Skip to content
Free AI Benchmark — see where you are exposed before you deploy AI.Start the benchmark

Why MergeOn

Turn the knowledge you already have into governed context AI can use.

Policies, procedures, manuals, regulations and operating documents were written for people — not AI.

MergeOn Document Intelligence transforms them into structured Tier-3 Review Packs, preserving meaning, relationships, dependencies and source context. Accepted knowledge can then be governed in the Knowledge Center and supplied to AI at execution.

Better context. Less repeated processing. More efficient AI execution.

Explore Governed Knowledge

Build on MergeOn

The application asks for a business outcome. The Runtime governs how it is produced.

An integration calls a published Business Capability rather than a model endpoint, so knowledge, policy, protection, human authority and evidence stay part of the activity instead of becoming your problem to rebuild.

Everything below describes the contract you build against and the architecture behind it.

Explore the developer platform

Know where you stand

Most organizations do not have an AI problem. They have a clarity problem.

Before deciding what to build, it helps to establish what your organization already believes about ownership, governance and decision-making — and where those beliefs disagree with each other.

Start with an honest read of where you are. Everything else follows from it.

Start the free benchmark
Legal/Cookie Policy

Cookie Policy

MERGEON INC.Effective: September 14, 2026Last updated: September 14, 2026

1.About this Policy

MERGEON INC., a Delaware corporation (“MergeOn,” “we,” “us,” or “our”), uses cookies and similar browser technologies on its websites and in the MergeOn platform. This Policy explains which ones we use, what each is for, how long it lasts, and what happens if you block them.

This Policy describes what MergeOn actually sets. It is written from the current implementation rather than from a standard template, and it will be updated when that implementation changes.

2.What Cookies Are

A cookie is a small text file a website asks your browser to store and send back on later requests. It is how a website recognises that two requests came from the same browser — which is what makes staying signed in possible.

“Similar technologies” means other places a browser can keep data for a site, principally localStorage and sessionStorage. These are not cookies: they are not attached to requests and are not sent to our servers unless the page deliberately reads them and sends them. Section 6 covers the ones we use.

3.How MergeOn Uses Cookies

Every cookie MergeOn sets is a first-party cookie, set by MergeOn, and exists to operate the service: signing you in, keeping you signed in, protecting the session, and protecting requests against cross-site forgery.

MergeOn does not use advertising or marketing cookies, and does not use analytics cookies. No third party sets a cookie through our website.

Because of that, this Policy has no advertising section and no cross-site tracking section. There is nothing to put in them.

4.Strictly Necessary Cookies

These are required for authentication, security and session continuity. All are first-party. Except where noted, all are HttpOnly — meaning page scripts cannot read them — and are sent over HTTPS only.

  • token — your signed-in session. Type: HttpOnly, session security. Duration: 15 minutes, renewed silently while you remain active.
  • refreshToken — keeps you signed in between requests and renews the session above. Type: HttpOnly, session security. Duration: your configured Session Timeout, between 5 minutes and 8 hours, defaulting to 30 minutes.
  • mo_session_expires — a timestamp only, readable by the page so the interface can warn you before your session lapses. It contains no secret and no personal data. Type: readable by scripts, functional to the session. Duration: matches refreshToken.
  • totp_pending — issued only during two-factor authentication, to carry the pending challenge between the password step and the code step. Type: HttpOnly, security. Duration: 10 minutes.
  • _csrf — protects forms and requests against cross-site request forgery. Type: HttpOnly, security. Duration: 24 hours.
  • oauth.sid — written only if you begin a third-party sign-in flow. If you never start one, it is never created. Type: HttpOnly, security. Duration: 10 minutes.
  • device_fingerprint — a random identifier generated in your browser when you begin signing in or creating an account. It lets a session be associated with the browser it was issued to and supports limits on concurrent sessions. It contains a random value only; it is not built by inspecting your device, and it is not used for advertising or cross-site tracking. Type: readable by scripts, security. Duration: 30 days.
None of these are created while you are simply reading our public website. Every one of them is written only when you do something that requires it — beginning a sign-in, creating an account, or submitting a form. If you browse our public pages and never sign in, MergeOn sets no cookies at all.

5.Functional, Analytics and Marketing Cookies

MergeOn does not currently use analytics cookies on its public website. MergeOn does not currently use marketing, advertising, attribution or retargeting cookies anywhere.

We do not operate a third-party analytics product, tag manager or advertising pixel on this website. If that changes, this Policy will be updated before the change takes effect, and we will say what was added.

6.Similar Technologies

These are browser storage, not cookies. They stay in your browser and are not automatically transmitted with requests.

6.1 On our public website

Reading our public website writes nothing to your browser. We previously recorded which email campaign a visitor arrived from; that measurement has been removed rather than made subject to a consent prompt, and nothing replaced it.

The one exception is a short-lived marker used once, immediately after you sign in, to send you to the right page. It is written only when you sign in and is cleared when you close the tab.

6.2 In the signed-in platform

Once you are signed in, the application stores interface preferences and working state in your browser so the product behaves consistently between visits — for example your selected theme, whether the sidebar is collapsed, and the operating context you last worked in. This information stays in your browser, belongs to your account's use of the product, and is not used for advertising.

7.Third-Party Services

No third party sets a cookie through the MergeOn website.

Our public pages make no third-party requests at all. Everything they need, including our typefaces, is served from mergeon.com. We previously loaded web fonts from Google, which set no cookie but did disclose your IP address to Google in order to deliver them; those fonts are now served from our own servers instead.

MergeOn uses other providers — for infrastructure, payments, email and AI processing — in the course of delivering the Services. Those are described in our Privacy Policy. They are not listed here, because they do not place or read cookies in your browser through this website.

8.Managing Cookies

You can block or delete cookies in your browser settings, and most browsers let you do this for an individual site. Your browser's help pages explain how.

Every cookie described in Section 4 is strictly necessary. Blocking or deleting them will not reduce advertising, because we do none — but it will prevent you from signing in, will end an active session, or will cause parts of the Services to stop working.

MergeOn does not currently provide an in-product cookie preference centre, because there are no optional cookies to offer a choice about. If we introduce cookies that are not strictly necessary, we will provide a way to choose before they are set.

9.Changes to this Policy

We may update this Policy from time to time. We will post updates and revise the “Last Updated” date. Where a change introduces a cookie that is not strictly necessary, we will say so.

10.Contact

Questions about this Policy, or about the cookies and browser storage described in it, may be sent to privacy@mergeon.com.

MERGEON INC.Privacy OfficerScottsdale, ArizonaUnited Statesprivacy@mergeon.com