Privacy Policy
Hermes is a space for your inner life — your dreams, the meaningful coincidences you notice, your reflections, and your astrological chart. Because the material you bring is deeply personal, we hold it with care. This policy explains, in plain language, what we collect, why, who we share it with, and the control you have over it.
1. Who we are
“Hermes” (“we,” “us,” or “our”) is the operator of the Hermes mobile application and the website at www.hermesdecode.com (together, the “Service”). For any privacy question or request, contact us at dreams@hermesdecode.com.
2. Information we collect
We only collect what the Service needs to function. We do not sell your data, and we do not run third-party advertising or analytics-tracking SDKs.
Information you provide
- Account details: your username, email address, and a securely hashed password.
- Birth data (optional): your birth date, time, and place (city/country and the corresponding coordinates and time zone), used solely to calculate your natal chart and transits.
- Journal content: the dreams, synchronicities, notes, and titles you record.
- Voice input (optional): when you choose to capture an entry by speaking — a voice memo, or a spoken reply during a guided session — the recording is transcribed to text. The audio itself is used only to produce that transcription and is not stored; only the resulting text is saved as your entry.
- Psyche & reflection content: your chat conversations with the Hermes companions, self-assessment answers, word-association responses, typology results, archetype journals, and mandala reflections.
- Preferences: language, pronouns (optional), experience level, and notification settings.
Information we generate for you
- AI interpretations: the readings, meanings, and reflections the Service produces from your entries.
- Your evolving profile: to give continuity across sessions, we maintain a private summary of your recurring symbols, themes, and patterns (internally: your “memory summary,” “pattern registry,” detected complexes, typology, and current archetype). This is derived from your own content and is visible only to you and to the AI that personalizes your readings.
Information collected automatically
- Push token: if you enable notifications, a device push token so we can deliver them.
- Technical/log data: standard server logs (such as request times and error diagnostics) needed to operate and secure the Service.
3. How we use your information
- To provide the core experience — generating dream and synchronicity interpretations, natal-chart and transit readings, companion conversations, and personalized daily insights.
- To remember context across your sessions so Hermes can recognize your recurring symbols and themes.
- To send notifications you’ve opted into (for example, daily transit insights), which you can turn off at any time.
- To maintain, secure, debug, and improve the Service.
- To communicate with you about support requests.
We rely on your consent and on the performance of our agreement with you (providing the Service you signed up for) as the legal bases for this processing.
4. AI processing & third parties
Hermes uses third-party AI to generate interpretations and conversations. When you request a reading or chat with a companion, the relevant content — for example, the dream text you submit, or your message and the recent context needed to answer it — is sent to OpenAI for processing and returned to you.
Voice transcription. When you record a voice memo or speak during a guided session, the audio is sent to OpenAI’s Whisper service to be transcribed into text. The recording is used solely to generate that transcript and is not stored by Hermes — only the resulting text is kept as your entry.
Service providers (sub-processors)
We share data only with the providers that make the Service run, each acting on our behalf:
| Provider | Purpose | Data shared |
|---|---|---|
| OpenAI | Generating interpretations, readings, and companion replies; transcribing voice input (Whisper) | The entry text and context you submit for that request; for voice input, the audio recording, which is transcribed and not retained |
| Expo | Delivering push notifications | Your device push token and the notification content |
| Railway | Application hosting & database | All stored account and journal data, securely hosted |
We do not sell, rent, or trade your personal information, and we do not share it for advertising.
5. Sharing with other users (social features)
Hermes includes optional social features — friend connections, shared artifacts, relationship (synastry) readings, and synchronicity “echoes.” These only operate when you choose to use them:
- Connections are made through a friend code you choose to share.
- Content is shared with another person only when you explicitly share it, or when you have enabled a specific sharing toggle (for example, allowing synastry with inner-circle friends).
- You control these permissions in Settings → Account → Privacy and can change or revoke them at any time.
If you don’t use the social features, your journal and reflection content remains private to your account.
6. Data retention
We keep your information for as long as your account is active so the Service can provide continuity. You can delete individual entries at any time inside the app. When you delete your account, we delete your personal content from our active systems; residual copies may persist in routine backups for a limited period before they are overwritten.
7. Security & encryption
We want to be precise about how your data is protected, because the material you bring is sensitive:
- In transit: all data moving between your device, our servers, and our AI provider travels over encrypted connections (HTTPS/TLS).
- Passwords: stored only as salted one-way hashes (bcrypt), never in readable form — not even we can see them.
- Authentication tokens: kept in your device’s secure storage (Keychain on iOS, Keystore on Android).
- Field-level encryption at rest: your most sensitive content — the dreams, synchronicities, notes, companion conversations, self-assessment and reflection entries you record, and the AI interpretations generated from them — is individually encrypted (AES-128) before it is written to our database. If the database or one of its backups were ever exposed on its own, that content would appear as unreadable ciphertext rather than plain text.
- Infrastructure protections: the database also sits behind account access controls and encryption of the underlying storage at the hosting level, adding a further layer beneath the field-level encryption above.
- What we’re honest about: this is not end-to-end (“zero-knowledge”) encryption. The encryption key is held securely by our application server, because Hermes has to be able to decrypt your entries to show them back to you and to generate interpretations. So while your content is protected against exposure of the database alone, it is not hidden from our own systems while the Service is running. We never send your password to anyone, and we send AI providers only the specific content needed to fulfill a request.
No system is perfectly secure, but we take measures appropriate to the sensitivity of the material you trust us with, and we will continue to strengthen them as Hermes grows.
8. Your rights & choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can:
- Access & edit most of your data directly in the app.
- Delete individual dreams, synchronicities, and entries at any time.
- Delete your account and all associated personal content directly in the app, under Settings → Account → Delete Account.
- Manage notifications and social-sharing permissions in Settings.
Account deletion is available directly in the app (Settings → Account → Delete Account) and erases your personal content from our active systems. To exercise any other right that isn’t available in-app — such as a full data export — email dreams@hermesdecode.com and we’ll respond within a reasonable timeframe.
9. Children
Hermes is intended for users 16 years of age or older. We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact us and we will delete it.
10. International users
Hermes is operated using infrastructure and AI providers that may process data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers. By using the Service, you understand your information may be processed in these locations.
11. Changes to this policy
We may update this policy as the Service evolves. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you in the app. Continued use after changes take effect means you accept the revised policy.
12. Contact
Questions, requests, or concerns about your privacy? Reach us any time at dreams@hermesdecode.com.