Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how Event Horizon Labs (“Event Horizon Labs,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use Mercury, our AI research-lab application (the “Service”).
By using Mercury, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Who we are
Mercury is operated by Event Horizon Labs, based in California, United States. For any privacy questions or requests, contact us at support@ehl-inc.com.
2. Information we collect
a. Account and identity information. When you sign up or sign in — including via Google sign-in — we collect your email address, display name, and authentication identifiers, and we store basic account and onboarding state.
b. Lab content you create.Mercury organizes your work into “Labs.” We store the content you put into them, including:
- Lab titles and custom instructions;
- Sources you upload or that Mercury creates on your behalf (file names, file types, and file contents);
- Conversations and messages — your prompts and Mercury’s responses;
- Any images or files you attach to a conversation.
c. Connected third-party accounts (optional). If you choose to connect an integration — Gmail, Google Calendar, Google Docs, Google Drive, or Google Sheets — we store the authorization tokens needed to access that service and, when you direct Mercury to act, we access the specific data required to fulfil your request (for example, reading a message, calendar event, document, or file you ask about). You can disconnect an integration at any time. See Section 6 for how we handle Google user data.
d. AI processing content. To generate responses, the messages, Lab content, and any connected-account data you include in a request are sent to the third-party AI model provider that hosts the model you select (see Section 5).
e. Compute / experiment data.If you approve a GPU compute experiment, the experiment details you provide — such as the experiment name, commands, setup scripts, and expected outputs — are sent to our compute provider to run the job, and we store a record of the job and its status.
f. Tool queries. When Mercury uses tools on your behalf (for example, web search or academic/arXiv search), the relevant query is sent to the corresponding external service.
g. Usage, feedback, and technical data. We collect information about how the Service is used, including model and token usage and run records (for reliability, cost measurement, and abuse prevention), rate-limiting counters, and feedback you submit on responses (a thumbs-up/down signal, a session identifier, and a limited excerpt of the associated message). We also process standard technical data such as timestamps and, via our infrastructure providers, server logs and IP addresses.
h. Cookies and local storage. We use essential browser storage and cookies to keep you signed in and to maintain your session. We do not use third-party advertising or analytics cookies.
3. How we use information
We use the information above to:
- Provide, operate, and maintain the Service and your Labs;
- Generate AI responses and run the tools, integrations, and compute you request;
- Authenticate you and secure your account;
- Monitor usage, enforce rate limits, and prevent abuse, fraud, and security incidents;
- Measure reliability and cost, and improve the Service;
- Respond to your requests and communicate with you about the Service;
- Comply with legal obligations.
We do not sell or share your personal information, we do not use it for advertising, and we do not use your Lab content, messages, or connected-account data to train machine-learning models.
4. Legal bases for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we process your information on the basis of: performance of our contract with you (to provide the Service); your consent (for optional integrations and any non-essential processing); our legitimate interests (security, abuse prevention, and improving the Service); and compliance with legal obligations. You may withdraw consent at any time.
5. Third parties and subprocessors
We share information with service providers who process it on our behalf, only as needed to run the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, and storage | Account data and Lab content |
| Sign-in and optional Workspace integrations | OAuth tokens; the account data you direct Mercury to access | |
| Anthropic, Together AI, OpenAI | AI model inference (the provider of the model you select) | The prompt and content sent for a given request |
| Prime Intellect | GPU compute for approved experiments | Experiment details you provide |
| Web and academic search providers | Tool queries | The search query |
| Vercel | Application hosting and logs | Technical/log data, IP address |
Each provider handles data under its own terms and privacy policy. We may also disclose information if required by law, to protect our rights or users’ safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).
6. Google user data (Limited Use)
Mercury’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained from Google sign-in and from the Gmail, Google Calendar, Google Docs, Google Drive, and Google Sheets integrations is used only to provide or improve the user-facing features you request; is not transferred to others except as necessary to provide those features, with your consent, or as required by law; is not used for advertising; and is not used to develop, improve, or train generalized AI or machine-learning models. You can revoke Mercury’s access at any time by disconnecting the integration in the Service or through your Google Account permissions.
7. Data retention
We retain your account and Lab content for as long as your account is active — that is, until you delete it. You can delete Labs, conversations, and sources within the Service at any time, and you can request deletion of your entire account and its associated data as described in Section 8. After deletion, residual copies may persist in routine backups for a limited period before being overwritten, and we may retain limited records where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal information, to object to certain processing, and to not be discriminated against for exercising these rights. To exercise any right, contact support@ehl-inc.com. You can also disconnect integrations and delete content directly in the Service at any time.
California residents (CCPA/CPRA).You have the right to know what personal information we collect and how we use and disclose it (see Sections 2, 3, and 5), the right to delete and to correct your personal information, and the right to opt out of the “sale” or “sharing” of personal information and to limit the use of sensitive personal information. We do not sell or share your personal information (including for cross-context behavioral advertising), and we use the contents of communications you access through integrations only to provide the features you request. We will not discriminate against you for exercising your rights. You may submit a request at support@ehl-inc.com, and you may use an authorized agent to do so.
9. Data location and international transfers
We are based in the United States, and your information is processed in the United States and in other countries where we or our service providers operate. If you access Mercury from outside the United States, you understand that your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
10. Security
We use technical and organizational measures to protect your information, including encryption in transit, access controls, and storage of integration credentials in a server-side context that is not accessible from the browser. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
Mercury is not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us at support@ehl-inc.com and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, provide additional notice.
13. Contact us
Questions or requests: support@ehl-inc.com· Event Horizon Labs, California, United States.