Privacy Policy
Hermes-Relay · Effective date: September 12, 2026
Summary
Hermes-Relay has no hosted cloud service and sends no analytics. Chat, voice, attachments, notifications and optional Android Assistant screen context are sent to servers you configure. Those servers may send content to your configured AI providers.
Google Play build
The Google Play build ships Hermes Bridge Core: chat, voice, standard inbound files, terminal and TUI relay, notification companion, Relay media enhancements, relay sessions, and status. It does not include AccessibilityService or MediaProjection Device Control and cannot tap, type, swipe, send SMS, place calls, access contacts or location, or perform unattended phone control. If Hermes-Relay is selected as Android’s Digital Assistant, a compatible explicit unlocked assistant-button invocation may include bounded visible text and an available screenshot in one Standard voice turn sent to the configured Hermes server and AI provider. Ordinary wake and keyguard invocations do not request screen context.
The sideload build is a separate distribution track for users who intentionally install Device Control outside Google Play.
Data storage
App settings, credentials, drafts and recovery state are stored locally in the app's private sandbox. Content sent to your configured Hermes server and AI providers follows their storage and retention settings.
| Data | Storage method |
|---|---|
| Server URLs and preferences | Android DataStore (app-private) |
| API keys and relay session tokens | AES-256-GCM encryption via Android Keystore |
| Performance counters | Android DataStore (local only) |
| Notification trigger rules and activity log | Android DataStore (local only) |
| Pending Android Assistant context | App-private cache until one turn is accepted, cancellation/session exit, or one-hour stale cleanup; failed preflight retains it for retry |
Your Hermes server owns conversation history. The app retains local drafts, queued messages and bounded in-flight turn checkpoints to recover interrupted conversations; these can include message text and confirmed Clarify answers. Attachment and Android Assistant context caches support viewing, sending and retrying content.
Network connections
Chat and voice content goes to endpoints you configure: your Hermes Dashboard/Gateway for standard chat, management, voice, and inbound files; an explicitly selected API-only connection for compatible chat; your relay server for terminal and TUI relay, Bridge Core status, explicit Relay media enhancements, notification companion, and session management; and your relay voice routes when you use enhanced Voice modes. Gateway-owned chats do not silently switch to an API server.
There is no telemetry, advertising or automatic external crash reporting. Your Hermes server may send content to AI providers according to its configuration. Optional update checks and links can contact public distribution and documentation services; these do not upload chat or voice content.
Voice Overlay
Voice Overlay is optional in both builds. Start it explicitly from Voice Focus while Hermes-Relay is visible and unlocked. It requires microphone access, display-over-other-apps access and an enabled microphone notification with Stop voice. Audio goes to the configured Hermes server; the overlay does not read or control other apps. Stop voice, closing the overlay, screen lock, task removal or loss of required access ends the overlay voice session. Returning to the app keeps foreground protection until the app is resumed. Granting permissions never starts a session.
Permissions
| Permission or access | Purpose | Required |
|---|---|---|
| Internet | Connect to your Hermes servers | Yes |
| Network state | Detect connectivity for reconnect behavior | Yes |
| Camera | QR code scanning for server pairing | No |
| Microphone | Voice, Voice Overlay and opt-in local wake detection | No |
| Display over other apps | User-started voice controls only | No |
| Android Digital Assistant role | Optional assistant invocation and bounded one-turn screen context | No |
| Notification access | Optional notification companion metadata forwarding to your paired relay | No |
Notification access is granted and revoked from Android system settings. When enabled, Hermes-Relay forwards posted-notification package, title, text, subtext, timestamp, and notification key to your paired relay. It does not forward notifications to a Hermes-Relay cloud service. Optional notification-trigger matching happens locally on the phone and does not automatically send an AI request or reply in another app.
Third-party services
Hermes-Relay includes no advertising, tracking, or analytics services. The app is built with Android platform components and open-source libraries.
Data export and deletion
From Settings, you can export a connection backup, import a saved configuration, or perform a full reset. Exported backups can include server URLs, preferences, API keys, relay session tokens, device IDs, and dashboard cookies, so keep them private. Full reset permanently deletes local data including encrypted credentials. Uninstalling the app removes all stored app data from your device.
Children's privacy
Hermes-Relay is not directed at children under 13. We do not knowingly collect information from children.
Changes to this policy
Updates will be posted on this page with a revised effective date. Significant changes will be noted in the app's release notes.
Contact
For privacy questions, open an issue in the Hermes-Relay issue tracker.
Open source
Hermes-Relay is MIT licensed and publicly auditable.