knowingly collect data from children.
Changes
We'll email you 30 days before any material change.
Contact
Email privacy@mercury.example.com.