Privacy

Last updated 8 October 2026

Hermit keeps memory for your AI agents. This page says what that means for your data: what we collect, what we never store, who helps us run the service, and how to take everything with you or delete it.

What we collect

Your account

Your GitHub user id and login if you sign in with GitHub, your Solana wallet address if you sign in with a wallet, or both. We don't ask for an email address, a name or a password.

Memory

The text that you or your agents write to Hermit: facts, decisions, preferences and file notes, with the project it belongs to, its kind, the model that wrote it and when. Memory text is encrypted at rest.

Usage

Counters of reads and writes per account and month, used for credit and the free allowance, and records of the $HRMT burns credited to your account (the transaction signature and amount, which are public on Solana anyway).

Security logs

IP addresses and request metadata, kept briefly for rate limiting and to investigate abuse and errors.

Cookies

One session cookie that keeps you signed in to the app. No tracking cookies, no advertising, no third-party analytics.

What we never store

  • Your source code. Hermit doesn't read your disk or repository and doesn't send your files anywhere. It only receives what your agent chooses to save, and a file note is a path and a line about it, not the file's contents.
  • Secrets. API keys, tokens, private keys and secret .env values are replaced with [redacted] before anything is written.
  • Your wallet's private key or seed phrase. Hermit never asks for them. Signing in is one signed message, not a transaction.
  • API keys and access tokens in plain text. Only their hashes, which is why a key is shown once.
  • Full chat transcripts.

How we use it

Only to run Hermit: to give your memory back to your own agents and the people you share a team project with, to count credit, to keep the service secure, and to fix problems. We don't sell your data, we don't use your memory to train models, and we don't show ads.

Memory text is sent to the model that reads it, through the client you connected. What that model's provider does with it is covered by their terms, not ours.

Processors

A few providers run parts of the service for us and see only what they need to:

  • Vercel — hosting and request handling.
  • Neon — the Postgres database where accounts and encrypted memory are stored.
  • A Solana RPC provider — to verify burn transactions on chain. It sees the public transactions we look up, not your memory.
  • GitHub — only if you choose to sign in with it.

Retention and deletion

Your memory stays until you delete it. You can delete a single memory, a whole project, or your account at any time in the app. Forgetting a memory erases its text at once; deleting a project or your account removes it from the live database right away.

Database backups are kept for a limited time for disaster recovery and age out on their own, so deleted data disappears from them as they expire. Security logs are kept only as long as needed to protect the service. Burn transactions are on Solana and public by nature; we can't remove them from the chain.

Export

Export any project as JSON or Markdown from the app, or with GET /api/v1/projects/{slug}/export. Exporting is free.

Contact

Questions or requests about your data: email hello@usehermit.xyz or send a direct message to @useHermit on X. We will never ask you for a seed phrase, a private key or a payment.

Changes

If this policy changes, we update this page and the date at the top. Significant changes are announced on @useHermit before they take effect.