
What Iris actually is
I build AI agents at eesel, and the part of that job that keeps me up is never the model. It's what the agent remembers and who it remembers it for. That's the lens for this review, since Iris is a memory product wearing an iMessage thread.
Iris started life as iHermes. One of its makers, Dan Krieger, introduced it on X as a personal assistant "powered by Hermes Agent, with GBrain for memory", aimed at people who wanted Hermes without the setup:
"We're huge fans of Hermes. We've been using it to build internal systems and automate work, and we wanted more people to get that kind of value without having to set up the whole thing themselves."
The post has 834 likes. Today the brand is Iris, the domain is iris-agent.co, and some pages still route to an ihermes support inbox and booking link, a useful hint about where it came from.
There are really two products under one name:
| Iris personal assistant | Iris for companies | |
|---|---|---|
| Who it's for | Founders, creators, busy individuals | Operations, sales, customer success, recruiting, finance teams |
| How you start | Text a phone number from iMessage | Book a demo |
| Price | Free, then Plus ($15 or $19/month) | Not published |
| Where it runs | Iris's hosted cloud | Hosted, customer private cloud, or scoped on-premises |
| Controls named | Approval before any send, memory you can inspect | SSO, role-based access, private model endpoints, action approvals, audit records |
The engine underneath is Hermes Agent, the MIT-licensed agent from Nous Research that shows up in most roundups of open-source AI agents next to OpenClaw. Hermes is powerful and famously fiddly to run. Iris's whole pitch is that it does the running for you.
How Iris works day to day
You text a number. That's the onboarding. Iris answers in the same thread, and when a job needs live data it sends a secure connection link for the one source it needs, then picks the job back up after you approve. The founder page puts it plainly: it "asks for the smallest useful connection."
What it can reach, according to its privacy policy:
- Gmail, read-only. Like most AI apps for Gmail, it reads mail to summarize and flag what needs you. The policy says it does "not send, delete, or modify mail via first-party Google."
- Google Calendar, read and write. It reads events and creates or updates the ones you ask for, including reminder holds.
- Linear and Slack, optional.
- Its own mailbox. Each user gets a unique agent address on
mail.iris-agent.co, so you can forward things to Iris without connecting your real inbox. - Reminders. It stores the text and the fire time, then texts you (and optionally emails you) when it's due.
The work it pitches is the stuff that normally lives in your head: turning a voice note into tasks with owners and due dates, a "watch" that waits for a condition in a thread and drafts the next step without sending it, meeting briefs, research that separates "supplied facts, connected context, public research, assumptions, and missing evidence." That last line is a good instinct. An assistant that labels what it guessed is easier to trust than one that blends it all together.
One early user summed up the appeal in a reply to the launch post:
"Surprisingly little setup for this. I especially like that there's no new app or dashboard to keep open."
That's the appeal in one line. If you've compared Martin, Orchid or Instinct, Iris sits in the same text-your-assistant category, and its edge is the Hermes skills system underneath rather than a slicker interface.
The September memory incident
This is the section I'd read first if I were deciding whether to connect my inbox. Iris published a public incident report on September 19, and it's more detailed than most I've seen from companies ten times its size.
What happened. During the early beta, the hosted Hermes agent wrote user details into Hermes's own memory files on a shared environment. Iris then moved to "phone-scoped tenancy", meaning each phone number became its own user with its own memory and connections. The migration missed one layer: the old shared Hermes memory was never fully deleted. Questions like "what do you know about me?" could still pull from it.
The scope, in Iris's own numbers:
5early-beta accounts whose messages matched details that later showed up for someone else2accounts that received those details7replies that first disclosed information the recipient hadn't supplied- The leaked details included names, job or employer references and "other personal context"

