Hermes HQ privacy policy
Last updated: October 6, 2026
Hermes HQ is an iPhone app for talking to your own Hermes agent. It is made by Charles McDowell ("we" below), and is not made by Nous Research. Contact: support@gethermeshq.com.
The short version
- Hermes HQ does not send your chats, files or voice to us.
- There are no Hermes HQ accounts. You sign in to a Hermes gateway that you (or someone you trust) run.
- There are no ads, no analytics and no tracking in the app.
- The one service we run is a push relay. It passes encrypted notifications from your gateway to Apple and keeps nothing.
- Your chats, files and settings go between your device and your gateway. A few features contact other services directly; they are listed below, with when and why.
What a gateway is
Hermes is agent software that runs on a computer you control. Its gateway is the part your phone connects to. Hermes HQ is a client for it, like a mail app is a client for a mail server. Whoever runs the gateway controls the data stored on it. That is usually you. We don't run it and can't see it.
What stays on your device
- Your sign-in. Each saved gateway's address, your username and the gateway's session (a session cookie, or with Sign in with Nous, the gateway's access tokens) are kept in the iOS Keychain, locked to this device: not synced to iCloud or restored to another device. Your password is never stored; it is sent once, to your gateway, when you sign in.
- Notification keys and bot pictures. If you use notifications, a key that unlocks your gateway's encrypted alerts, and each bot's picture for those alerts, are kept in the Keychain on this device.
- A Composio key, if you add one (see "Connect Apps" below). Also in the Keychain, on this device only.
- App data. Drafts, settings, the bot list, recent messages (to open chats quickly) and similar data are stored in the app's own storage on the device.
- Share extension data. So you can share to a bot from other apps, the app keeps a small list of your bots (names, pictures, colours and chat IDs) in storage that only Hermes HQ and its Share extension can read.
- Attachments you are preparing. Photos, files and voice memos you pick or record are kept in the app's private folders until they are sent or no longer needed. They are excluded from iCloud backup.
- Notification settings, muted bots and Shortcuts settings.
- Diagnostics. Recent error messages, connection timings and simple stability counts, shown in Settings › About › Diagnostics. They never leave your device unless you tap Copy and send them to someone yourself. Passwords, tokens, cookies and web-address details are removed from the copied text.
- Performance figures from iOS. iOS gives the app a daily summary of things like memory use and freezes (Apple's MetricKit). The app keeps a few of these numbers for the Diagnostics screen. It never uploads them.
What goes to your gateway
Everything you do in Hermes HQ is done by your gateway, so the app sends it there:
- your sign-in, to start a session;
- your messages, and the photos, files and voice memos you attach, including what you share from other apps (photos are sent without their location);
- voice you record for dictation or voice conversations, so the gateway can turn it into text or speech;
- your choices: bots, settings, scheduled jobs, tasks, approvals you give;
- if you watch or take over a bot's browser, or use Bot Screen: the screen is sent from your gateway to you, and your taps, typing, addresses and any text you paste go to it;
- if notifications are on and your gateway has the push plugin: a push token from Apple, a random ID for this device, which alerts you want, whether to show previews, and the key your gateway uses to encrypt alerts for this device.
If you saved more than one gateway, the app also checks the others now and then, with each one's own sign-in, to show you which have new messages.
Your gateway may pass your messages on to the AI and speech services you configured on it (for example a model provider). Those services, and how long they keep data, are set by whoever runs the gateway, not by Hermes HQ.
Notifications
When a reply is ready or a bot asks for approval, your gateway sends a notification through Apple's push service. Unless you run your own Apple push key, it goes through our push relay (push.getdispatchapp.com), because only the relay holds the app's key.
Your gateway encrypts every alert with a key only your device has. The relay and Apple see the device's push token, the time and the size of the alert, and the words "New notification" — never who it is from or what it says. The app's notification extension unlocks the alert on your device. The relay stores nothing: no list of devices, and its logs contain no tokens and no alert content.
