Privacy Policy
This policy explains the information HermesBackup processes to provide zero-knowledge offsite backup for Hermes Agent.
Information we process
We process your account email, device names, optional backup labels, subscription status, and service preferences. For each backup we store ciphertext size, a SHA-256 digest of the ciphertext, backup kind, timestamps, and account and device identifiers.
Information we cannot read
Backups are encrypted on your machine before upload. We do not receive plaintext Hermes files, private encryption keys, passphrases, or unencrypted archives. Losing every copy of your private recovery key makes the stored ciphertext permanently unreadable, including to us.
Why we use information
We use account and operational data to authenticate users and devices, enforce quotas, provide restores, send transactional service alerts, prevent abuse, process billing, and meet legal obligations. We do not sell personal information or use backup contents for advertising or model training.
Service providers
Cloudflare provides compute, metadata storage, encrypted-object storage, network protection, and operational logging. Clerk provides human account authentication. Stripe processes payments. Emailit delivers transactional email. These providers process only the information needed for their role under their own terms and privacy commitments.
Retention and deletion
Stored backups remain until you delete them, rotate them through your client policy, close your account, or an expressly disclosed inactive-account policy applies. Object deletion is immediate; a metadata-only tombstone may remain for seven days for dispute handling. Account deletion revokes devices and deletes stored objects and account-owned operational records, subject to records we must retain for tax, fraud, or legal compliance.
Logs and security
Cloudflare may process request metadata such as IP address, user agent, path, and status code. Application logs are designed not to include request bodies, backup labels, device names, encryption keys, or plaintext backup data. We use short-lived presigned transfer URLs, hashed device tokens, private R2 storage, and tenant-scoped database queries.
Your choices and rights
You can review backups and devices, revoke device access, change email preferences, delete backups, or delete your account from the dashboard. Depending on where you live, you may also request access, correction, portability, restriction, or objection. Email [email protected].
Changes
Material changes will be posted here with a new effective date. If a change materially reduces user rights, we will provide reasonable notice through the account email or dashboard.