Privacy Policy

Hermes Google Workspace Connector  ·  Effective: September 28, 2026  ·  Last updated: September 28, 2026

1. Summary

This application — the Hermes Google Workspace Connector — is a private, self-hosted software integration with exactly one user: the individual who owns and operates the computer on which it runs, and who owns the Google Account that grants it access. It is not a commercial product, is not offered to the public, is not distributed or licensed to anyone else, and operates no servers of its own.

Because the application has a single user who is also its owner, the data it accesses is that user's own data, processed on that user's own equipment, for that user's own benefit. No personal data belonging to any other person is collected, and no data is sold, rented, or transferred to any third party for any commercial purpose.

2. Who this policy applies to

This policy applies to the single individual who installs, configures, authorizes, and operates this application. There are no other users, no accounts to create, no public sign-up, and no customers. If you are not the individual who personally authorized this application on your own device, this application holds no data about you and this policy does not apply to you.

3. What data the application accesses

When the owner grants authorization through Google's standard OAuth 2.0 consent screen, the application may access the following categories of data belonging to that owner's own Google Account. The table below describes each category, what is accessed, and why it is needed:

Google serviceData accessedWhy it is needed
Gmail Message contents, subject lines, senders and recipients, labels, attachment contents and filenames, message metadata To let the owner ask his assistant to search, read, summarize, label, and send email on his behalf
Google Calendar Calendar names, event titles, times, locations, descriptions, attendees, reminders To let the owner check his schedule, create events, and review upcoming commitments
Google Drive File and folder names, contents, MIME types, sizes, modification dates, sharing permissions, parent folders To let the owner find, read, upload, organize, and share his own files
Google Docs Document text content and document structure To let the owner read and draft documents, such as research notes or teaching material
Google Sheets Spreadsheet cell values and sheet structure To let the owner read and update his own tracking spreadsheets
Google Contacts Names, email addresses, phone numbers To let the owner look up contact details when sending email or scheduling events

The application accesses only these categories, and only within the owner's own Google Account. It has no mechanism to access any other person's Google Account, and it never attempts to.

4. How data is used

Accessed data is used for exactly one purpose: to carry out instructions the owner gives to his own local AI assistant. Typical uses include searching email for a specific message, summarizing a document, checking the day's calendar, drafting a reply, or filing a file into a folder.

Data is never used for advertising, marketing, profiling, behavioral targeting, creditworthiness assessment, resale, or any purpose unrelated to the owner's direct request. No analytics, telemetry, or usage tracking of any kind is performed on Google user data. No automated decision-making producing legal or similarly significant effects is performed on Google user data.

5. How data is stored

Google user data is processed and stored locally on the owner's own computer. There is no remote database, no cloud storage bucket, and no application server; the application operates no infrastructure of its own. Consequently, no copy of any Google user data is held by this application anywhere other than the owner's own device.

The only persistent credential the application stores is an OAuth 2.0 refresh token, saved to the local filesystem on that computer with owner-only file permissions. That token permits the application to request fresh access tokens from Google; it does not itself contain email contents, calendar entries, file contents, or contact details. Deleting the local token file immediately removes the stored credential.

6. How data is shared

Google user data is not sold, rented, traded, or shared with any third party for any commercial purpose whatsoever. There is no advertising network, no data broker, no analytics provider, and no marketing partner involved. The only circumstances in which data leaves the owner's computer are the following, each narrow and necessary for the application to function:

No other party receives Google user data, and no data is transferred to any party for any purpose beyond operating the application for the owner.

7. Data retention

This application does not maintain a persistent datastore of Google user data. Data is retrieved from Google's APIs when the owner makes a request, is used to fulfil that request, and is not retained in a dedicated store afterwards. The following retention rules apply:

There is no separate retention schedule beyond these, because there is no separate store of data to schedule the deletion of.

8. How to revoke access and delete data

The owner can end all access immediately and permanently at any time, without asking anyone and without any waiting period:

Because the application stores no Google user data on any remote system, there is no remote copy to request deletion of — revocation is complete and immediate.

9. Security

Access is granted exclusively through Google's official OAuth 2.0 authorization flow. The owner's Google password is never seen, requested, or stored by this application; only a revocable OAuth token is held. Credentials are stored locally with restrictive file permissions. Data in transit between the application and Google's APIs is encrypted using TLS. The application accepts no inbound network connections from the internet, exposes no listening ports or public services, and therefore presents no remote attack surface. It runs on a single personal computer under the owner's exclusive physical control.

10. Compliance with Google API Services User Data Policy

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

11. Cookies and tracking technologies

This website consists of static pages. It does not set cookies, does not run analytics or tracking scripts, does not display advertising, does not embed third-party trackers, and does not fingerprint visitors. No visitor data is collected by this site.

12. International data transfers

The application runs on the owner's own computer. Data is not transferred across borders by this application. When the owner's assistant communicates with Google's APIs or with the owner's chosen AI model provider, those services apply their own data-handling terms, which the owner has accepted directly with them.

13. Children's privacy

This application is not directed at children, is not available to the public, and is not intended for use by anyone under the age of 16. It has exactly one adult user, its owner. No data relating to children is knowingly collected or processed.

14. Changes to this policy

This policy may be updated to reflect changes in the application's functionality or in applicable law. When it is updated, the "Last updated" date at the top of this page will be revised. Continued operation of the application after a change constitutes acceptance of the revised policy. Substantive changes will not be applied retroactively to data already processed.

15. Contact

This is a private, single-user application operated by its owner. Questions about this policy, or requests relating to data processed by it, may be directed to the owner through the Google Account that administers the associated Google Cloud project.