Herkos

Herkos privacy policy

Last updated: 12 September 2026. Canonical URL: https://herkos.app/privacy

Herkos is a free, open-source mail client for the Nostr network, published by the Herkos project ("we"). This document explains what data the app handles, where it goes, and who can see it. We wrote it to be read, not skimmed: if something here surprises you, tell us at privacy@herkos.email.

The short version

Data that stays on your device

You can erase all of it from Settings → More → Reset application, or by removing an account.

Data that leaves your device, and to whom

Recipient What they can see When
Nostr relays (default list in Settings → Network, editable) Your IP address, your public key, the events you publish (profile, relay lists, Blossom server list, NIP-32 labels, encrypted settings) and the encrypted "gift wraps" addressed to you, plus their timing. Relays cannot read the content of gift wraps. Always, while the app syncs.
Blossom servers (editable) Your IP address and public key, and the encrypted blobs of emails larger than 32 KB and their attachments. The key to decrypt a blob travels only inside the encrypted message. When you send or open a large email.
Bridges (nostrmail.org and uid.ovh by default, editable) The full content of any email you send to, or receive from, a traditional email address (Gmail, Outlook…), and the alias name@bridge you register. Bridges are independent operators with their own privacy terms; Herkos does not run them. When you use a @bridge identity or write to a non-Nostr address.
NIP-05 servers (the domain of an address you type) That someone asked whether name@domain is a Nostr user. When you add a user@domain recipient.
Push server (api.nmail.li, operated by the upstream Nostr Mail project; configurable at build time) Your public key, a device push token (FCM or UnifiedPush endpoint), your notification language, and — because it watches relays on your behalf — when you receive mail (not what it says). Only if you turn on notifications for an account. Turning them off asks the server to delete the subscription.
Scheduler DVM (a Nostr service run by a third party, see NostrConfig.schedulerDvm) Your public key, the already-encrypted messages to publish, their destination relays and the scheduled time. Only if you use "send later".
Remote signer / relays for NIP-46 (relay.nsec.app and fallbacks) Your public key and encrypted signing requests. Only if you log in with a bunker or signer app.
Google (Firebase Cloud Messaging) A push token and delivery metadata. Only in the Google-services build (nmail_standard), and only with notifications on. The FOSS build uses UnifiedPush instead and never contacts Google.

Herkos itself receives none of this. There is no crash reporting or telemetry.

Public by design

Nostr is a public network. These things are visible to anyone who queries the relays you use, and are linked to your public key:

Your choices and rights

Changes

We will change this document when the app's behaviour changes, and record the date at the top. The source of truth is PRIVACY.md in the repository; the published page is a copy of it.

Contact: privacy@herkos.email · https://herkos.app