What it didn't touch, per the report. No evidence that Gmail contents, Calendar data or Google OAuth tokens crossed between users, and a Gmail or Calendar connection wasn't needed to reproduce the leak. The failure lived in the legacy agent-memory layer, not in Iris's per-phone database.
The part that worried me most. The first fix shipped on September 18 and tested clean on fresh accounts. The next day, a follow-up question on an already-affected thread still got the agent to confirm that other people's profiles were in memory. The report is blunt about why: follow-up questions weren't classified as identity questions, and the outbound safety check was looking for numbered lists while the leak came out as ordinary paragraphs. It also admits it hasn't determined whether that reply reread surviving memory or repeated what was already in the thread, and adds a line every agent builder should tape to their monitor: "The assistant saying it verified durable memory is not evidence that it queried storage."
I've watched our own agents say confident things that weren't true, which is exactly why every eesel rollout gets replayed over historical tickets before it touches a live customer. The Iris story is the consumer version of the same lesson: the first test that passes is rarely the test that matters. If you want the support-side version of this problem, I wrote up how AI hallucinations in support happen and how to catch them.
To Iris's credit, the report lists what's still missing rather than declaring victory: no self-serve conversation export, no one-click account deletion, and no independent third-party audit yet. It says it's engaging external security testing teams and treats any new cross-phone leak as a P0.
What Iris changed from stock Hermes
The fix is the most useful thing to understand about how Iris differs from running Hermes yourself, because it changed which parts of Hermes are switched on.

Per the incident report, consumer Hermes profiles on Iris are now provisioned without Hermes-native memory, session search or cron. Each turn must run under a profile tied to the authenticated phone (user_{User.id}), and a missing, shared or default profile is rejected rather than used as a fallback. Questions about you are answered from Iris's own per-phone store; questions about other people's names or profiles are refused.
That's the right call for a multi-user product. Stock Hermes was designed for one operator. Its memory sits in two small files per profile (MEMORY.md and USER.md), and every chat on that profile loads the same files, which I covered in detail in the Hermes for customer support breakdown. Put many strangers on one profile and you get exactly the September incident.
One oddity: Iris's own blog post on owning your intelligence still lists "persistent bounded memory", "searchable session history" and "scheduled work" as part of the system. Memory and reminders do still exist in Iris, they just live in Iris's application layer now rather than in Hermes's native tools. Worth knowing if you came to Iris specifically for the Hermes learning loop.
Iris pricing
Iris's pricing is simple, with one inconsistency.
| Plan | Price | What's included |
|---|---|---|
| Free | $0, no credit card | Iris through iMessage, all supported connections, starter professional skills, persistent memory, saved personal skills |
| Plus | $15/month on five pages, $19/month on one | Everything in Free, higher AI usage limits, longer and more complex tasks, proactive and scheduled skills, larger files and research jobs, priority processing |
| Teams | Contact sales | A personal Iris per member, shared company skills, shared approved context, team integrations and permissions, centralized billing, custom onboarding |
| Iris for companies | Demo only | Custom department agents, optional private cloud or on-premises, SSO, role-based access, audit records |
The $15 figure appears on five pages aimed at founders, creators and fundraising, including the iMessage page. The personal assistant page says $19. I'd budget for $19 and be pleasantly surprised.
The bigger gap is that "higher AI usage limits" has no number attached on any page, so you can't tell how much Free gets you before you hit the wall. Every plan says you can "pause or cancel anytime."
For context, $15 to $19 a month is cheaper than Martin's Basic plan and in the same range as most tools in my AI scheduling assistants roundup. The terms also cap Iris's liability at the greater of $100 or what you paid in the last 12 months, which is standard for a consumer app but worth remembering when you decide what to connect.
Privacy and control
These are the things I'd check before connecting a real account.

The good:
- Iris gives you "a clear preview before anything consequential happens", per the founder page. A connected Gmail account doesn't by itself let Iris send email.
- You can "inspect, correct, or remove" what Iris remembers.
- OAuth secrets are encrypted at rest, and Google data isn't used to train general models, per the privacy policy.
- Model choice is flexible. Iris calls itself model-agnostic, and company deployments can route to private model endpoints.
The things to know:
- Ad measurement. When you first message Iris, it "may send Meta a one-way hashed phone identifier" to measure whether an ad led you there. Message contents and Google data aren't included.
- Deletion is by email. You write to support from the phone number or Google email on the account. The privacy policy and terms list
support@ihermes.co; the incident report listssupport@iris-agent.co. Use both if it matters. - The privacy policy predates the incident. It was last updated September 1, 2026, so it doesn't reflect the new per-phone memory rules. The incident report is the more current document.
Compared with self-hosted Hermes, where your data never leaves your machine, Iris is a trade: less setup, more trust in a three-week-old product. That's not unusual for this category, and it's the same question I'd ask about AI agent data privacy in any helpdesk. It's the same trade you make with Claude Cowork or Meta's Muse agent, just with a younger vendor and a fresher incident.
Iris vs running Hermes yourself
Dan Krieger was upfront about this trade too, writing on X that "running Hermes yourself is still an option for people who want that level of control." Here's the side-by-side.

