Merkur Sign in

Privacy Policy

Last updated 5 October 2026

Summary. This summary is provided for convenience only; the policy below governs.

  • Your password and your terminal sessions are not disclosed to us. Terminal traffic is encrypted end to end between your browser and your machine (section 2).
  • We process the data needed to operate your account: your email address or username, your linked machines, and the browsers you sign in from (section 3).
  • Our primary infrastructure is located in the European Union (section 5).
  • We do not use advertising or tracking cookies, and we do not sell personal data (sections 4 and 5).
  • You may delete your account under Settings, and its data is erased seven days later (section 6).

1. Controller

The Merkur service is operated by Dmytro Pletenskyi, a sole proprietor (FOP) registered in Ukraine ("we", "us", "our"), who is the controller of the personal data described in this policy. Contact: dmitriy.pletenskoy@gmail.com.

This policy applies to the Merkur service at merkur.sh, including the website, the web application, the Merkur daemon installed on your machines, and the Linux machines we host on your behalf ("boxes").

2. Data not disclosed to us

This does not apply to the contents of a hosted box. A box's disk is stored on our servers and is therefore technically accessible to us, as with any hosted server. We access it only in the circumstances described in section 7.

3. Data we process and legal bases

Account data

Your username, or your email address where sign-in is by email; the OPAQUE sign-in record; your account's public key and the encrypted copy of its private key; the account creation date; and whether deletion of the account has been requested.

Legal basis: performance of a contract (GDPR Art. 6(1)(b)).

Email verification

When you register with an email address, we send a six-digit code to that address and retain a keyed hash of the code for up to ten minutes. If the address is already registered, we send a notice instead of a code. Before sending, we compare the address's domain against public lists of disposable email services and compare the address with those of suspended accounts, ignoring subaddress tags and, for Gmail, dots. A refused address is not stored.

Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b)), and our legitimate interest in protecting account holders and preventing abuse of the service (Art. 6(1)(f)).

Browser sessions

For each signed-in browser: the time of sign-in and session expiry, the browser and operating system names, and whether it is the installed application. This list is shown under Settings, Sessions, where any session may be revoked.

Legal basis: performance of a contract and our legitimate interest in account security.

Linked machines

For each machine: its name, operating system, Merkur version, public keys and last time online. To establish direct connections, your browser and machine exchange network addresses, including IP addresses, through our server and our connection-check (STUN) servers.

Legal basis: performance of a contract.

Hosted boxes

The boxes associated with your account, your position on the box waitlist, and the files and programs you place in a box.

Legal basis: performance of a contract.

Preferences and notifications

Your keyboard layout settings and, if you enable notifications, the push endpoint provided by your browser. Notifications are delivered through your browser vendor's push service (for example Apple, Google or Mozilla), and their content is encrypted.

Legal basis: performance of a contract; for notifications, your consent (Art. 6(1)(a)), which you may withdraw in your browser at any time.

Security and operational logs

Our servers log requests, including IP address, browser user agent, requested address, timing and errors. To prevent password guessing and abuse, we also count recent attempts per IP address and per account name for up to one hour.

Legal basis: our legitimate interest in the security and operation of the service.

Performance reporting (disabled by default)

If you enable Performance reporting in Settings, your browser sends timing measurements from your sessions, your browser and device type, and error reports. It is disabled by default and stops when disabled.

Legal basis: your consent.

Website analytics

Our public website (not the application) uses Rybbit, a cookieless analytics service. It records visits, pages viewed, referring sites, country, language, browser, device type and screen size, page-load timing, and which of the website's own buttons and links are selected, for example "Start free", the waitlist button, a navigation link, a link to our source code or a question in the FAQ. When an address is added to the box waitlist, our server also reports to Rybbit that one address was added, without the address itself. These records do not include anything you type or the query string of a page's address. It sets no cookies and stores nothing on your device. It distinguishes visits using a hash of the IP address and user agent that changes daily, so visits cannot be linked across days.

Legal basis: our legitimate interest in understanding how the service is found and used.

4. Cookies and local storage

The service sets one cookie, merkur_refresh, which maintains your sign-in. It is strictly necessary, is sent only to our sign-in endpoints, and is not accessible to scripts.

The application also stores data in your browser: your settings, a copy of your machine list for faster start-up, the application's files for offline start-up, and your browser's signing key, which does not leave your device. None of this data is used for tracking, and no advertising or third-party cookies are used.

5. Storage location and service providers

Our primary infrastructure is located in the European Union. We use the following service providers. Where a provider processes personal data on our behalf, it is bound by a data processing agreement.

ProviderPurposeLocation
RailwayApplication server, database, session cacheNetherlands
Fly.ioEncrypted relay and connection-check serversFrankfurt, Germany
HetznerHosted boxes and connection-check (STUN) serversFalkenstein, Germany
ResendRegistration emailsIreland
AxiomLogs, traces and opt-in performance reportsFrankfurt, Germany
RybbitCookieless website analyticsRybbit's hosted service
GitHubDistribution of the Merkur daemon and its updatesUnited States

Several of these providers are based in the United States. Where a provider, or we as an operator established in Ukraine, may access personal data from outside the European Economic Area, the transfer is protected by the European Commission's Standard Contractual Clauses or the provider's certification under the EU–US Data Privacy Framework.

We do not sell personal data or share it for advertising purposes.

6. Retention

We may retain data for longer where required by law, or where necessary to address a specific abuse or security incident.

7. Access and disclosure

We access account data or a hosted box only as necessary to operate the service at your request, to manage the capacity of the service, to address abuse or a security incident (for example, a box used to attack others), or where required by law. We disclose personal data to public authorities only where legally required, and only to the extent required.

8. Your rights

Subject to applicable law, you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on consent, you may withdraw consent at any time. You may delete your account under Settings, Account.

To exercise these rights, contact dmitriy.pletenskoy@gmail.com. We respond within the time limits set by applicable law, generally one month.

You also have the right to lodge a complaint with a supervisory authority: in the European Union, the authority of the country where you live or work; in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.

9. Security

Terminal sessions are encrypted end to end using post-quantum key exchange. Sign-in uses OPAQUE, and each browser session is authorised by a key held only in that browser. Releases of the Merkur daemon are signed. No system is completely secure. In the event of a personal data breach, we will notify you and the competent authority as required by law.

10. Age

The service is not intended for persons under 18, and we do not knowingly collect their personal data.

11. Changes to this policy

We may amend this policy from time to time. Amendments are published on this page with a new date. We will notify you of any material amendment in the app or by email before it takes effect.