Skip to content

Privacy policy

Privacy Policy

What is stored, why, and who can see it. Merc keeps the minimum needed to execute and audit trades.

Last updated 30 July 2026

01

Account data

Discord identifier, email, subscription status, and the sources you enable.

02

Signal data

Raw messages from approved channels, parse results, confidence scores, and validation decisions — retained so any execution can be explained.

03

Execution data

Orders planned and placed, fills, and lifecycle events tied to your account.

04

Credentials

Exchange API keys are stored encrypted and used only to place and manage your orders. Keys are never shown back in full.

05

What partners see

Server admins receive aggregate, source-level statistics only. Individual identities, positions, and results are never exposed to them.

06

Third parties / processors

Payment processing is handled by a deposit gateway under contract. Product analytics are processed by PostHog (US cloud) so we can understand usage, onboarding, and recorded-exit performance — identified by internal user id, not sold for advertising.

07

Your controls

You can disconnect sources, rotate or revoke keys, export your history, and request deletion of your account at any time.

08

Cookies

Merc sets first-party cookies for product function and analytics: merc_session and merc_oauth_state for Discord sign-in; merc_ref for invite attribution (~30 days, first touch); merc_path and merc_invite_skipped for Getting Started preferences; merc_cookies_ack when you dismiss the cookies notice; plus PostHog analytics cookies/storage (loaded via a first-party ingest path on merc.bot) for product usage. These are not sold and are not advertising cookies.