Privacy
Hermes Products Privacy Policy
The canonical Hermes Products Privacy Policy, including the strict Fin Hermes product and account boundary.
Canonical shared legal pack 2026-08-03.1; Fin Hermes consumes the exact versioned public copy.
Hermes Products Privacy Policy
Version: 2026-08-03.1
Effective date: The date this approved version is first published
Operator and controller: HODL Media Inc.
Address: 1052 High Street, Palo Alto, CA 94301, United States
1. Scope
This Privacy Policy explains how HODL Media Inc. ("HODL Media", "we", "us") handles personal data when a person uses standalone Hey Hermes or Fin Hermes (together, the "Hermes Products"). It covers the product websites, iPhone apps, accounts, managed services, support, and the product-specific data described below.
HODL Media Inc. is incorporated in Delaware, USA. The California address above is its public business address and does not change its incorporation jurisdiction.
Hey Hermes and Fin Hermes are separate products. Each has its own account, authentication, entitlement, workspace or runtime, support path, and deletion journey. We do not join the products merely because email addresses or other displayed details match. A cross-product interaction requires a specific, authenticated and authorized connection.
2. Data we handle and why
| Data category | Examples | Purposes |
|---|---|---|
| Account, contact, and authentication | Product account ID, verified identity-provider issuer and subject, email or profile details supplied by the provider, session and device-binding records | Create and secure the selected product account; sign users in and out; prevent unauthorized or cross-product access |
| Purchases and entitlements | Store product, purchase and entitlement references, trial/renewal/expiry/grace status, opaque RevenueCat App User ID, refund or dispute state | Provide paid or complimentary access; Restore Purchases; prevent duplicate or foreign-product entitlement use; meet accounting and dispute duties |
| User content and commands | Messages, prompts, files, tasks, workspace content, voice input where used, and outputs | Perform the work the user requests; preserve the user's product history and workspace; provide export, recovery, and support where available |
| Connections | Provider choice, connection state, approved scopes, encrypted credential material or protected references, and requested actions | Connect a service chosen by the user and perform only authorized work within that connection |
| Usage, diagnostics, security, and audit | Feature and model usage, timestamps, run/job state, device/app and error data, security events, redacted audit and support-access receipts | Operate, meter, protect, troubleshoot, and improve reliability of the service; enforce allowances and investigate incidents |
| Support communications | Messages, attachments the user chooses to send, case state, and resolution records | Respond to the user, diagnose the reported issue, keep a support history, and protect the service |
We process this data as needed to perform the contract with the user, comply with law, protect the service and users, and pursue legitimate operational and security interests that do not override the user's rights. Where applicable, we ask for consent, including for a user-selected Connection or device permission. A user may withdraw consent, but this does not invalidate earlier lawful processing and may make the selected feature unavailable.
We do not sell personal data. We do not use cross-app tracking or targeted advertising. We do not silently link Hey Hermes and Fin Hermes accounts by email. HODL Media does not use customer content to train its own models.
3. Standalone Hey Hermes
Hey Hermes may handle the common categories above plus the user's private Hermes workspace and runtime content, conversations, files, tasks, memory, voice, Connection metadata and secrets, runtime and backup-control records, support grants, and audit records.
Hey Hermes uses this data to provide and secure a managed Hermes runtime, deliver requested AI and computer work, maintain the account and workspace, apply the user's selected AI Access and Connections, meter included usage, deliver notifications, and provide user-authorized support. Customer workspace content belongs to the user's product-local runtime boundary. Control-plane records are limited to what the managed service needs.
4. Fin Hermes
Fin Hermes may handle the common categories above plus product-local watchlists, portfolios, positions, transactions entered or imported by the user, finance conversations and jobs, finance-context and research/source artifacts, and optional connection status or data for a financial provider if that feature is made available and the user chooses to connect it.
Fin Hermes uses this data to show and preserve the user's financial context, research requested questions, produce source-backed results, prepare proposed actions, and maintain versioned records and receipts. Fin Hermes does not adopt an account, portfolio, entitlement, runtime, history, or provider connection from HODL, LiveQuote, CapChat, or standalone Hey Hermes merely because an email or another displayed value matches.
Broker connection is not an active public-launch feature in this version. We will update the provider disclosure before enabling a new broker flow for public users.
5. Providers and disclosures
We disclose data only to operate a requested feature, comply with law, protect rights and safety, or complete a corporate transaction subject to appropriate protections. The selected route and feature determine which provider receives data.