| Iris | Self-hosted Hermes | |
|---|---|---|
| Setup | Send one text | Install Hermes, configure a gateway, pick a model provider |
| iMessage | Built in | Needs an always-on Mac running BlueBubbles signed into your Apple ID |
| Who's allowed in | Every phone is its own tenant | You approve each person with a pairing code, or open it to everyone |
| Native memory and skills loop | Off on the consumer path; memory lives in Iris's own store | Full Hermes memory, session search, cron and self-written skills |
| Models | Model-agnostic; no model picker documented | Any provider, including Nous Portal plans from $20/month |
| Software cost | $0 to $19/month | $0 license, plus models and a server |
| Where your data lives | Iris's cloud | Your machine |
If you're the kind of person who already runs a home server, self-hosted Hermes gives you more and costs little beyond model usage. The Hermes Agent alternatives post and my Instinct vs Hermes comparison cover the other ways people get the same result. If you want the result without touching a terminal, Iris is the shortest path I've found to Hermes in your pocket.
Who should use Iris, and who should wait
Use it if you're a founder or operator drowning in small follow-ups, you live in iMessage, and the work you'd hand over is reminders, research, meeting prep and draft replies. Start on Free, connect only the agent mailbox and Calendar, and see if it earns Gmail access.
Wait if you'd be connecting an inbox full of investor, legal or customer data. The product isn't careless, and the incident report shows the opposite. The reason to wait is that the fix is three weeks old and the audit isn't out. I'd revisit once Iris publishes that external review and ships self-serve deletion.
Look elsewhere if you're on Android (it's iMessage-first), or if you want a broad agent you build yourself, like Lindy, or one that works across the web like the ones in my ChatGPT agents or Manus write-ups.
For a wider menu, my AI personal assistants test covers 10+ tools.
Where Iris stops for support teams
I read 26 of Iris's public pages for this review. None of them mention a helpdesk, a support ticket or an integration with Zendesk, Freshdesk or Gorgias. The connections are Gmail, Calendar, Linear and Slack, and the company-side agents are pitched at operations, sales, customer success, recruiting and finance. That's a reasonable focus, it just means Iris isn't the tool for a support queue.
The question support buyers ask me on almost every call is the same one the incident answers the hard way. One technical evaluator at a hardware company asked whether the AI would only answer from their approved knowledge, and whether that knowledge stayed closed to their organization. A B2B team gated by an internal security review asked whether ticket data with personal details stays in their environment. Those aren't paranoid questions. They're the right ones, and they're why memory isolation is a design decision you make on day one, not a migration you finish later.

eesel's AI helpdesk teammate is built for that job, and it's one of the AI teammates you hire for a defined role rather than a general errand-runner. It plugs into Zendesk, Freshdesk, Gorgias and other helpdesks, learns from your help center and past replies, and keeps each company's knowledge in its own workspace. It's in my roundup of the best AI helpdesk software for that reason.
Before go-live, you can simulate it over hundreds of your past tickets and see exactly what it would have said, so the first surprise happens in a test, not in a customer's inbox. If you'd rather drive it from a terminal, like most AI agent CLIs, the eesel CLI lets you or a coding agent check status, edit instructions, approve actions and read every run from the command line.
Try eesel
Iris is a good bet for clearing your personal to-do list by text. If what's actually piling up is customer tickets, eesel is the teammate for that: it joins your helpdesk in minutes, answers from your docs and past tickets, and hands anything it isn't sure about to a human with a clean handoff. Plans start free with 100 credits, then fixed monthly batches from $299 for 500 tickets or chats on the pricing page. Try eesel and run it on last month's tickets before you decide.
Frequently Asked Questions
What is the Iris Hermes Agent?
How much does Iris cost?
Is Iris Hermes Agent safe to use?
Iris Hermes Agent vs self-hosted Hermes: which should I pick?
Does Iris send emails on its own?
Can Iris handle customer support tickets?
How do I delete my Iris data?

Article by
Kira
Kira is a writer at eesel AI with a Computer Science background and over a year of hands-on experience evaluating AI-powered customer service tools. She focuses on breaking down how helpdesk platforms and AI agents actually work so that support teams can make better buying decisions.








