Skip to content
Mercury11
How it works Pricing Security Sign in Try it with one file

Privacy Policy

Effective September 26, 2026. Mercury11 LLC, Colorado, USA.

Mercury11 connects the tools a business already uses, reads their records, and answers questions about them. That means we hold data you care about. This policy explains what we collect, why, how long we keep it, and what you can do about it. It is written to be read, not skimmed. If anything here is unclear, ask us at privacy@mercury11.com.

Who this covers

This policy applies to mercury11.com and the Mercury11 application at app.mercury11.com and its subdomains (together, the Service). It covers visitors to the website, people who try the Service with a file upload, and people who create or use an account. When a business connects its systems to Mercury11, the business is the owner of that data and we process it on the business’s behalf.

What we collect

Account information. Your name, email address, password (stored only as a salted hash), the business you belong to, and your role in it.

Connected source data. When you connect a system such as a payment processor, accounting package, advertising account or CRM, we read records from it and store a copy so questions answer quickly. Which records depends on the source, and each source shows what it provides before you connect it. Connections are read-only. We test every key and permission for write access before accepting it and refuse any that could change your records.

Connection credentials. The keys and sign-in tokens that let us read your sources. These are encrypted with a managed key service, usable only by your business’s account, and never written to logs, error messages or support tools.

Uploaded files. Spreadsheets and exports you drop into the Service.

What you tell us about your business. When Mercury11 finds something unusual, it asks you a question. Your answers are stored as rules, along with who answered and when. Your questions and the answers we gave are stored so you can return to them.

Usage and technical information. Pages visited, features used, browser and device type, IP address, and the timing of requests. On the website we use analytics tools for this. In the application we keep an access log that records who read which data and when, because we think you should be able to see that.

Billing. Payments are processed by Stripe. We receive the last four digits of your card, its expiry, and your billing address. We never see or store the full card number.

How we use it

  • To provide the Service: read your sources, find where they disagree or change, ask you about it, and answer your questions.
  • To keep your account secure and to investigate misuse.
  • To bill you and to send receipts, notices about your account, and alerts you have turned on.
  • To improve the Service, using aggregate usage patterns that do not identify any business’s records.
  • To respond when you contact us.

What we never do

  • Train any machine learning model on your business data.
  • Sell your data, share it with advertisers, or benchmark your numbers against another business’s.
  • Write anything back into a system you have connected.
  • Ask for the password to any of your systems. Connections use a vendor sign-in or a scoped key.

The AI part

Answering a question involves a large language model run by a third-party provider. The model reads your records through the same read-only path as everything else. Our agreement with the provider does not allow it to use your data to train its models. The model never decides what your numbers mean on its own. That comes from the rules you have given us, which you can read, edit and remove at any time.

Google user data

Some sources connect through Google sign-in, such as Google Ads, Google Analytics and Search Console. Mercury11’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide the features you connected it for, we do not transfer it to others except as needed to provide the Service or as required by law, we do not use it for advertising, and no human reads it except with your permission, for security, or to comply with the law.

Who can see your data

Each business gets its own isolated database, with credentials that can only reach that one business’s records. Within your business, admins decide who can connect sources, who can answer questions and write rules, and who can only ask.

We share data with service providers only as needed to run the Service: cloud hosting, the language model provider, email delivery, payment processing, and website analytics. Each is bound by contract to use the data only to provide their service to us. We will disclose data if the law requires it, and we will tell you when we are allowed to. If Mercury11 is ever acquired, your data would move with the Service under this policy, and you would be told before anything changed.

How long we keep it

  • Trial uploads without an account are deleted within one hour of being read.
  • Connected source data is deleted, not archived, when you disconnect the source.
  • Uploads on an account stay in your own storage until you remove them.
  • Everything in your account is deleted when you close the account. Before you do, you can export every rule and answer you have given us, because what you have told us about your business belongs to you.
  • Billing records are kept as long as tax and accounting law requires.
  • Backups roll off within 30 days of deletion.

Your choices

You can see and change your account information in Settings, disconnect any source at any time, export your rules and answers, and close your account. If you are in a place that gives you legal rights over your personal data, such as the right to access, correct, delete or port it, or to object to how it is used, you can exercise them by emailing us. We will not treat you differently for doing so. If you are a member of a business account, some requests go through that business’s admin, because they own the data.

Cookies

The application uses a session cookie to keep you signed in and a security token to prevent forged requests. Neither tracks you across other sites. The website uses analytics cookies to understand how it is used; you can block these in your browser without affecting the Service.

Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect information from children.

Changes

If we change this policy in a way that matters, we will email account holders before it takes effect and note the new date at the top. Small clarifications may be made without notice.

Contact

Mercury11 LLC
Lone Tree, Colorado, USA
privacy@mercury11.com

© 2026 Mercury11
How it works Pricing Security Privacy Terms of Service