Privacy
What this product reads, what it refuses to keep, and who can see it.
Hermeas is operated by Enterprises Automated Inc. It reads the mail and calls you connect so a deal can show what was actually said. Most of what it reads is thrown away in the same pass. This page says which parts, and why the throwing away is the point.
Google user data
Hermeas’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements
The scopes requested are gmail.modify, which lets a connected mailbox be read and replied from, and userinfo.email, which names the mailbox that consented. Nothing is used for advertising. Nothing is sold or passed to a data broker. No general-purpose model is trained on it.
- Read
- Messages in the mailbox you connect
- Send
- Replies you approve, from your own address
- Never
- Advertising, resale, model training
The Chrome extension
Hermeas for Chrome reads only the pages it names, and only for the account that installed it
The extension runs on LinkedIn, Gmail, Google Docs and Drive, HubSpot and hermeasinc.com, and nowhere else. On a LinkedIn profile or an opened email it reads who you are looking at, so it can say whether that person is already in your People. In LinkedIn messaging it reads the conversations the page itself loads, and sends to Hermeas only those with people you already hold; a stranger’s words are never requested. It sends the messages and connection requests you approve, from your own browser, within the pace your account sets. Your LinkedIn sign-in never leaves your browser, unless you choose a cloud seat, in which case it is handed only to your own encrypted seat. Your Hermeas sign-in is kept in the browser’s own extension storage. Nothing the extension reads is sold, used for advertising or credit decisions, or used to train a model, and its use of that data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- Reads
- The person on screen, and conversations with people you already hold
- Sends
- Only what you approve, at your account’s pace
- Never
- Browsing history, other sites, advertising, resale
The discard
Mail from people you are not on a deal with is never stored
Every counterparty address is matched against the people already on your deals. A message that matches nobody is dropped in the same pass that read it — not hidden, not filtered later, never written. A mailbox holds newsletters, receipts, recruiters and family, and none of that is a sales conversation. The number it dropped is shown back to you on the Integrations page, because a promise nobody can see being kept is one nobody is reassured by.
Who can read it
You see a message because it was in your inbox
Not because a colleague shared it. This product grants access to nothing; it puts access people already have in one place. You sent it, received it or were copied: you see it. You were not on it: you do not, exactly as you would not by opening your own mail. That is one rule in one place in the code rather than a check repeated per screen.
Human access
Nobody here reads your mail
Not to improve the product, not to look at examples, not out of curiosity. The exceptions are the ones the Google API Services User Data Policy allows and no others: with your explicit agreement to view specific messages, where it is necessary to investigate abuse or a security incident, or where the law requires it.
Where it is held
Encrypted at rest, in the European Union
Credentials — the tokens for a connected mailbox, and any provider key you supply — are encrypted with AES-GCM before they are written, under a key this deployment holds and no customer shares. Message text and transcripts are stored in a Postgres database hosted in eu-west-1. Recordings you upload are kept so a quoted line can still be checked against the audio it came from.
- Credentials
- AES-GCM, per organisation
- Region
- eu-west-1
- Transport
- TLS everywhere
Ending it
Disconnecting stops the reading immediately; erasure removes the words
Disconnect a mailbox on the Integrations page and it is read no further, while the messages already on a thread stay — removing them would take real history off a deal other people were working. Ask for erasure and every readable field on that person’s messages is emptied, with the rows kept empty so a later sync cannot write them back. A sign-in can also be revoked from your own Google or Microsoft account settings at any time, without telling us first.
Who is involved
The services that touch this data, named
Supabase stores it, in the EU. Railway and Vercel run the software, in Amsterdam and Dublin. AssemblyAI transcribes recordings you upload. Anthropic and DeepSeek models do the reading and drafting. ElevenLabs carries voice calls an organisation turns on. BetterContact looks up work contact details only when someone approves the quote. Stripe handles billing. HubSpot, Fathom, Fireflies, LinkedIn, Google and Microsoft are sources you connect and can disconnect. No other party receives it.
Transfers
Held in the EU; some processing happens elsewhere
Records are stored in the EU. The background job queue runs in the United States, and model and voice providers may process the text they are sent outside the EU. Where personal data leaves the EU or UK it is covered by the provider’s standard contractual clauses.
Your rights
See it, correct it, take it with you, or have it erased
Under the GDPR and UK GDPR you may ask what is held about you, have it corrected, receive a copy in a portable format, object to or restrict its processing, or have it erased. Requests are answered within thirty days. You may also complain to your local data protection authority.
- Lawful basis
- Contract with your organisation, and its legitimate interest in running its own sales
- Retention
- For as long as the account is active, then erased within thirty days of a request
- Cookies
- Sign-in, theme and language only; no advertising or analytics cookies
Contact
Enterprises Automated Inc, at hermeasinc.com
The controller of the data Hermeas holds about its own users, and processor of the data each organisation connects. Questions about this page, a request to see what is held about you, or a request to erase it: [email protected]. A data processing agreement is available on request. Last updated 8 October 2026.
See the funnel run, and the gate hold.
A live walkthrough of the console: agents working an account end to end, and every action that would reach a customer stopping to wait for you.