// legal / privacy_policy
Privacy policy.
last_updated 2026.08.09
this site
You are on the public marketing site at https://www.elderhermit.com. Elderhermit is created and operated by Gnosix. There is no sign-in on this property. The policy below covers both this site and the Elderhermit product at app.elderhermit.com. When you create an account on the product, additional terms apply — see Terms of Service.
Who runs Elderhermit
Elderhermit is built and operated by Gnosix (Mexico City). Gnosix is the data controller for this site and for the product. When we say “we” on this page, we mean Gnosix acting as the operator of Elderhermit. Contact: elderhermit@gnosix.io.
What we collect
On this marketing site: anonymous Vercel Analytics (page views, route timings, referrers) and PostHog product analytics, used to see which parts of this page lead people to try Elderhermit. PostHog here records page views and a small set of interactions — which pricing cycle you toggled, which call to action you clicked, which FAQ you opened. No form contents, no free text, and no session recordings on this site. We do not create a PostHog person profile for anonymous visitors. No Segment. No Google Analytics.
In the product (after sign-in):
- Account data via Clerk: email, optional name.
- Onboarding data: date of birth for the 21+ gate, philosophical baseline answers, and your timezone.
- Your date of birth may also be used to derive symbolic astrological context inside the product.
- Product data you create: habits, grimoire entries, tarot draws, chat with the Hermit, long-term memories.
- Billing data via Stripe: payment method tokens (we never see card numbers), invoice history.
- Operational telemetry: token usage per OpenRouter call (model, input/output token count, cost) — used to protect the Magus offer from abuse and never tied to message content.
- Safety telemetry: signals about misuse patterns (automated abuse, scraping attempts, content that violates the acceptable use rules in our Terms), together with the matched excerpt of the message that triggered them — used to act on the account and to review that action, never sold or shared. The record in our admin tools is deleted after 90 days; a copy of the excerpt is also emailed to our operations mailbox and that copy is not on a deletion schedule. See “How we handle abuse” below.
What we do NOT do
- We never train any AI model on your reflections. Your grimoire, chat with the Hermit, and long-term memories belong to you. They are stored in our database (Convex) and surface to the AI only inside your own session.
- We never sell your data.
- We never share your data with advertisers.
- We never read your reflections except in narrow operational scenarios (debugging an explicit support ticket you opened with consent, or investigating a specific safety incident under section 6).
Subprocessors
We use a small set of operational vendors. Each handles one slice and is bound by their own privacy contract:
- Convex — primary database. Stores all product data.
- Clerk — auth / account management.
- Stripe — billing and payment processing.
- Resend — transactional email (welcome, weekly review, billing receipts), and security alerts to our operations mailbox. A security alert contains your email address and the excerpt described in “How we handle abuse” below. That copy sits in a mailbox and is not covered by the 90-day deletion that applies to the record in our admin tools.
- OpenRouter — AI inference routing under a zero-data-retention provider policy. We do not route reflections to a provider that retains them for model training.
- Groq — speech-to-text processing when you choose to dictate a message.
- ElevenLabs — voice processing when an eligible user chooses a Hermit voice feature.
- Composio — connection and action layer when an eligible user explicitly links Notion or Google Calendar.
- PostHog — product analytics. In the product it runs server-side; on this marketing site it runs in your browser, as described under “What we collect” above. We do not send chat or reflection bodies as analytics events.
- Linear — issue tracking. When you submit a bug or feedback report from inside the app and it concerns production, the text you wrote is filed as an issue so it can be fixed. Your email address is not included. This applies only to reports you choose to send, never to your reflections, chats or grimoire.
- Vercel — hosting and Vercel Analytics (anonymous on this marketing site).
Birth date handling
We collect your date of birth during onboarding to enforce the 21+ age gate. It is stored encrypted at rest in our Convex database and may be used to derive symbolic astrological context for your own experience. It may be included in the minimum personal context sent through OpenRouter when relevant. Deleting your account deletes the date of birth with the rest of your profile.
Safety monitoring
To keep Elderhermit a serious tool for self-reflection, we monitor for patterns of misuse described in our Terms of Service — automated abuse, attempts to extract proprietary content, content that violates law, or use that puts the user or others at risk. When a pattern triggers a review, we record a structured event: account id, timestamp, signal class, action taken, and the excerpt of your message that matched — the matched phrase plus a short margin around it, never the full message body. That excerpt exists so a suspension can be checked by a human rather than trusted to a pattern match, and so a false positive can be found and reversed.
Two copies of that excerpt exist, and they do not have the same lifetime. The record in our admin tools is deleted automatically after 90 days. A copy is also sent by email to our operations mailbox so the review can happen quickly; that email is not deleted on a schedule and persists until it is deleted by hand, both in the mailbox and with our email provider. We may suspend or cancel the account in accordance with the Terms.
21+ and DOB
Elderhermit is exclusively for adults 21 years of age or older. We collect your date of birth at onboarding to verify age. DOB is retained for the lifetime of your account; deleting your account deletes the DOB.
Your rights
You can use the in-app controls at any time to:
- Export a structured JSON snapshot of your account data from Settings → Privacy.
- Delete any individual chat thread, tarot reading, or memory from its corresponding product screen.
- A saved grimoire entry is permanent. Once you write and save it, it cannot be edited or deleted from the app. That is deliberate: the record is worth having because it is what you actually wrote on the day you wrote it. To remove it, delete your account, which erases it along with everything else.
- Request account deletion from Settings → Privacy. This action is irreversible.
For a complete access or erasure request beyond the in-app snapshot and deletion controls, or other regulatory requests including rights under the GDPR, CCPA, or Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), email elderhermit@gnosix.io and we'll respond within 30 days.
If you are in Mexico, this contact channel is also how you may exercise your rights of access, rectification, cancellation, and opposition (ARCO), or revoke consent where the law permits.
International processing
Elderhermit is operated from Mexico, while several service providers listed above process or host data in other countries, including the United States. This means your data may be processed outside your country of residence. We use those providers only for the purposes described in this policy and under their applicable data-processing, confidentiality, and security terms.
If you are in the European Economic Area or the United Kingdom, international processing is subject to the transfer safeguards and data-processing terms made available by the relevant provider. Contact us if you need information about the safeguard used for a particular processing activity.
Changes to this policy
When we make a material change, we update the date at the top and provide additional notice when required by applicable law or by the nature of the change. Last updated: 2026.08.09.
// end_of_document