Privacy Policy
Last updated: May 13, 2026
This Privacy Policy describes how hermesweb (operated by Gustavo Policarpo, hereinafter “we”) collects, uses, stores and protects users' (“you”) personal data, in compliance with Brazil's General Data Protection Law (LGPD, Law No. 13.709/2018).
1. Data we collect
- Account: email, name (optional) and password, stored as a bcrypt hash.
- Connector OAuth: access and refresh tokens for services you connect voluntarily (Google Drive, Gmail, Calendar and others). These tokens are encrypted at rest with AES-256-GCM before being written to the database.
- Agent-produced content: files, memories and knowledge the agent creates at your request. Stored in a per-user isolated environment.
- Minimal telemetry: AI usage count per session (for billing) and login date/time. We do not use third-party tracking cookies.
2. Purpose of processing
We process data only to: (i) deliver the contracted service; (ii) process credit usage; (iii) comply with legal obligations, such as issuing invoices and tax records.
3. Sharing
We do not sell data. We share only with strictly necessary sub-processors: Stripe (payments), file storage providers and the AI providers you select (Anthropic, OpenAI, Google and others) to respond to your instructions. The content of your conversations with the agent is sent to the chosen AI provider.
4. Data subject rights (LGPD, art. 18)
You have the right, at any time and free of charge, to:
- Confirm the existence of processing and access your data;
- Correct incomplete, inaccurate or outdated data;
- Delete your account and all associated data, under Dashboard → Settings → Delete account;
- Request data portability;
- Withdraw consent;
- File a complaint with the ANPD (gov.br/anpd).
5. Security
- Passwords: bcrypt hash.
- OAuth tokens and API keys: encrypted at rest with AES-256-GCM.
- Transport: HTTPS required (TLS 1.2 or higher).
- Database: accessible only via the internal network.
- Agent environment: isolated per user, with resource limits.
- Rate-limiting on authentication endpoints.
6. Retention
Account data is kept while the account exists. After deletion, it is removed within 30 days, including from backups. Tax records are kept for 5 years, as required by law.
7. Data Protection Officer (DPO)
To exercise your rights or ask questions, write to privacidade@hermesweb.app. We reply within 15 business days.
8. Changes
Changes to this policy will be communicated by email and reflected in the “last updated” date at the top of this page.