With Settings › Notifications › Show Previews off, even the unlocked alert says only who it is from.
Other services the app contacts directly
Each of these sees your device's internet address and the request, as with any website.
| Service | When | What it receives |
|---|---|---|
| Websites in your chats | When a message contains a link or an image, the app fetches the page title, its icon or the image to show it | The address of that page or image. No cookies and no gateway credentials are sent. |
| YouTube, Vimeo, Spotify, Google Maps, OpenStreetMap | Only if you allow an embedded preview (the app asks first by default) | What that service's embedded player or map normally receives |
Nous Research (portal.nousresearch.com) |
Only when you tap Sign in with Nous | You sign in on Nous's own page, in iOS's secure sign-in sheet; the app never sees your Nous password. Your gateway then gives the app its session. |
Hermes catalogs (nousresearch.github.io) |
When you open Capabilities (the plugin list), and the skills list if you open it | A plain request for the public lists. Nothing about you. |
GitHub (api.github.com) |
When you open Settings › About, or check for updates there | A request comparing two public versions of Hermes. Nothing about you. |
Hermes Skills Hub (hermes-agent.nousresearch.com) |
Only when you open "Browse skills hub" | What that website normally receives |
Composio (composio.dev) |
Only if you use Connect Apps with your own Composio API key | Your key, a random user ID the app makes, the apps you choose to connect, and the sign-in pages of those apps |
| Nous Research diagnostics | Only if a reply fails and you choose Send Diagnostics and then Upload | Your gateway sends the error details and its own diagnostic bundle to Nous Research, the makers of Hermes |
| Apple | For notifications, and for crash reports if you share them | See "Notifications" and "Crash reports" |
| Pages you open | When you tap a link, it opens in an in-app Safari view or your chosen app | What that site normally receives |
Permissions the app asks for
iOS asks you first. You can change each one in Settings › Hermes HQ.
- Microphone: for voice memos, dictation and voice conversations you start. Recording only happens when you start it.
- Camera: to take a photo to attach to a chat.
- Photos: to pick photos to attach. The app uses Apple's photo picker, so it only gets the photos you pick.
- Add to Photos: to save images from your chats. The app can add images, not read your library.
- Local network: to reach a gateway on your home network or Tailscale.
- Notifications: to tell you when a reply is ready or a bot needs your approval.
Siri and suggestions
When the app shows a notification for a bot, it tells iOS which conversation it came from (the bot's name and picture, never the message), so iOS can show it like a message and suggest the conversation in Siri and the share sheet. This stays on your device, under Apple's control. Signing out removes these records.
Crash reports
If you choose to share analytics with app developers in your device's settings, Apple sends us reports when the app crashes. They contain technical details about the app and the device model, not your messages. TestFlight testers can also choose to send us a crash report or feedback with a comment. We use these only to fix bugs. They stay in Apple's App Store Connect, where only we can see them, and we don't copy them anywhere else.
Signing out and deleting data
Sign Out (Settings › Gateway) ends the session with your gateway where it can, removes that gateway's sign-in from the Keychain, stops its notifications to this device, and deletes the app's chats, drafts, cached messages, notifications and Siri conversation records from the device. Attachments and voice memos are deleted too when no other gateway is saved. It keeps your other saved gateways, the address and username for signing in again, a few device settings (notification choices, muted bots), the notification key and bot pictures (removed when you remove that gateway), and a Composio key until you remove it in Connect Apps.
Deleting the app removes everything it stored on the device.
Data on your gateway is not deleted by signing out. To delete it, use the gateway's own tools or ask the person who runs it. Hermes HQ never creates accounts, so there is no Hermes HQ account to delete. Accounts you made with other companies (Nous, Composio) are deleted with them.
If you email us, we keep the conversation for up to two years after it ends, then delete it. Ask us to delete it sooner at the address above.
Children
Hermes HQ is not made for children. It doesn't collect anyone's personal information, including children's.
Changes
We will update this page when the app changes what it does with data, and change the date at the top.