Herculon— All Hands

Legal · Privacy Policy

Privacy Policy

Effective July 25, 2026 · Last updated July 26, 2026

This Privacy Policy explains how Joshua Vigil, a sole proprietor doing business as "Herculon" ("Herculon", "we", "us") collects, uses, and shares information when you use the Herculon desktop application and any related services at https://herculon.io (collectively, the "Service").

By using the Service you agree to this Policy. If you don't agree, don't use the Service.

1. Who we are

Herculon is a desktop application for orchestrating AI agents that call third-party business tools. We are the data controller for the personal data described in Sections 2.2, 2.3, and 2.4 below.

2. What we collect

2.1 Stored locally on your device (we never see it)

The following is stored on your machine only and is not transmitted to us:

We do not log or transmit the contents of your API keys, agent conversations, or third-party integration data to our servers under any circumstance.

2.2 Collected and stored by us

2.3 Processed transiently through the licence and voice proxy

If you subscribe to the Voice tier, the following flows through our Cloudflare Worker proxy:

2.4 Sent to third parties directly from your device

3. Legal bases for processing (EEA/UK users)

Where the GDPR or UK GDPR applies, we process personal data on the following legal bases:

Processing activity Legal basis
Verifying your licence and metering voice usage Performance of a contract (Art. 6(1)(b))
Relaying voice audio to Groq and ElevenLabs Performance of a contract (Art. 6(1)(b))
Processing payments via Gumroad Performance of a contract (Art. 6(1)(b))
Responding to support requests Performance of a contract / legitimate interests (Art. 6(1)(b), (f))
Retaining licence and billing records after cancellation Legal obligation and legitimate interests in accounting and dispute resolution (Art. 6(1)(c), (f))
Securing the Service and preventing abuse or quota fraud Legitimate interests (Art. 6(1)(f))
Sending you our newsletter or marketing updates Consent (Art. 6(1)(a)), withdrawable at any time

We do not process special-category data, and we do not make automated decisions producing legal or similarly significant effects about you.

4. Subprocessors

We rely on the following third-party services to operate the Service:

Subprocessor Purpose What they see
Cloudflare Hosts our Worker proxy and KV store Licence key, email, quota counters, voice audio in transit, IP metadata
Groq Speech-to-text transcription Voice audio (in transit)
ElevenLabs Text-to-speech synthesis Text prompts for voice generation
Gumroad Subscription billing, voice top-up payments, and licence issuance Name, email, payment info you provide at checkout
Beehiiv Sending our newsletter and managing marketing contacts (only if you opt in) Email address, phone number (if provided), and consent record

Each subprocessor has its own privacy policy, and we cannot control how they retain or process data once it reaches them. Their handling of any data that passes through their systems is governed by their own policies, which we recommend reviewing:

5. How we use information

We use the information described above solely to:

We do not sell your data, share it for third-party advertising, or train machine-learning models on it. When we send you our own newsletter, that is first-party marketing to people who asked for it, and you can opt out at any time.

5A. Marketing communications

We send our newsletter and marketing updates from dispatch@herculon.io using Beehiiv, which stores your contact details and consent record on our behalf and provides the unsubscribe mechanism in each email. If you opt in to our newsletter or marketing updates, the following applies:

6. Retention

7. Your rights

Depending on where you live, you may have rights under GDPR, UK GDPR, or other privacy laws, including:

To exercise any right, email support@herculon.io from the email address associated with your licence. We may ask you to verify your identity (for example, by confirming details of your subscription) before acting on a request, to protect your data from unauthorized access. We'll respond within 30 days (or sooner where the law requires).

EEA/UK users: you also have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en; the UK authority is the Information Commissioner's Office (https://ico.org.uk).

California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. You may exercise the rights above regardless of whether the CCPA formally applies to us.

8. Cookies and tracking

The desktop app itself uses no cookies and contains no analytics or telemetry. Our marketing website (https://herculon.io) sets no cookies of its own and uses no third-party analytics as of the Last-updated date above. If you interact with a newsletter signup form or subscribe page powered by Beehiiv, Beehiiv may set its own cookies as described in its privacy policy; that occurs only when you engage with the signup. If our own cookie or analytics use changes, we will update this section (and, where required, present a consent banner) before deploying them.

Do Not Track: because we do not track visitors across websites, we do not respond to Do Not Track browser signals; there is nothing to disable.

9. Children

The Service is not directed to anyone under 18, and our Terms of Service require users to be at least 18. We don't knowingly collect personal information from anyone under 18. If you believe we've done so, contact us and we'll delete it.

10. International transfers

We are based in the United States, and the personal data described in this Policy is processed in the United States by us and our subprocessors. If you use the Service from the EEA, UK, or Switzerland, you are transferring your data to the United States.

Where a subprocessor is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), we rely on that certification for the transfer; otherwise we rely on Standard Contractual Clauses or another lawful transfer mechanism in our agreements with them. You can request more information about the mechanism applicable to a given subprocessor by emailing us.

11. Security and breach notification

We use industry-standard measures including encrypted transport (HTTPS/TLS) for all network traffic, and your API keys are stored in your OS's native secure credential store on your own device. No system is perfectly secure; we can't guarantee absolute security.

If a breach of security affecting your personal data occurs, we will notify you and the relevant authorities as required by applicable law, including Florida's Information Protection Act (Fla. Stat. §501.171) and, where applicable, the GDPR's 72-hour notification requirement.

12. Changes to this policy

If we make material changes to this Policy, we will notify you by email (from dispatch@herculon.io) or through the app at least 14 days before the changes take effect, and update the "Last updated" date above. Non-material changes (clarifications, formatting, contact details) may take effect immediately upon posting. If you don't agree with a material change, you may cancel your subscription before it takes effect.

13. Contact

Questions or requests about this policy:

Email: support@herculon.io Address: 2811 SW Archer Rd, Gainesville, FL 32608, United States