Legal
Privacy Policy
Effective date: October 24, 2023 · Last updated: September 8, 2026
1. Who We Are and What This Policy Covers
Mercuri is a customer messaging platform that lets businesses send and receive email, SMS, and WhatsApp messages from one inbox, with AI agents that reply, follow up, and book on the business's behalf. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have.
Data controller for account, billing, and website data: Santhe Technology Consulting OPC Pvt LTD, trading as Mercuri. Privacy requests: privacy@mercuri.cx.
This policy covers our website (mercuri.cx), the Mercuri app (app.mercuri.cx), our APIs, and our integrations. It does not cover the privacy practices of our customers, of the messaging networks we deliver through, or of Google and Microsoft.
2. Our Two Roles: Controller and Processor
- When you are a Mercuri customer (a business using our platform), we are the controller of your account, billing, and usage data.
- When you are a contact of a Mercuri customer (someone who receives an email, SMS, or WhatsApp message from a business that uses Mercuri), that business is the controller and we process your data on its instructions as a processor. Questions about why you received a message, or requests to access or delete your data, should go to that business first. We will help them respond.
3. Information We Collect
- Account and identity data: name, business name, email address, phone number, role, login credentials, and connected-account identifiers.
- Billing data: billing address, plan, subscription status, and payment metadata from our payment processors. We do not store full card numbers.
- Contact data you upload or sync: names, phone numbers, email addresses, tags, booking and purchase history, and notes about your customers, whether entered manually, imported, or synced from a connected CRM, booking, or e-commerce system.
- Message data: the content, attachments, and metadata (sender, recipient, timestamps, delivery status, read status, opt-in and opt-out records) of email, SMS, and WhatsApp messages sent or received through Mercuri, including replies that customers send back to you.
- Connected mailbox data: see Section 5 for the specific data we access when you connect Gmail or Outlook.
- AI agent data: the knowledge you give your AI agent (FAQs, services, prices, opening hours, booking rules), the conversations it has, and the actions it takes.
- Technical and usage data: IP address, browser and device details, pages visited, features used, and event logs.
- Support data: anything you share with us in support tickets, chat, calls, or onboarding.
4. How We Use Information
- To provide the service (contractual necessity): deliver your messages across email, SMS, and WhatsApp, receive and route replies into your inbox, run your AI agents, sync with your integrations, and bill you.
- To keep the platform safe (legitimate interests): prevent spam, fraud, and abuse; protect sender reputation on the networks we deliver through; secure accounts; and debug problems.
- To improve Mercuri (legitimate interests): aggregate usage analytics and product research. We do not use your message content or your customers' data to train general-purpose AI models.
- To communicate with you (contract and consent): service notices, security alerts, and, with your consent where required, product updates.
- To meet legal obligations: tax, accounting, telecoms record-keeping, and lawful requests.
5. Connected Email Accounts (Gmail and Outlook)
Mercuri sends your email campaigns and one-to-one emails from your own mailbox rather than from a shared sending domain. To do this you connect your Google Workspace or Gmail account, or your Microsoft 365 or Outlook account, using OAuth. You never give us your email password, and you can disconnect at any time.
What we access (Google user data). Connecting a mailbox is optional. If you choose to connect one, Mercuri asks Google or Microsoft for permission to:
- Send email on your behalf, so campaigns and one-to-one replies go out from your own address.
- Read email, so replies to conversations that Mercuri started appear in your Mercuri inbox and your AI agent can respond to them. Where a permission would technically allow broader access to the mailbox, Mercuri only retrieves messages belonging to threads it sent or that customers sent in reply to those threads. It does not scan, index, or store the rest of your mail.
- See your basic profile (your name and email address), to label the connected account.
The exact permissions requested are shown on the Google or Microsoft consent screen before you approve them, and you can review or revoke them at any time.
What we do with it. We use mailbox data only to provide the features you can see in Mercuri: sending, receiving, threading, and AI-assisted replies for the conversations you run through the platform. We store the OAuth tokens needed to keep the connection alive, the messages that belong to Mercuri conversations, and delivery metadata. We do not use mailbox data for advertising, sell it to data brokers, use it for credit decisions or retargeting, or share it with third parties except the sub-processors needed to run the service (Section 8).
No AI model training. Mercuri does not use data obtained through Google Workspace APIs, or through Microsoft's APIs, to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. Mailbox data is used only to power the AI features you configure for your own account, such as drafting a reply within a specific conversation.
Human access. Mercuri staff do not read your mailbox data except with your explicit permission to resolve a support issue, where required for security or abuse investigation, or where required by law.
