Mercury Cloud

Privacy Policy

Last updated: July 15, 2026

1. What this policy covers

This Privacy Policy explains how Mercury Cloud, operated by Cosmic Stack, handles data when you use the Mercury Cloud website, dashboard, APIs, billing flows, and terminal pairing features.

2. Data we collect

  • Account data: name, email address, password hash, role, subscription tier, and authentication/session metadata.
  • Terminal pairing data: pairing codes, linked agent identifiers, connection timestamps, and status metadata used to connect Mercury Agent to your cloud account.
  • Usage data: model IDs, provider routing metadata, token counts, request counts, rate-limit state, costs, and error metadata. This powers usage dashboards, billing controls, and abuse prevention.
  • Memory data: memory entries you sync to the cloud, associated metadata, and embeddings used for semantic search when Qdrant-backed search is enabled.
  • Billing data: plan, subscription status, Paddle customer/subscription identifiers, invoices, tax/VAT metadata, and payment method metadata. We do not receive or store full card numbers.
  • Support data: messages you send to us, diagnostic details you provide, and email correspondence.

3. Paddle and payments

Paid plans and, when enabled, Free plan card validation are processed through Paddle. Paddle may process payment method details, billing address, tax/VAT data, fraud-prevention signals, invoices, and transaction records. Paddle handles PCI-DSS-scoped card data directly.

4. How we use data

We use data to operate Mercury Cloud, authenticate users, connect agents, route model requests, enforce tier limits, show usage, process billing, prevent abuse, respond to support requests, and comply with legal obligations. We do not sell personal data and we do not train models on your data.

5. Retention

Account and billing records are retained while your account is active and as required for tax, accounting, fraud prevention, and legal compliance. Usage records may be retained for cost reporting and abuse prevention. Cloud workspace data may be retained for 30 days after cancellation so you can reactivate, then deleted according to operational schedules.

6. Your rights

You may request access, correction, deletion, or export of your data by emailing [email protected]. Billing and subscription records required by law may be retained even after account deletion.

7. Security

We use HTTPS, hashed passwords, role-based access controls, managed infrastructure, and restricted production access. No system is perfectly secure; report security or privacy concerns to [email protected].

8. Contact

Privacy questions: [email protected]. Billing privacy questions: [email protected].