Mercury Social Media Copilot

Data Requests

This page explains the difference between disconnecting a channel, a provider callback and a broader privacy request. For all other privacy information, see the Copilot Privacy Notice.

1. Disconnect a channel

An authorized administrator can disconnect a social account in the Copilot’s Connect section. This removes the saved local connection and, for TikTok, requests token revocation. Queued automatic posts for the disconnected provider are changed to manual reminders.

Disconnecting is not the same as deleting all related data. Drafts, media, approvals, publication history, platform-synced analytics and audit records can remain where they are still needed for business accountability, rights management or legal obligations. Provider-side permissions or content may also need to be removed in the relevant platform account.

2. Meta deauthorization

If a person removes the Meta app, Meta can send Mercury a signed deauthorization callback. After validating that callback, the Copilot removes the matching Meta connection and disarms queued automatic Meta publishing. This callback does not by itself represent a request to erase every related company record.

3. Meta data-deletion request

Meta provides a separate “Send Request” action for data deletion. When Meta sends a valid signed deletion request, the Copilot removes the matching connection data and Meta connection diagnostics, removes all Meta-synced performance records currently held in the workspace, disarms queued automatic Meta publishing, and returns a confirmation code with a status URL. A status panel appears above only when a valid confirmation code is present.

Editorial content, source media and publication records created or held by Mercury are not automatically erased by that platform callback. They are assessed under the broader request process below and may be retained where a legal or documented business reason applies.

4. Submit a broader privacy request

To request access, correction, deletion or another privacy action, use Mercury’s contact form and select “Privacy request”. State that the request concerns “Mercury Social Media Copilot” and provide only enough information to identify the relevant account or record. Do not send passwords, access tokens, payment data or sensitive documents.

If you cannot use the form, write to Mercury International GmbH, Sinserstrasse 65, 6330 Cham, Switzerland. We may request proportionate information to verify identity, authority and scope. We generally respond within 30 days or explain when applicable law permits more time.

5. What happens next

Mercury identifies data within the verified scope, applies any correction, export, restriction or deletion that applicable law requires, and records completion where necessary. Deletion can be limited by legal duties, the rights of others, security evidence, active claims or justified company record-keeping. Where an exception applies, we explain it unless law prevents us from doing so.

A request to Mercury does not automatically delete data independently held by Shopify, Meta, TikTok, OpenAI or another provider. Use the relevant provider’s controls for provider-side accounts and content.

6. Contact-form privacy

The Mercury website contact form is a separate service. Its processing and providers are described in the Mercury website Privacy Notice.