Google API Services User Data Policy. Mercuri's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. You can disconnect a mailbox from your Mercuri settings, from your Google Account permissions, or from your Microsoft account permissions. When you disconnect, we delete the stored OAuth tokens immediately and stop accessing the mailbox. Messages already in your Mercuri conversation history remain until you delete them or close your account. You can also ask us to delete all Google or Microsoft user data we hold for you at any time by emailing privacy@mercuri.cx; we complete such requests within 30 days.
6. SMS and WhatsApp
SMS is delivered through telecoms carriers via our SMS provider. To send SMS we process the recipient's phone number, the message content, delivery receipts, and replies (including STOP and HELP keywords, which we honour automatically).
WhatsApp messages are delivered through the WhatsApp Business Platform operated by Meta. Meta processes messages under its own terms and privacy policy. To send WhatsApp messages we process the recipient's phone number, WhatsApp profile name, message content and media, message templates, delivery and read receipts, and replies.
Consent records. We store the opt-in and opt-out status of each contact, including how and when consent was given where you record it. We do not share mobile opt-in data, phone numbers, or consent details with third parties for their own marketing purposes. Our customers are responsible for obtaining valid consent before messaging their contacts (see our Terms of Service).
If you received a message from a business using Mercuri and want it to stop: reply STOP to an SMS, block or reply STOP on WhatsApp, or use the unsubscribe link in an email. You can also contact the business directly. If you cannot reach them, email privacy@mercuri.cx and we will help.
7. AI Agents
Mercuri's AI agents draft and send replies, answer questions, follow up with leads, and book appointments. To do this, the content of the relevant conversation and the knowledge you have given the agent are sent to our AI model providers for processing. Our providers are contractually prohibited from using this data to train their models. You control what your agent knows, which channels it answers on, and whether it replies automatically or drafts for your approval.
8. Who We Share Information With
We share personal information only with the following categories of recipients, and only as needed to run the service:
- Messaging networks: our SMS provider and the carriers it delivers through; Meta for WhatsApp; Google or Microsoft where you have connected a mailbox.
- AI model providers for AI agent replies and message drafting.
- Cloud hosting, database, search, and monitoring providers.
- Email service providers that deliver email on our behalf, both your campaign email where it is not sent through a connected mailbox, and Mercuri's own account emails (password resets, invoices, alerts).
- Payment processors for subscriptions and message credits.
- Analytics providers on our website, such as Google Analytics.
- Integrations you connect (CRM, booking, e-commerce, calendar), which receive and send data according to your configuration.
- Authorities or other parties when required by law, legal process, or to protect rights, safety, and the integrity of messaging networks.
- A successor business in a merger, acquisition, or asset sale, subject to this policy.
We do not sell personal information.
9. Cookies
We use cookies and similar technologies for login sessions, security, remembering preferences (such as dark mode), and website analytics. You can control cookies in your browser settings. Blocking essential cookies will stop the app from working.
10. Data Retention
- Account and billing records: for the life of the account and then as long as required for tax and accounting law.
- Contacts and message history: for the life of your account, or until you delete them in the app.
- Mailbox OAuth tokens: until you disconnect the mailbox or close your account, then deleted immediately.
- Consent and opt-out records: retained after account closure for as long as needed to demonstrate compliance with messaging law.
- Logs: typically 90 days unless needed for security or a dispute.
- On account closure we delete or anonymise your data within 30 days unless the law requires us to keep it longer.
11. International Transfers
We are based in India and use providers in the United States and elsewhere. Where we transfer data out of the UK, EEA, or other regulated regions, we rely on approved safeguards such as standard contractual clauses and the UK Addendum.
12. Security
We encrypt data in transit and at rest, restrict access on a need-to-know basis, store OAuth tokens encrypted, log access, and maintain incident-response procedures. No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and, where required, regulators without undue delay.
13. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict processing, to withdraw consent, and to complain to a supervisory authority (for example the ICO in the UK). California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing. We do not discriminate against anyone for exercising their rights.
To exercise your rights, email privacy@mercuri.cx. We may verify your identity first. If you are a contact of one of our customers, we will usually pass your request to that business and support them in responding.
14. Children
Mercuri is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children.
15. Changes to This Policy
We will post any changes on this page and update the date above. For material changes we will also notify account holders by email or in the app.
16. Contact
Santhe Technology Consulting OPC Pvt LTD (Mercuri)
Privacy: privacy@mercuri.cx
Support: support@mercuri.cx