Privacy Policy
Last updated 5 October 2026
Summary. This summary is provided for convenience only; the policy below governs.
- Your password and your terminal sessions are not disclosed to us. Terminal traffic is encrypted end to end between your browser and your machine (section 2).
- We process the data needed to operate your account: your email address or username, your linked machines, and the browsers you sign in from (section 3).
- Our primary infrastructure is located in the European Union (section 5).
- We do not use advertising or tracking cookies, and we do not sell personal data (sections 4 and 5).
- You may delete your account under Settings, and its data is erased seven days later (section 6).
1. Controller
The Merkur service is operated by Dmytro Pletenskyi, a sole proprietor (FOP) registered in Ukraine ("we", "us", "our"), who is the controller of the personal data described in this policy. Contact: dmitriy.pletenskoy@gmail.com.
This policy applies to the Merkur service at merkur.sh, including the website, the web application, the Merkur daemon installed on your machines, and the Linux machines we host on your behalf ("boxes").
2. Data not disclosed to us
- Your password. Sign-in uses the OPAQUE protocol, under which your password does not leave your browser. We store a record that allows a sign-in to be verified, not the password or a hash of it.
- Your terminal sessions. Input and output are encrypted end to end between your browser and your machine. Where a direct connection is not possible, our relay forwards encrypted packets without access to the keys.
- Your account key. Your account's signing key is generated in your browser and stored by us only in encrypted form, protected by your password.
This does not apply to the contents of a hosted box. A box's disk is stored on our servers and is therefore technically accessible to us, as with any hosted server. We access it only in the circumstances described in section 7.
3. Data we process and legal bases
Account data
Your username, or your email address where sign-in is by email; the OPAQUE sign-in record; your account's public key and the encrypted copy of its private key; the account creation date; and whether deletion of the account has been requested.
Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
Email verification
When you register with an email address, we send a six-digit code to that address and retain a keyed hash of the code for up to ten minutes. If the address is already registered, we send a notice instead of a code. Before sending, we compare the address's domain against public lists of disposable email services and compare the address with those of suspended accounts, ignoring subaddress tags and, for Gmail, dots. A refused address is not stored.
Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b)), and our legitimate interest in protecting account holders and preventing abuse of the service (Art. 6(1)(f)).
Browser sessions
For each signed-in browser: the time of sign-in and session expiry, the browser and operating system names, and whether it is the installed application. This list is shown under Settings, Sessions, where any session may be revoked.
Legal basis: performance of a contract and our legitimate interest in account security.
Linked machines
For each machine: its name, operating system, Merkur version, public keys and last time online. To establish direct connections, your browser and machine exchange network addresses, including IP addresses, through our server and our connection-check (STUN) servers.
Legal basis: performance of a contract.
Hosted boxes
The boxes associated with your account, your position on the box waitlist, and the files and programs you place in a box.
Legal basis: performance of a contract.
Preferences and notifications
Your keyboard layout settings and, if you enable notifications, the push endpoint provided by your browser. Notifications are delivered through your browser vendor's push service (for example Apple, Google or Mozilla), and their content is encrypted.
Legal basis: performance of a contract; for notifications, your consent (Art. 6(1)(a)), which you may withdraw in your browser at any time.
Security and operational logs
Our servers log requests, including IP address, browser user agent, requested address, timing and errors. To prevent password guessing and abuse, we also count recent attempts per IP address and per account name for up to one hour.
Legal basis: our legitimate interest in the security and operation of the service.
Performance reporting (disabled by default)
If you enable Performance reporting in Settings, your browser sends timing measurements from your sessions, your browser and device type, and error reports. It is disabled by default and stops when disabled.
Legal basis: your consent.
Website analytics
Our public website (not the application) uses Rybbit, a cookieless analytics service. It records visits, pages viewed, referring sites, country, language, browser, device type and screen size, page-load timing, and which of the website's own buttons and links are selected, for example "Start free", the waitlist button, a navigation link, a link to our source code or a question in the FAQ. When an address is added to the box waitlist, our server also reports to Rybbit that one address was added, without the address itself. These records do not include anything you type or the query string of a page's address. It sets no cookies and stores nothing on your device. It distinguishes visits using a hash of the IP address and user agent that changes daily, so visits cannot be linked across days.
Legal basis: our legitimate interest in understanding how the service is found and used.
4. Cookies and local storage
The service sets one cookie, merkur_refresh, which maintains your sign-in. It is strictly necessary, is sent only to our sign-in endpoints, and is not accessible to scripts.
The application also stores data in your browser: your settings, a copy of your machine list for faster start-up, the application's files for offline start-up, and your browser's signing key, which does not leave your device. None of this data is used for tracking, and no advertising or third-party cookies are used.
5. Storage location and service providers
Our primary infrastructure is located in the European Union. We use the following service providers. Where a provider processes personal data on our behalf, it is bound by a data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| Railway | Application server, database, session cache | Netherlands |
| Fly.io | Encrypted relay and connection-check servers | Frankfurt, Germany |
| Hetzner | Hosted boxes and connection-check (STUN) servers | Falkenstein, Germany |
| Resend | Registration emails | Ireland |
| Axiom | Logs, traces and opt-in performance reports | Frankfurt, Germany |
| Rybbit | Cookieless website analytics | Rybbit's hosted service |
| GitHub | Distribution of the Merkur daemon and its updates | United States |
Several of these providers are based in the United States. Where a provider, or we as an operator established in Ukraine, may access personal data from outside the European Economic Area, the transfer is protected by the European Commission's Standard Contractual Clauses or the provider's certification under the EU–US Data Privacy Framework.
We do not sell personal data or share it for advertising purposes.
6. Retention
- Account data, linked machines, boxes and preferences: for as long as the account exists.
- Deleted accounts: deletion signs out every browser immediately, and the account and all data attached to it are permanently erased seven days later. Signing in within those seven days cancels the deletion.
- Browser sessions: up to 30 days, or until signed out or revoked.
- Registration codes and sign-in attempts in progress: up to 10 minutes.
- Rate-limit counters: up to one hour.
- Logs and performance reports: 30 days.
- Sent emails: the delivery record kept by our email provider, for its standard retention period.
We may retain data for longer where required by law, or where necessary to address a specific abuse or security incident.
7. Access and disclosure
We access account data or a hosted box only as necessary to operate the service at your request, to manage the capacity of the service, to address abuse or a security incident (for example, a box used to attack others), or where required by law. We disclose personal data to public authorities only where legally required, and only to the extent required.
8. Your rights
Subject to applicable law, you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on consent, you may withdraw consent at any time. You may delete your account under Settings, Account.
To exercise these rights, contact dmitriy.pletenskoy@gmail.com. We respond within the time limits set by applicable law, generally one month.
You also have the right to lodge a complaint with a supervisory authority: in the European Union, the authority of the country where you live or work; in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.
9. Security
Terminal sessions are encrypted end to end using post-quantum key exchange. Sign-in uses OPAQUE, and each browser session is authorised by a key held only in that browser. Releases of the Merkur daemon are signed. No system is completely secure. In the event of a personal data breach, we will notify you and the competent authority as required by law.
10. Age
The service is not intended for persons under 18, and we do not knowingly collect their personal data.
11. Changes to this policy
We may amend this policy from time to time. Amendments are published on this page with a new date. We will notify you of any material amendment in the app or by email before it takes effect.