Privacy Policy
1. Who operates this application
Hermes Agent GWS is a single-user, self-hosted deployment of a personal assistant. It is operated by its owner, for the owner's own Google account only. It is not offered as a service to anyone else. Contact: [email protected].
2. What Google user data is accessed
When the owner authorises the application, it requests access to:
- Gmail — reading, organising, drafting and sending messages.
- Google Calendar — reading events and creating or modifying events.
- Google Drive, Docs, Sheets and Slides — reading and editing the files the owner asks the assistant to work with.
- Google Tasks — reading and managing the owner's task lists.
- Basic profile (e-mail address, name) — only to identify the signed-in account.
- Cloud Pub/Sub and Google Cloud Platform — technical access to the owner's own Google Cloud project that hosts this application (for example, change notifications). These scopes do not touch user content.
The exact OAuth scopes are listed on Google's consent screen at the moment access is granted, and can be reviewed at any time at myaccount.google.com/permissions.
3. How the data is used
Data is used solely to carry out tasks the owner explicitly asks the assistant to perform: summarising and triaging mail, drafting or sending replies, managing calendar entries, and working with the documents, spreadsheets, presentations and tasks the owner points it to. There is no profiling, no analytics on message content, and no use unrelated to the owner's request.
4. How the data is stored
OAuth tokens are stored encrypted at rest on the owner's private server. Message, calendar and document content is processed in memory for the duration of a task and is not retained afterwards, except where the owner explicitly asks the assistant to save something (for example, a note or a summary the owner requested).
5. Sharing
Google user data is not sold, not shared with third parties, not used for advertising, and not used to train machine-learning models. To fulfil the owner's own request, relevant content may be transmitted to the language-model provider the owner has configured; that transmission is strictly limited to what the request requires.
6. Limited Use disclosure
Hermes Agent GWS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Revoking access
Access can be revoked at any time at myaccount.google.com/permissions. Once revoked, stored tokens become invalid immediately and the application can no longer access the account.
8. Deletion requests
To request deletion of stored tokens and any retained data, email [email protected]. Requests are honoured within 30 days.
9. Changes to this policy
This page is the canonical version of the policy. The "Last updated" date above changes whenever the policy does.