← Back to home

Privacy Policy

Effective date: March 16, 2026

1. Who We Are

Herm.Chat ("we", "us", or "our") is an AI agent platform that lets businesses deploy conversational AI agents on their websites and in Slack. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform, website, and services (collectively, the "Service").

2. Information We Collect

Information you provide directly

  • Account registration details (name, email address, password)
  • Billing and payment information (processed by Stripe — we do not store card numbers)
  • Content you upload to your knowledge base (documents, URLs, images, videos)
  • Bot configuration settings and agent instructions
  • Support communications and feedback

Information collected automatically

  • Usage data (pages visited, features used, session duration)
  • Log data (IP address, browser type, referring URL, timestamps)
  • Device identifiers and browser fingerprint data
  • Conversation data processed through your deployed AI agents

Information from third parties

  • OAuth tokens when you connect Slack or other integrations
  • Website content crawled at your direction via our site crawler

3. How We Use Your Information

  • To provide, operate, and improve the Service
  • To process transactions and send billing communications
  • To respond to your support requests and feedback
  • To send product updates, security alerts, and administrative notices
  • To detect and prevent fraud, abuse, or security incidents
  • To comply with legal obligations
  • To analyze usage trends and improve our product (aggregated, anonymized data)

We do not sell your personal data to third parties. We do not use your knowledge base content or conversation data to train our AI models or those of our LLM providers.

4. LLM Providers and Data Processing

When your AI agents process messages, content is sent to your selected LLM provider (OpenAI, Anthropic, or Google). Each provider processes data under their own privacy policies and data processing agreements. By using the Service, you acknowledge that conversation data is transmitted to these providers solely for inference purposes.

We have Data Processing Agreements in place with all third-party processors who handle personal data on our behalf.

5. Data Retention

We retain your account data for as long as your account is active. Conversation logs are retained for up to 90 days by default. Knowledge base content is retained until you delete it. You may request deletion of your data at any time (see Section 8).

Upon account termination, we delete or anonymize your personal data within 30 days, except where required by law to retain it longer.

6. Data Security

We use industry-standard security measures including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, and regular security assessments. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

7. Cookies and Tracking

We use essential cookies required for authentication and session management. We may also use analytics cookies to understand how our Service is used. You can control cookie preferences through your browser settings. Disabling essential cookies will prevent you from logging in.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your personal data ("right to be forgotten")
  • Object to or restrict certain processing activities
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at support@herm.chat. We will respond within 30 days.

9. GDPR and CCPA

For users in the European Economic Area (EEA), the United Kingdom, or California, additional rights apply under GDPR and CCPA respectively. Our lawful basis for processing personal data is typically contract performance (to provide the Service), legitimate interests, or your consent where indicated.

California residents may submit a "Do Not Sell My Personal Information" request, though we do not sell personal information. EEA users may lodge a complaint with their local supervisory authority.

10. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website at least 30 days before the changes take effect. Your continued use of the Service after that date constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at support@herm.chat.