Privacy Policy
Effective and last updated: 27 August 2026
1. Scope
This policy describes the handling of Google user data by Hermes, a private, owner-operated local automation integration. Hermes is not offered to the public as a product or service and is intended solely for use by its owner.
2. Google data accessed
Depending on the workflow explicitly authorized by the owner, Hermes may access:
- Gmail messages, message metadata, threads, and labels, and may send email or modify message state;
- Google Calendar calendars and events;
- Google Drive files, folders, and file metadata;
- Google Docs documents and Google Sheets spreadsheets;
- Google Contacts on a read-only basis.
Hermes requests only the permissions configured for a particular local profile. Some profiles use a smaller subset of these permissions.
3. How Google data is used
Google user data is used only to perform workflows requested or scheduled by the owner, such as organizing information, monitoring selected inbox and business processes, maintaining files and spreadsheets, and generating private reports. Google user data is not used for advertising, user profiling, or sale.
4. Storage and processing
OAuth credentials and primary workflow data stores are kept on locally managed systems controlled by the owner. Workflow output may be written back to the owner's authorized Google account. When the owner configures a workflow to use an external AI or API provider, only the information needed for that workflow may be sent to that configured provider for processing. No unrelated third party is granted independent access to the Google account.
5. Sharing and disclosure
Google user data is not sold, rented, or shared for advertising. Data may be processed by infrastructure or API providers selected by the owner solely to operate a requested workflow, or disclosed where legally required. This public website is delivered through Cloudflare; Cloudflare serves these informational pages but does not receive Hermes OAuth tokens or Google account content through this website.
6. Retention and deletion
Local workflow data is retained only for as long as needed by the owner for the applicable automation, record, report, or backup. The owner can delete local data and generated output at any time. OAuth access may be revoked through the Google Account permissions page, after which Hermes can no longer obtain new Google access tokens.
7. Security
Credentials and workflow data are maintained on owner-controlled systems with local access controls. No OAuth credentials, authorization codes, Google content, or local databases are exposed through this website.
8. Google API Services User Data Policy
Hermes's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Your controls
The account owner can review or revoke access at Google Account connections, pause or remove local scheduled workflows, and delete locally stored data and generated output.
10. Contact
Privacy questions may be sent to olmns@icloud.com.