Last updated: 1 September 2026
Hermes is a self-hosted personal automation agent operated by a single household for its own use. It has no customers, no public sign-up, and no users other than its operator. This policy explains how the application handles data, including Google user data, in accordance with the Google API Services User Data Policy.
With the operator's explicit OAuth consent, Hermes accesses the operator's own Google account data: Gmail messages (to read, label and organise them) and Google Calendar events (to read and create entries). Access is only ever to accounts owned by the operator, authorised individually by the operator.
Gmail and Calendar data is used solely to provide the application's functionality to the operator: categorising the operator's own email, flagging messages that need attention, and creating calendar entries for the operator's confirmed bookings. Data is processed by the application and, where needed for classification, by a third-party large language model API acting as a data processor. Data is never used for advertising, profiling, or model training.
OAuth tokens and application data are stored on private servers controlled by the operator. Tokens are stored in files readable only by the operator's account. Connections to Google APIs use TLS.
Google user data is not sold, rented, or shared with third parties, except for the model API processing described above, and is never transferred for advertising purposes.
Email remains in the operator's Gmail account; Hermes stores only labels applied through the Gmail API and minimal processing logs. The operator can revoke access at any time at myaccount.google.com/permissions, which immediately invalidates the application's tokens. Stored tokens and logs can be deleted by the operator directly on the operator's own servers.
Hermes' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Questions about this policy: chrisconway888@gmail.com