Skip to content

Help

Privacy and your data

What MyHermes encrypts, where your paid agent runs, what a backup holds, and how to delete your data.

This page sums up how MyHermes handles your keys, where your paid agent runs, what its backups hold, and how to cancel or have your data deleted. The Privacy Policy is the full statement, and the Terms of Service cover the rest.

Your keys and secrets

The keys and secrets you save in the dashboard are encrypted at rest: MyHermes encrypts them (AES-256-GCM) before it stores them. That covers:

  • model provider keys, on a paid plan and on the free tier, and ChatGPT or Grok sign-ins;
  • your Telegram bot token;
  • tool keys, voice keys and memory service keys;
  • connector sign-ins and the API keys you paste for connectors;
  • webhook signing secrets.

Your agent needs some of these keys to work. On some providers, its own configuration file holds your model key, and that file is in your backups; see What a backup holds.

A webhook's secret is shown to you once, when you create it, and never again.

The key for your API endpoint works differently: SettingsAPI keeps showing it so you can copy it again. Treat it like a password, and press "Rotate key" if it gets out. API endpoints has more.

Where your agent runs

  • A paid agent runs on its own machine, with its own disk: 2 vCPU and 4 GB of RAM on Mini, 8 vCPU and 16 GB on Pro.
  • On the free tier there's no machine of your own. Free chat runs on a shared MyHermes AI endpoint, or goes to your own provider if you saved your own key.
  • Memory. By default, your agent keeps its memory as ordinary files on its own disk. If you switch to a memory service in SettingsMemory, your agent's memory goes to that service's account, under your own key. See Memory and background tasks.

Who can reach your agent

Besides you in the dashboard, these can send your agent messages:

  • On Telegram, your bot's owner (whoever sent it the first /start in a private chat) and every id under "Allowed Telegram users". Send /start yourself as soon as you've connected the bot. Telegram explains.
  • Through the API, anyone who has your API key.
  • Through a webhook, anyone who has both its URL and its secret. Your agent reads the body as written, so only wire up sources you trust. See Webhooks.

Apps you connect under SettingsConnectors work the other way round: your agent acts in them with the access you approved. Press "Disconnect" to cut that off, or revoke the access in the app itself. See Connectors.

What a backup holds

A backup is a snapshot of your agent's own files, and that includes its configuration file. That file can hold your model key (on MyHermes AI, OpenAI, NVIDIA NIM, OpenCode Zen, OpenCode Go, Groq, DeepSeek, Google Gemini, Ollama or Custom) and the key your agent uses to reach your connectors. So treat your backups as containing secrets.

  • Mini keeps the newest 3 backups and Pro the newest 7. You make them by hand, and on Pro you can also schedule them.
  • You can delete any backup from SettingsBackups: press "Delete", then "Yes" at "Delete permanently?".
  • There's no download. Backups can only be restored onto your agent.

Backups lists everything a backup holds and which keys end up in it.

Deleting things yourself

WhatHow
A backupSettingsBackups: "Delete", then "Yes"
A webhookSettingsWebhooks: "Delete". It's removed straight away, and its address stops working.
A connected appSettingsConnectors: "Disconnect", then "Restart Hermes". You can also revoke the access in the app itself.
Someone's Telegram accessSettingsChannels: press the "✕" on their row, then "Save credentials". The bot's owner can't be removed this way.
Your API keySettingsAPI: "Rotate key". The old key stops working at once. There's no way to delete the key or turn the endpoint off.

The dashboard has no button to delete a chat. To have your data deleted, see Deleting your account.

Cancelling and what happens to your data

Cancel from SettingsBilling (open it): press "Cancel plan", then "Yes, cancel". A cancellation can't be undone.

  1. Until the end of the period you've paid for, you keep your agent, and everything works as before.
  2. When the period ends, MyHermes takes a final backup of your agent, then removes your agent and its machine. Your account goes back to the free tier.
  3. That final backup is kept for 30 days, but the dashboard can't put it back. If the backup can't be taken, your agent is still removed, after a 7-day grace period, without it.

The Privacy Policy describes the same steps for a cancellation.

If a renewal payment fails instead, your agent keeps working for 7 days after the failed payment. If it's still unpaid after that, your plan ends, and your agent is removed once 7 days have passed since the end of your paid period, with no final backup.

Billing goes through each step.

Deleting your account

There's no button in the dashboard that deletes your account and everything in it. The Privacy Policy explains how to ask for your data to be deleted: email [email protected].

Getting a copy of your data

There's no download or export in MyHermes, for backups or anything else. To ask for a copy of the personal data MyHermes holds about you, see the Privacy Policy. You can copy your agent's personality files yourself from SettingsPersonality.

The Privacy Policy and Terms

  • The Privacy Policy says what MyHermes collects, who it shares data with, how long it keeps it, and your rights.
  • The Terms of Service cover using MyHermes and paying for it.

Both are also linked at the bottom of SettingsHelp, as "Privacy policy" and "Terms of service".

What's next