emploidai Marketplace

Hermes Agent Chat privacy policy

Policy content supplied in the product package by its publisher.

← Back to Hermes Agent Chat

Privacy Policy / 隐私政策

Effective Date / 生效日期: May 12, 2026 / 2026年5月12日 Version / 版本: v0.0.1 Plugin Name / 插件名称: Hermes Agent Chat / Hermes Agent 对话 License / 许可证: Apache License 2.0


English Version

Overview

The Hermes Agent Chat Plugin ("Plugin") connects Dify to a user-configured Hermes Agent API Server. It allows Dify workflows and agents to send text and uploaded images to Hermes Agent through Hermes' HTTP API. This privacy policy explains how data is handled when you use this plugin within the Dify platform.

License Information

This plugin is licensed under Apache License 2.0, a permissive open-source license that allows use, modification, and distribution. The full license text should be provided with the plugin package or project repository.

Data Collection

What we DO NOT collect:

  • Personal identification information for analytics or tracking
  • User account details outside Dify runtime metadata needed for conversation routing
  • Usage analytics or tracking data
  • Device information
  • Location data
  • Cookies or similar tracking technologies

What we process:

  • User messages sent through the Dify tool
  • Dify uploaded image files passed to the tool
  • Dify runtime metadata used to derive Hermes conversation keys
  • Provider credentials configured in Dify, including Hermes API Server base URL, API key, model, and timeout
  • Hermes responses returned to Dify

Data Processing

Hermes API Server Processing:

  • Tool requests are sent to the configured Hermes API Server /v1/responses endpoint.
  • Provider validation requests are sent to the configured Hermes API Server /v1/models endpoint.
  • Text messages are sent as Responses API input_text.
  • Uploaded images are converted to base64 and sent as input_image parts.
  • A derived conversation key is sent through the Responses API conversation field with store=true to support context retention.

Local Plugin Processing:

  • The plugin validates configuration, uploaded image MIME type, file size metadata, aggregate upload size, and runtime metadata.
  • Uploaded images are read only for the current tool invocation.
  • Uploaded images may be base64 encoded in memory before being sent to Hermes.
  • The plugin does not intentionally persist uploaded image content after the invocation.
  • Remote image URLs, document URLs, and non-image uploads are not supported in this version.

Data Storage

No Plugin Data Retention:

  • The plugin does not store copies of uploaded images after processing.
  • The plugin does not store chat messages or Hermes responses outside the current invocation.
  • The plugin does not maintain its own database or analytics store.
  • Provider credentials are stored by Dify according to Dify's plugin credential storage mechanisms.

Hermes and Downstream Handling:

  • Hermes API Server may retain conversation context because the plugin sends store=true for Responses API calls.
  • Hermes may call configured model providers, tools, channels, or plugins according to your Hermes Agent configuration.
  • Users should review their Hermes deployment, model provider, and Dify privacy policies for complete data handling behavior.

Security Measures

Data Protection:

  • The plugin sends requests only to the configured Hermes API Server base URL.
  • API Server authentication uses a bearer token configured in Dify provider credentials.
  • Uploaded image MIME types, sizes, and aggregate size are checked before forwarding.
  • Conversation routing parameters are derived from Dify runtime metadata and are not exposed as LLM-controllable tool parameters.
  • Remote URL fetch inputs are not exposed in this version to avoid SSRF and DNS rebinding risks.

Important Security Notes:

  • Hermes API Server credentials are operator-level credentials. Protect them carefully.
  • Do not expose Hermes API Server directly to the public internet.
  • If using plain HTTP, use it only on trusted private networks such as loopback, VPN, tailnet, Docker host networking, or another private ingress path.

Third-Party Services

  • This plugin relies on the Hermes API Server configured by the user.
  • Hermes may rely on external LLM providers, tools, channels, or plugins configured by the user.
  • Third-party services process data according to their own privacy policies and the user's Hermes/Dify configuration.

