Last updated July 26, 2026

Privacy Policy

This policy explains the information HermesBackup processes to provide zero-knowledge offsite backup for Hermes Agent.

Information we process

We process your account email, device names, optional backup labels, subscription status, and service preferences. For each backup we store ciphertext size, a SHA-256 digest of the ciphertext, backup kind, timestamps, and account and device identifiers.

Information we cannot read

Backups are encrypted on your machine before upload. We do not receive plaintext Hermes files, private encryption keys, passphrases, or unencrypted archives. Losing every copy of your private recovery key makes the stored ciphertext permanently unreadable, including to us.

Why we use information

We use account and operational data to authenticate users and devices, enforce quotas, provide restores, send transactional service alerts, prevent abuse, process billing, and meet legal obligations. We do not sell personal information or use backup contents for advertising or model training.

Service providers

Cloudflare provides compute, metadata storage, encrypted-object storage, network protection, and operational logging. Clerk provides human account authentication. Stripe processes payments. Emailit delivers transactional email. These providers process only the information needed for their role under their own terms and privacy commitments.

Retention and deletion

Stored backups remain until you delete them, rotate them through your client policy, close your account, or an expressly disclosed inactive-account policy applies. Object deletion is immediate; a metadata-only tombstone may remain for seven days for dispute handling. Account deletion revokes devices and deletes stored objects and account-owned operational records, subject to records we must retain for tax, fraud, or legal compliance.

Logs and security

Cloudflare may process request metadata such as IP address, user agent, path, and status code. Application logs are designed not to include request bodies, backup labels, device names, encryption keys, or plaintext backup data. We use short-lived presigned transfer URLs, hashed device tokens, private R2 storage, and tenant-scoped database queries.

Your choices and rights

You can review backups and devices, revoke device access, change email preferences, delete backups, or delete your account from the dashboard. Depending on where you live, you may also request access, correction, portability, restriction, or objection. Email [email protected].

Changes

Material changes will be posted here with a new effective date. If a change materially reduces user rights, we will provide reasonable notice through the account email or dashboard.