Privacy Policy
Hermes-Relay ยท Effective date: July 18, 2026
Summary
Hermes-Relay does not collect, transmit, or share personal data with third parties. The app connects only to servers that you configure. There are no accounts, no hosted Hermes-Relay cloud service, and no externally transmitted analytics.
Google Play build
The Google Play build ships Hermes Bridge Core: chat, voice, terminal and TUI relay, notification companion, media handoff, relay sessions, and status. It does not include AccessibilityService-based Device Control and cannot read your screen, tap, type, swipe, capture screenshots, send SMS, place calls, access contacts or location, or perform unattended phone control.
The sideload build is a separate distribution track for users who intentionally install Device Control outside Google Play.
Data storage
All data is stored locally on your device in the app's private sandbox.
| Data | Storage method |
|---|---|
| Server URLs and preferences | Android DataStore (app-private) |
| API keys and relay session tokens | AES-256-GCM encryption via Android Keystore |
| Performance counters | Android DataStore (local only) |
| Notification trigger rules and activity log | Android DataStore (local only) |
Chat messages are not cached on your device. They are loaded from your Hermes server on demand and exist only in memory while the app is running.
Network connections
The app connects only to endpoints you configure: your Hermes API server for chat streaming; your relay server for terminal and TUI relay, Bridge Core status, media handoff, notification companion, and session management; and your relay voice routes when you use Voice mode.
No connections are made to Google, Anthropic, or any other third-party service by the app. There is no telemetry, advertising, external crash reporting, DNS prefetching, or background network activity to hosted Hermes-Relay services. Your Hermes server may separately connect to AI providers according to its configuration; that server-side activity is outside the scope of this app.
Permissions
| Permission or access | Purpose | Required |
|---|---|---|
| Internet | Connect to your Hermes servers | Yes |
| Network state | Detect connectivity for reconnect behavior | Yes |
| Camera | QR code scanning for server pairing | No |
| Microphone | Voice mode speech-to-text | No |
| Notification access | Optional notification companion metadata forwarding to your paired relay | No |
Notification access is granted and revoked from Android system settings. When enabled, Hermes-Relay forwards posted-notification package, title, text, subtext, timestamp, and notification key to your paired relay. It does not forward notifications to a Hermes-Relay cloud service. Optional notification-trigger matching happens locally on the phone and does not automatically send an AI request or reply in another app.
Third-party services
Hermes-Relay includes no advertising, tracking, or analytics services. The app is built with Android platform components and open-source libraries.
Data export and deletion
From Settings, you can export a connection backup, import a saved configuration, or perform a full reset. Exported backups can include server URLs, preferences, API keys, relay session tokens, device IDs, and dashboard cookies, so keep them private. Full reset permanently deletes local data including encrypted credentials. Uninstalling the app removes all stored app data from your device.
Children's privacy
Hermes-Relay is not directed at children under 13. We do not knowingly collect information from children.
Changes to this policy
Updates will be posted on this page with a revised effective date. Significant changes will be noted in the app's release notes.
Contact
For privacy questions, open an issue in the Hermes-Relay issue tracker.
Open source
Hermes-Relay is MIT licensed and publicly auditable.