Privacy Policy

Hermes · Last updated 25 August 2026

Hermes is a private, self-hosted automation assistant operated by a single individual for their own personal and work use. It has no other users and is not offered as a service. This policy explains how it handles data obtained through Google APIs.

Whose data is processed

Only the operator's own Google account data. Hermes has one authorised account — the operator's. It provides no way for any other person to connect an account, and it does not collect data from visitors to this website.

What data is accessed

With the operator's explicit consent, Hermes may access:

Incidentally, this includes information about people who appear in the operator's mail, calendar events and contacts — for example a meeting attendee's name and email address. That information is used only to carry out the operator's own tasks, and is treated with the same care as the rest of the account data described here.

Why it is accessed

Solely to perform tasks the operator has asked for: preparing meeting briefs, tracking commitments, drafting and sorting mail, maintaining personal notes and documents, and producing scheduled reminders and summaries. The data is not used for advertising, profiling, marketing, or training any general-purpose model.

Storage and retention

Data is held on a private server controlled by the operator, and in the operator's own private notes. Access credentials are stored on that server and are not shared. Data is kept only while useful for the tasks above and can be deleted by the operator at any time.

Sharing and disclosure

Google user data is never sold, rented, or shared for anyone else's purposes. There are no analytics, advertising, or tracking services.

To generate summaries and drafts, content may be sent to third-party AI model providers strictly as needed to produce a result for the operator. Those providers act as processors for that request; the content is not used by Hermes for any other purpose.

Limited Use disclosure

Hermes's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Withdrawing access

The operator can revoke Hermes's access at any time at myaccount.google.com/permissions. Revoking access immediately stops all further data collection.

Security

The server is private and access-controlled, and credentials are restricted to the operator. As with any self-hosted system, no absolute guarantee of security can be given.

Changes

Any change to this policy will be published on this page with an updated date.

Contact

Questions about this policy: brancook02@gmail.com