Last updated July 26, 2026
Privacy Policy
This policy explains the information HermesBackup processes to provide zero-knowledge offsite backup for Hermes Agent.
Information we process
We process your account email, device names, optional backup labels, subscription status, and service preferences. For each backup we store ciphertext size, a SHA-256 digest of the ciphertext, backup kind, timestamps, and account and device identifiers.
Information we cannot read
Backups are encrypted on your machine before upload. We do not receive plaintext Hermes files, private encryption keys, passphrases, or unencrypted archives. Losing every copy of your private recovery key makes the stored ciphertext permanently unreadable, including to us.
How we use information
We use operational metadata to provide the service: rate-limit check, quota enforcement, backup listing, missed-backup detection, and billing. We do not sell, share, or use backup metadata for advertising, analytics, or machine-learning training. The service runs on Cloudflare infrastructure; Cloudflare's standard platform logging may store request metadata (URL, method, status, IP) according to their policies.
Data retention
Backup ciphertext and metadata are retained until you delete the backup or delete your account. Deleted backups have a 7-day soft-delete tombstone for support and dispute resolution, then are purged. Account deletion purges all backups, objects, and metadata.
Your rights
You can request a copy of your account metadata or request deletion of your account at any time by emailing [email protected]. Because backups are encrypted before upload with keys we do not hold, we cannot decrypt or export backup content on your behalf.
Contact
Email [email protected] for privacy-related questions.