Contact Information

Developer: https://github.com/sawyer-shi Email: sawyer36@foxmail.com Source Code: https://github.com/sawyer-shi/dify-plugins-hermes_agent_chat Support: Available through Dify platform and GitHub Issues


中文版本

概述

Hermes Agent Chat 插件("插件")用于将 Dify 连接到用户配置的 Hermes Agent API Server。它允许 Dify workflow 和 agent 通过 Hermes HTTP API 向 Hermes Agent 发送文本和上传图片。本隐私政策说明您在 Dify 平台中使用本插件时,数据如何被处理。

许可证信息

本插件采用 Apache License 2.0 许可证。这是一个宽松的开源许可证,允许使用、修改和分发。完整许可证文本应随插件包或项目仓库一起提供。

数据收集

我们不收集的内容:

  • 用于分析或跟踪的个人身份信息
  • Dify runtime 会话路由所需信息之外的用户账户详情
  • 使用分析或跟踪数据
  • 设备信息
  • 位置数据
  • Cookie 或类似跟踪技术

我们处理的内容:

  • 通过 Dify 工具发送的用户消息
  • 传给工具的 Dify 上传图片文件
  • 用于派生 Hermes conversation key 的 Dify runtime 元数据
  • Dify 中配置的 Provider 凭据,包括 Hermes API Server 地址、API Key、模型和超时时间
  • Hermes 返回给 Dify 的响应内容

数据处理

Hermes API Server 处理:

  • 工具请求会发送到配置的 Hermes API Server /v1/responses endpoint。
  • Provider 校验请求会发送到配置的 Hermes API Server /v1/models endpoint。
  • 文本消息会以 Responses API input_text 发送。
  • 上传图片会转换为 base64,并以 input_image 发送。
  • 派生出的 conversation key 会通过 Responses API conversation 字段发送,并设置 store=true 以支持上下文保持。

本地插件处理:

  • 插件会校验配置、上传图片 MIME 类型、文件大小元数据、上传总大小和 runtime 元数据。
  • 上传图片只会在当前工具调用中读取。
  • 上传图片可能会在内存中 base64 编码后发送给 Hermes。
  • 插件不会有意在调用结束后持久保存上传图片内容。
  • 当前版本不支持远程图片 URL、文档 URL 和非图片上传。

数据存储

插件不保留数据:

  • 插件处理后不存储上传图片副本。
  • 插件不在当前调用之外存储聊天消息或 Hermes 响应。
  • 插件不维护自己的数据库或分析存储。
  • Provider 凭据由 Dify 按其插件凭据存储机制保存。

Hermes 和下游处理:

  • 因为插件调用 Responses API 时发送 store=true,Hermes API Server 可能会保留 conversation 上下文。
  • Hermes 可能会根据您的 Hermes Agent 配置调用模型提供商、工具、渠道或插件。
  • 用户应查阅自己的 Hermes 部署、模型提供商和 Dify 隐私政策,以了解完整数据处理行为。

安全措施

数据保护:

  • 插件只会向配置的 Hermes API Server Base URL 发送请求。
  • API Server 鉴权使用 Dify Provider 凭据中配置的 Bearer Token。
  • 上传图片的 MIME、大小和总大小会在转发前进行校验。
  • Conversation 路由参数来自 Dify runtime 元数据,不暴露为 LLM 可控工具参数。
  • 当前版本不暴露远程 URL 抓取输入,以避免 SSRF 和 DNS rebinding 风险。

重要安全说明:

  • Hermes API Server 凭据是 operator 级凭据,请妥善保护。
  • 不要将 Hermes API Server 直接暴露到公网。
  • 如果使用明文 HTTP,请仅在可信私有网络中使用,例如 loopback、VPN、tailnet、Docker host 网络或其他私有入口。

第三方服务

  • 本插件依赖用户配置的 Hermes API Server。
  • Hermes 可能依赖用户配置的外部 LLM 提供商、工具、渠道或插件。
  • 第三方服务会按照其自身隐私政策以及用户的 Hermes/Dify 配置处理数据。

联系信息

开发者: https://github.com/sawyer-shi 邮箱: sawyer36@foxmail.com 项目代码来源: https://github.com/sawyer-shi/dify-plugins-hermes_agent_chat 支持: 通过 Dify 平台和 GitHub Issues 提供


最后更新: 2026年5月12日