This privacy policy applies to the Send to Hermes Chrome browser extension.
Send to Hermes does not collect, sell, or share your data. Your chats, selected content, and API keys stay on your device and travel only to the Hermes AI server you configure yourself. No analytics, no tracking.
The only optional off-device data is your settings sent for cloud sync (if you sign in and enable it), which is end-to-end encrypted on your device — the sync server stores ciphertext only and can never read your API keys or settings. Message content is never sent to our server.
We collect nothing. The extension does not use analytics, tracking, telemetry, or any third-party services.
All configuration data — your Hermes API endpoint URL(s), API key(s), language preference, and service list — is stored
locally in your browser via chrome.storage.local. This data never leaves your device except
when sent directly to the Hermes API server you have configured.
Optional cloud sync: if you sign in and set a sync passphrase, a copy of your settings is uploaded to our sync server (Cloudflare-hosted) in end-to-end encrypted form. The passphrase derives an encryption key that exists only on your devices; the server stores and transmits only the ciphertext and cannot read the underlying configuration. You can reset or delete your synced data at any time inside the extension.
You can clear all stored data at any time by removing the extension from Chrome, or by deleting the values in the extension's popup settings.
The extension makes network requests in a few scenarios:
http://127.0.0.1:8642).
The extension developer has no access to this traffic, and it is never sent to our server.
chrome.identity); the extension then sends only a short-lived authorization code to our login endpoint to
receive a session token. We store only the minimal account profile you approved (name, email, avatar URL) needed to
identify your account.
No chat or message content is ever sent to the extension developer or our server.
The extension requests the following Chrome permissions, each with a specific purpose:
The identity permission (Chrome's OAuth support) is used for one purpose only: to let you optionally sign in with Google or GitHub so that cloud sync and account preferences can be attributed to your account.
chrome.identity.launchWebAuthFlow OAuth flow. The extension asks only for the minimal
scopes needed for login: openid email profile (Google) and read:user user:email (GitHub) — it
never requests access to Gmail, Drive, documents, contacts, or any other account data, and never reads
your passwords.
The alarms permission schedules exactly one background timer (hermes-sync)
that fires roughly every 15 minutes to check whether your cloud-sync settings changed on another device and,
if so, pull the updated (encrypted) settings. It is used only for this periodic cloud-sync check.
No data is sold, rented, shared, or disclosed to any third party. Your chats and message content are never transmitted to our server or the extension developer.
The only data our servers hold is (a) the minimal account profile you explicitly approved when signing in with Google/GitHub and (b) your end-to-end encrypted cloud-sync settings (ciphertext only, unreadable by us). This data is processed solely to provide the optional cloud-sync feature and is never used for advertising, profiling, or any other purpose.
If this privacy policy changes, the updated version will be published at the same URL. Continued use of the extension after changes constitutes acceptance.
For questions about this privacy policy, contact boping2010@gmail.com.
Follow on X: @fremango960
Last updated: 2026-08-22