Privacy Policy

Last updated: 2026-09-30 · Product: Kantharos · Contact: hello@kantharos.ai

This Privacy Policy explains how Kantharos (“Kantharos,” “we,” “us”) handles information when you use our website and Mac app (the “Service”).

1. Who we are

Kantharos is a client for the Hermes Cloud or Local or Remote gateway you select. That Hermes gateway remains the system of record for your agents and conversations.

2. Information we collect

Website analytics and your choice

We use Vercel Web Analytics to understand which public pages people visit and which installer links they click, so we can improve Kantharos and its setup experience. Reports include page paths, visit or click time, referrer, approximate location, browser, operating system and device category. Our installer-click event adds only platform and release version. We remove query parameters and fragments from the page URL before reporting it; we do not add names, email addresses, app installation identifiers, chats or credentials to website events.

Website analytics does not use tracking cookies. Vercel derives a temporary visitor hash from the incoming request and discards that visitor-session identifier after 24 hours. Vercel receives request IP addresses to deliver and secure the service; its Web Analytics reports do not store raw IP addresses as visitor identifiers. Ordinary hosting and security logs are separate and are handled under Vercel’s policies. See Vercel’s analytics privacy information.

Our current plan provides 12 months of viewable analytics history. That reporting window is not a promise that Vercel deletes all provider-held data at that point; its own retention policies also apply. Download clicks measure interest, not completed downloads, installations or unique app users.

We respect your browser’s Do Not Track or Global Privacy Control signal for this website integration. You can also turn website analytics off for this browser below. This choice is stored locally, does not block downloads and is separate from any app setting.

Website analytics choices require JavaScript. Browser content controls can also block analytics.

Daily app usage reporting in upcoming updates

The currently published 0.1.0/a19fd9a Mac and Ubuntu installers do not send a daily Kantharos usage report. We are preparing this feature for updated app releases; this notice describes that planned behavior, not reporting already active in those installers.

In releases that include it, usage reporting is on by default and can be turned off in Settings under Usage reporting. While the app is being used, it makes at most one reporting attempt per UTC day after meaningful foreground interaction. It does not run a background service, keep an offline queue or retry that day. Turning it off prevents further reporting requests; it does not restrict the app.

The report contains only a schema version, a random app-generated installation UUID, platform, app version, connection category (Local, Gateway, Cloud or unknown) and UTC activity day. It does not contain conversations, prompts, replies, bot names, files, credentials, account email, gateway addresses or hardware identifiers. The random identifier is pseudonymous, not fully anonymous; separate devices are not linked. These reports count active installations, not unique people.

The planned collector is a Kantharos-operated Cloudflare Worker with a Cloudflare D1 database. Installation/day records are retained for no more than 14 days to calculate weekly active installations; nonidentifying daily totals are retained for 13 months. The collector is designed not to store IP addresses, User-Agent or request headers, with request and body logging disabled. Cloudflare necessarily receives network IP addresses to handle requests and may process infrastructure or security logs under its own privacy policy; those provider logs are not controlled by the app payload. Collection will begin only in updated releases after the collector is deployed.

3. Hermes / Nous and other third parties

Your selected Hermes gateway processes your agents, chats, and sign-in. If you choose Hermes Cloud, Nous Research operates that gateway and its billing. If you choose a Local or Remote gateway, the operator of that Hermes installation controls it. Kantharos does not host a second agent runtime.

We use providers for the website, DNS, and email. They process data to provide those services.

4. How we use information

We do not sell your personal information.

5. Legal bases (EEA/UK where applicable)

Where GDPR/UK GDPR applies, we rely on contract performance, legitimate interests (secure/improve the Service), consent where required, and legal obligations.

6. Retention

We keep personal data only as long as needed for the purposes above, then delete or anonymize it, unless a longer period is required by law.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal data. Contact hello@kantharos.ai. For Hermes-side data, use Hermes / Nous account controls as well.

See also our Account deletion page.

8. Children

The Service is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal data from children.

9. Security

We use reasonable technical and organizational measures. No method of transmission or storage is 100% secure.

10. International transfers

We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards.

11. Changes

We may update this Policy. We will change the “Last updated” date and, for material changes, provide additional notice where appropriate.

12. Contact

Privacy and support: hello@kantharos.ai
Website: kantharos.ai