// Legal
Privacy Policy
- Effective
- Version
- 2026-09-26
This Privacy Policy explains what personal data we collect when you use Hermes API at https://api.hermes-ai.net, including its console, documentation, Playground and API (the "Service"), how we use and share it, how long we keep it and the rights you have.
This policy describes our processing; it is not a request for your consent. Where we rely on consent for something, we will ask for it separately. Our Terms of Service govern your use of the Service.
See also Terms of Service
1.Who we are#
The Service is operated by MIMOS AI LTD, a private limited company registered in England and Wales under company number 15265239, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. MIMOS AI LTD is the controller of the personal data described in this policy.
For privacy questions or requests, email support@hermes-ai.net.
If you build on the Service
If you use the Service to process personal data about your own end users (for example in prompts or uploaded media), you are responsible for telling them about it and having a lawful basis for it. Please contact us if you need to discuss data processing terms before sending such data.
2.Information we collect#
Account information
- Your name or display name, email address, whether it is verified, when your account was created and your account role.
- From Google or GitHub, which are the only ways to sign in: your account identifier, name, email address and profile image link from that provider, and the sign-in tokens it issues. We ask only for basic profile and email access.
- If you created an account with a password before password sign-in was retired: that password's hash, never the plain text. It can no longer be used to sign in.
Sign-in and security information
- Session records, including IP address, browser user agent and when the session was created and expires.
- Rate-limit records used to prevent abuse, which may include IP addresses.
- Account status, such as whether an account is suspended and why.
- API key details: name, a short prefix, scopes, expiry, usage count and last use. Full API keys are not stored in plain text.
Task data
- Task records: the model, the full input parameters you submit (such as prompts, options and references to uploaded media), the idempotency key, status, error codes, price and timestamps.
- Results: text results are stored in the task record; image, video and audio results are stored as files.
- Uploaded media: images and videos you upload as inputs, with their type, size and upload time.
Please do not include personal data in prompts or uploads unless you need to, especially sensitive information or information about other people.
Credit and payment information
- Your credit balance and each ledger entry (grants, holds, charges and releases), with the related task and time.
- The reason recorded when we add credits to an account manually.
- When online purchase is available: order details from the payment provider, such as order number, product, amount, currency, tax, payment and refund status, and the information used to match the order to your account. We do not receive or store full card numbers.
Communications
If you email us, we receive your email address, the content of your message and any attachments.
Technical logs
Our application is designed to log only fixed error codes and request IDs when something goes wrong, not request bodies, API keys or raw error messages from the execution platform. Our hosting infrastructure, such as servers and reverse proxies, may record access logs containing IP addresses, request paths, times and status codes.
3.How we use information#
Under UK data protection law (and the GDPR, where it applies), we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and running your account and signing you in with Google or GitHub | Contract |
| Running your tasks and storing and returning results | Contract |
| Holding, charging and releasing credits; showing your balance and ledger | Contract |
| Purchases, refunds and billing questions (when purchase is available) | Contract; legal obligation |
| Answering support requests | Contract; legitimate interests |
| Service messages, such as verification, security or Terms-change notices | Contract; legitimate interests |
| Preventing abuse, fraud and attacks; rate limiting; handling misuse reports | Legitimate interests; legal obligation |
| Reviewing tasks with an uncertain outcome and handling disputes | Contract; legitimate interests |
| Meeting legal, tax and accounting duties and responding to lawful requests | Legal obligation |
Our legitimate interests are keeping the Service secure and reliable, preventing misuse and resolving disputes. You can object to processing based on legitimate interests (see Your rights).
We do not:
- sell your personal data or share it for cross-context advertising;
- send marketing emails (if we ever want to, we will ask for your consent first);
- use your inputs or outputs to train AI models of our own;
- make decisions about you that have legal or similarly significant effects based solely on automated processing.
6.International transfers#
We are registered in England and Wales. Our model execution platform and other service providers may process data in other countries, which may not have the same data protection laws as your country. Where UK data protection law (or the GDPR) applies to these transfers, we will take the steps it requires for them. Contact us if you would like more information about a particular transfer.
7.How long we keep information#
| Data | How long |
|---|---|
| Uploaded input files | Expire 7 days after upload. After that they can no longer be accessed through the Service and are deleted by a periodic maintenance process. |
| Stored result files (images, video, audio) | Expire 30 days after they are saved. After that they can no longer be downloaded and are deleted by a periodic maintenance process. |
| Task records, including input parameters and prompts, text results and status | Kept while your account exists. This is separate from the file expiry above: task records remain after the related files have been deleted. |
| Credit ledger and order records | Kept while your account exists and afterwards for as long as needed for tax, accounting, fraud prevention and dispute handling, as the law requires or allows. |
| Account information and API key details | Kept while your account exists. |
| Session and rate-limit records | Kept for as long as needed for their purpose. |
| Support emails | Kept for as long as needed to resolve your request and any related dispute. |
| Backups | Backup copies, where retained, may contain deleted data until the relevant backup is deleted. Any restoration from a backup will respect applicable deletion requests. |
The model execution platform and other providers decide how long they keep the data they receive; this table does not cover them.
8.Security#
Our measures include:
- encrypting connections with HTTPS;
- storing API authentication values (and any legacy password) as hashes, plus encrypted copies of new API keys for viewing after sign-in;
- encrypting the credentials we use to call the execution platform;
- signed download links for uploaded media that are valid for 1 hour, and result files that can only be downloaded by the account that owns them or its API keys with read permission;
- API keys with access controls, optional expiry dates and rate limits;
- application logs designed not to record request bodies or keys.
No system is completely secure. If a security incident affects your personal data, we will notify you and/or the relevant authority where the law requires it.
9.Your rights#
Depending on where you live, you may have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data deleted in certain circumstances;
- restrict processing, or object to processing based on legitimate interests;
- receive data you provided in a common machine-readable format;
- withdraw consent at any time where we rely on consent, without affecting earlier processing;
- complain to a data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk); elsewhere, the authority where you live or work.
You can view your tasks, credit ledger and API keys in the console, and delete API keys there. For anything else, including closing your account and deleting data, email support@hermes-ai.net from your account email address. We may need to verify your identity first. We will respond within the time the law requires, normally one month.
Please note:
- account closure and data deletion are currently handled manually;
- we may need to keep some information to meet legal duties, such as tax and accounting records, or to handle an open dispute;
- deletion of data already sent to the model execution platform is governed by that platform's rules.
We would appreciate the chance to deal with your concerns before you approach the authority, so please contact us first.
10.Children#
The Service is only for people aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, please contact us and we will deal with it.
11.Third-party sites and services#
The Service links to third-party sites and services, including checkout pages and third-party sign-in pages. Their handling of your data is governed by their own policies.
12.Changes to this policy#
We may update this policy. For material changes, we will post a notice in the Service at least 14 days before the change takes effect and, where email delivery is available, also email the address on your account. The effective date and version at the top of this page show which version applies.
13.Contact#
MIMOS AI LTD, registered in England and Wales, company number 15265239.
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Email: support@hermes-ai.net