Privacy Policy
This policy explains how Hermes Conduit handles information in the iOS app, the optional Hermes Conduit Notifier plugin, and the optional notification relay used to deliver Apple Push Notification service (APNs) alerts.
Summary
- Conduit has no advertising SDKs, third-party analytics SDKs, or cross-app tracking.
- Your conversations, attachments, model settings, and gateway credentials are sent to the Hermes dashboard or gateway that you configure, not to a hosted Hermes service operated by Conduit.
- The optional notification relay processes only the information needed to pair a gateway and deliver the notification categories you enable.
- Personal information is not sold.
Information stored on your device
Conduit stores the dashboard URL you provide, dashboard session information, app preferences, notification registration credentials, locally selected profile avatars, and cached attachment information on your device. Sensitive session and notification credentials are stored using iOS secure storage where supported.
Your Hermes dashboard and gateway
When you sign in, send a message, load a session, change a model or setting, run a command, or upload an attachment, Conduit communicates with the dashboard and gateway URL that you configured. The operator of that Hermes installation controls the storage, processing, retention, and security of that data. If you connect to a gateway operated by someone else, their privacy terms also apply.
Optional push notifications
If you enable notifications, Conduit sends the following information to the Conduit notification relay:
- Your APNs device token and a randomly generated installation identifier.
- Notification preferences, such as enabled event categories, sound, and preview settings.
- A gateway display name and randomly generated, revocable pairing credentials.
- For notification delivery: event type, event identifier, session identifier, profile name, gateway identifier, and—only when notification previews are enabled—limited notification title and body text supplied by your gateway.
- Basic request metadata used for security, rate limiting, diagnostics, and abuse prevention, which may include IP address, request path, response status, and time.
The relay uses this information solely to authenticate paired installations, enforce notification preferences, prevent duplicate delivery, troubleshoot failures, and send notifications through APNs. Apple processes the device token and notification payload under Apple's applicable privacy terms.
Retention and deletion
On-device information remains until you remove it, sign out, disable the related feature, or uninstall the app. Notification registrations remain active until notifications are disabled, the registration is invalidated, or deletion is requested. Disabling notifications prevents further delivery and revokes the app's local notification credential. Short-lived pairing codes expire after ten minutes, and event identifiers used to prevent duplicate delivery expire after approximately 24 hours.
To request deletion of notification relay information, contact support@milim.dev. We may ask for limited installation information to locate the registration. Information stored by your Hermes gateway must be deleted through that gateway's operator.
Sharing
Information is shared only with service providers necessary to provide the requested function, including Apple for APNs delivery and infrastructure providers used to operate the notification relay and this support site. Information may also be disclosed when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.
Security
Conduit uses HTTPS and secure WebSocket connections when communicating with configured services. Notification credentials are randomly generated, scoped, revocable, and stored as cryptographic hashes on the relay where applicable. No method of transmission or storage can guarantee absolute security.
Children
Hermes Conduit is a developer and productivity tool and is not directed to children under 13. We do not knowingly collect personal information from children.
International processing
The notification relay and its service providers may process information in countries other than your own. By enabling notifications, you request this processing to provide the feature.
Changes
This policy may be updated as Conduit changes. The effective date above will be revised when material changes are published.
Contact
For privacy questions or requests, email support@milim.dev. For general help, visit the support page.