We are asking for your books. Here is exactly what we do with them.
You should not have to take a vendor’s word for this. Everything below is a design decision we made on purpose, not a policy we wrote afterwards.
Read-only, and we check
Every connection uses read permissions only. When you paste a key, we test its scope before we accept it and reject anything that can write. Mercury11 cannot create an invoice, issue a refund, move money, or change a record in any system you connect. Not by policy. By permission.
Your data sits on its own
Each business gets its own isolated database, with credentials that can only reach that one business’s records. This is not a filter applied at query time that someone could get wrong. It is enforced underneath, where a mistake returns an error instead of somebody else’s numbers.
Leaving takes one click
Disconnect any source and everything we hold from it is deleted, not archived. Close your account and the whole database goes with it. Before you do, you can export every answer you have given us, because what you have told us about your own business belongs to you.
Files are read once
If you try us with an upload and do not make an account, the file is deleted within the hour. If you do make an account, uploads live in your own storage and you can remove any of them at any time.
What we store
A copy of the records we read, so questions answer in a second rather than a minute
The answers you give us about what your data means, with who gave them and when
Your questions and the answers we gave, so you can go back to them
Connection credentials, encrypted, usable only by your account
What we never do
Train any model on your business data
Sell, share or benchmark your numbers against anyone else’s
Write anything back into your systems
Ask for a password. Connections use sign-in or a scoped key, never your login
On the AI part, specifically
Answering a question involves a language model, and people reasonably want to know what that means for their records. Two things: the model only ever reads, through the same read-only path everything else uses, and nothing it sees is retained by the model provider for training.
More importantly, the model never decides what your numbers mean. That comes from the answers you gave us, which are stored as plain rules you can read, edit and remove. If an answer looks wrong, you can see exactly which rule produced it.
Still want to ask something?
Security questionnaires, a DPA, or a specific question about your own compliance requirements. We would rather answer it than have you guess.