| Provider or recipient | Product and purpose | Data disclosed | Activation boundary |
|---|---|---|---|
| Apple identity services | Hey and Fin sign-in where selected | Identity token and the account details Apple makes available | Only when the user chooses Apple sign-in and the exact product client is configured |
| Google identity services | Hey and Fin sign-in where selected | Identity token and the account details Google makes available | Only when the user chooses Google sign-in and the exact product client is configured |
| Apple App Store | iPhone subscription purchase, renewal, cancellation, refund, and Restore Purchases | Store account handles payment; the product receives purchase/product/status references, not the user's full payment-card details | Only for an App Store transaction in the same product |
| RevenueCat | Product-local subscription and entitlement administration | Opaque product App User ID, product/entitlement and lifecycle event data | Separate Hey and Fin projects, products, entitlements, and identifiers; no email-based cross-product merge |
| Hetzner | Private managed infrastructure | Runtime/workspace content stored on the provisioned service, network and operational metadata | Only for the exact product/account runtime; infrastructure sharing does not share product identity or data authority |
| OpenAI | Selected ChatGPT/OpenAI route or service operation | Content needed for the selected request, response and limited routing/usage metadata | Only when that route is selected or authorized for the request |
| OpenRouter and the model provider named for the route | Included managed-AI or another selected routed model | Content needed for the request, response and limited routing/usage metadata | Only for the selected managed route; provider handling and available privacy settings apply to that route |
| A user-selected AI provider, including Anthropic where connected | User-selected AI Access or BYOK route | Content needed for the request plus connection/routing metadata | Only after the user connects or selects that provider; provider terms also apply |
| Apple Push Notification service (APNs) | Optional iPhone notifications | Device push token and the minimum notification payload and delivery metadata | Only after notification permission and product-local device registration |
| HODL Media-owned market, news, research, and portfolio services; disclosed public or licensed sources | Fin market context, research, sources and portfolio features | Exact query/context needed for the requested result, product-local resource reference, source and freshness metadata | Only for the Fin feature requested; no foreign-product account authority is transferred |
The table is the launch disclosure set, not a claim that every listed option is enabled for every user. A final shipped-binary and provider audit determines the separate App Store privacy answers for each app. We will update this Policy before adding a materially different public data recipient or purpose.
6. AI processing and Connections
AI output may require sending the relevant prompt, selected context, files or tool results to the AI provider for the route the user selected or the product is authorized to use. We minimize the content to what is needed for that work. Third-party provider terms and data practices apply; we do not make an absolute no-training or zero-retention promise on a third party's behalf.
A Connection operates only within the scopes and product account approved by the user. Provider credentials and protected references are encrypted or kept in protected storage and are not returned as normal application data. A user can disconnect a Connection through the available product flow; the provider may retain data under its own terms.
7. Retention and deletion
| Data or event | Retention rule |
|---|---|
| Active core data: account/profile, conversations, workspace/files/tasks, watchlists and portfolios | Kept while the relevant product account/service is active or until the user deletes it |
| Confirmed account deletion | Sign-in and sessions revoked promptly; active product data purged within 30 days; the other Hermes Product is never deleted by matching email |
| Subscription cancellation | Not account deletion; access and data handling follow the actual entitlement state |
| Billing failure and service expiry | Seven-day grace, then a 14-day export/recovery window after expiry, followed by teardown and purge of private runtime/workspace product content |
| Backup residuals after confirmed deletion | Expire no later than 90 days; a deletion marker is replayed after disaster restore |
| Fin broker/action artifacts | 7 days |
| Fin finance-context artifacts | 14 days |
| Fin general research/source artifacts | No more than 30 days |
| Security and audit evidence | 90 days by default; longer only for an active incident or legal hold |
| Support communications | 24 months after resolution |
| Billing, tax, entitlement, fraud, and dispute records | Up to 7 years where accounting, tax, fraud, dispute, or another legal obligation requires it; this record set is minimized and segregated |
| Active legal hold | Only the required data until the hold resolves |
An account-deletion request must be authenticated, reauthenticated where required, explicit and confirmed. Account deletion, Store subscription cancellation, and refund requests are separate actions. Product routes explain their current availability; a support email does not falsely stand in for an in-app deletion flow required for launch.
8. Security
We use technical and organizational safeguards appropriate to the data and risk, including product-local authorization, encrypted or protected secret storage, redacted logs and receipts, scoped support access, and separated runtime and control responsibilities. No security measure can guarantee that an incident will never occur. Users must protect their devices, accounts and credentials and should not send passwords, authentication codes, API keys, payment credentials or brokerage credentials by support email.
9. International handling
HODL Media is a United States company and the Hermes Products use providers in the United States and Europe, including private infrastructure in Germany. Data may therefore be processed outside the user's country. Where required, we use an available lawful transfer mechanism and contractual, technical or organizational safeguards. Mandatory local privacy rights remain available.
10. Rights and choices
Depending on the user's location, rights may include access, correction, deletion, portability, restriction, objection, withdrawal of consent, and a right to complain to a regulator. We may need to verify identity and product account authority before acting. We may retain limited data where required by law or needed for security, fraud, disputes, or a legal hold.
Use the authenticated product features where available or contact the relevant product team:
- standalone Hey Hermes:
contact@heyhermes.app - Fin Hermes:
support@finhermes.app
These are product-local contacts. They are not representations that a separate corporate-wide legal or privacy mailbox exists.
11. Age eligibility
The Hermes Products are for users aged 16 or older. A user under the local age of majority must have consent from a parent or legal guardian where local law requires it. No person under 16 may create or use an account.
12. Changes
We may update this Policy as products, providers or legal requirements change. The published version and effective date identify the controlling copy. We will provide notice when required. Any translation is provided for convenience; the approved English version controls to the extent local law permits.
