Mercury Falling
Privacy Policy
Last updated: 10 August 2026
What We Collect
- Account information: your email address. There is no password. If you create a passkey, we store the public credential it gives us, which cannot be used to sign in anywhere else.
- Alert configuration: the locations you monitor and the conditions you've chosen. Locations are stored as coordinates and a name you supply, and you can give an alert a private name of your own, which nobody but you ever sees.
- Sign-in records: when a sign-in link or code was requested for your address, and the network address and country it was asked for from. This is what stops the site being used to mail people who never asked to hear from us, so it is kept whether or not the address turns out to have an account.
- Delivery records: which alerts we sent you, when, by which channel, and whether delivery succeeded, so we can troubleshoot. If your mail provider tells us a message bounced permanently or that you reported it as spam, we record that and stop sending to the address.
- Push subscription data: if you enable web push, the endpoint and keys your browser provides, one record per device and browser.
- Subscription status: if you subscribe, whether your subscription is active and an identifier that links your account to Stripe. We never see or store your card number, expiry, or security code. Those go directly to Stripe and never reach our servers.
Location
We do not collect continuous or background location. Your device is never asked for its position.
Two things are inferred from your network connection rather than entered by you, both only as a starting suggestion you can change:
- An approximate city, used to offer a location when you add your first one.
- A time zone, used as the default for when an alert checks.
These come from the network address your browser connects from, by way of Cloudflare. Nothing is stored from them unless you save a location that uses them.
What We Don't Do
- We do not sell your personal information.
- We do not share your information for advertising, cross-context behavioral advertising, or any similar purpose.
- We do not use advertising or tracking cookies, advertising trackers, or analytics that follow you across other websites. The only cookies we set are the two that keep you signed in, and the bot check on the sign-in page may set one of its own while it runs.
The Sign-In Page
The sign-in form is protected by Cloudflare Turnstile, a check that tells a person apart from an automated script. It runs in your browser and reports to Cloudflare characteristics of your browser and device, along with the network address you connect from. Most people are never asked to do anything.
This is here because anyone can type anyone's email address into a sign-in form. Without it, this site can be used to send unwanted mail to people who never asked for it, so the check protects strangers as much as it protects us. It is not used for advertising, and it does not follow you to other sites.
What Is Public
Every alert has a public page at a short address, showing its generated name, its conditions, the city and state of its location, and the forecast readings that matched. It does not show your email address, your account, or your exact coordinates. Alert names are generated from the conditions and the place (you cannot type one), so nothing you write, including the private name you may have given an alert, is ever published.
The calendar feed, if you use it, is readable by anyone holding its address. You can revoke it from your profile at any time.
Service Providers
We use a small number of vendors to operate the service. Except where noted below, they may process your data only to provide their service to us, and may not use it for their own purposes:
- Open-Meteo: weather and air quality data. Receives the coordinates of a place you have saved, and never your identity.
- The National Oceanic and Atmospheric Administration: the public radar mosaic behind the observed conditions on some pages. Not a vendor under contract to us but a public government service, read the same way anyone reads a public radar map. It receives the coordinates of a place you have saved, and never your identity.
- Mapbox: turning a place you type into coordinates, the reverse of that, and the picture on the map you confirm a location with. Your browser never contacts them: we fetch the map image ourselves and serve it from this site, so what they see is our server rather than yours.
- Anthropic: if you describe an alert in your own words, those words are sent to a model there to be turned into proposed conditions you then edit and confirm; alert names are phrased the same way. It receives what you typed along with the conditions and the city, and never your email address or your exact coordinates. Under the terms we use their API on, what we send is not used to train their models.
- Resend: email delivery.
- Stripe: payment processing and subscription billing. Receives your card details directly, along with your email address and whatever it needs to take a payment. We never receive the card itself. Stripe handles that information as a controller in its own right, under its own privacy policy.
- Cloudflare: network routing, the approximate city and time zone described above, and the Turnstile bot check on the sign-in page.
- Hetzner: server hosting.
One more is not ours to choose. If you turn on push notifications, they are delivered through the push service your own browser uses: Apple's, Google's or Mozilla's, depending on the browser. The message is encrypted so that only your device can read it, but the service handling it knows a notification was sent to your device. Turning notifications off in the browser stops it.
Email You Receive From Us
- Alert emails: the service you signed up for. Every one carries a one-click link that pauses that alert.
- Login emails: the sign-in link and six-digit code you ask for. Sent only when you request one, and never stopped by anything you do to an alert, because they are how you get back in.
- Account status emails: anything else needed to operate your account.
We do not send marketing email.
Data Retention
We keep your data while your account is active, and after you cancel, so that subscribing again picks up exactly where you left off. Ask us to delete your account and we remove your personal information within 30 days. Aggregate statistics that do not identify you may be retained.
Your Choices
You can view and edit your configuration, and cancel your subscription, from your settings at any time. Email [email protected] to have your account deleted, if you'd like help with any of that, or if you want to know what we hold about you.
Depending on where you live, you may have additional rights to access, correct, delete, or restrict use of your personal information. We honor these requests regardless of where you live. Just ask.
Security
We use encryption in transit and limited internal access. Sign-in links and codes are single-use and expire after five minutes. No system is perfectly secure, but we'll notify affected users promptly if we learn of a breach involving personal information.
Children
Mercury Falling is not directed at children under 13, and we don't knowingly collect their information.
Changes
We'll post updates here and email you about material changes.
Contact
1235Media LLC
1135 W Cheltenham Ave, Ste 8 #234, Elkins Park, PA 19027
[email protected]