Hermes Assistant / Privacy

Privacy Policy

How Google data is accessed and handled for the owner's requested tasks.

Last updated

Overview

Hermes Assistant is a private personal AI assistant used by a single owner. It is not offered as a public consumer service. This policy explains how the assistant accesses, uses, stores, and handles Google user data when the owner connects Gmail, Google Calendar, or Google Drive through Google OAuth.

This informational website does not connect to Google accounts or collect Google user data. It uses no cookies, analytics, external trackers, or third-party scripts. The hosting provider may process basic request information, such as IP addresses and browser details, to deliver and secure the website.

Data accessed

The assistant accesses data only to perform tasks explicitly requested by the owner and only within the Google permissions the owner grants. The data involved depends on the requested task and may include emails, calendar events, files, attachments, and associated metadata.

A Google permission defines what the assistant is allowed to access; it does not mean all available data is routinely collected.

Gmail data

For email tasks, the assistant may process message content, subject lines, sender and recipient addresses, timestamps, labels, threads, and attachments. It may use this information to find or summarize messages, prepare replies, or organize email.

Sending, modifying, or deleting messages is performed only when requested by the owner and permitted by the granted OAuth scopes.

Google Calendar data

For scheduling tasks, the assistant may process calendar names, event titles, descriptions, dates and times, locations, attendee details, availability, and related event metadata. This data is used to review schedules or create, update, and manage events as requested and permitted.

Google Drive data

For file tasks, the assistant may process file names, contents, identifiers, types, folder locations, timestamps, sharing information, and other relevant metadata. It may find, read, summarize, create, update, or organize files as needed for the owner's instructions and within the permissions granted.

How the data is used

Google user data is used only to carry out the owner's explicit requests, including productivity, research, automation, email, scheduling, and file-management tasks. Processing is limited to the information needed for those tasks.

Google user data is not sold or used for advertising. It is not used to train or improve generalized, foundational, or shared AI models.

Hermes Assistant's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Data storage

Task data may be processed temporarily in memory or stored on owner-controlled infrastructure when needed to complete a task or preserve an output requested by the owner. Depending on the configuration, retained data may include selected emails, event details, file content, summaries, or task history.

The assistant does not intentionally maintain a separate archive of all Google account data. Saved results in Gmail, Google Calendar, or Google Drive remain in those services until the owner changes or deletes them. Any external processing must follow the restrictions in the Data sharing section below.

OAuth credentials and tokens

Google OAuth is used to authorize access without giving the assistant the owner's Google password. OAuth access and refresh tokens may be stored securely on owner-controlled infrastructure so the assistant can perform authorized tasks.

Tokens and other credentials are treated as secrets, with access restricted to the owner and the processes needed to operate the assistant. They are not included in this public website or its source files. Credentials are removed or replaced when no longer needed or if compromise is suspected.

Data sharing

Google user data is not sold, shared with advertisers, or transferred to unrelated third parties.

Some requested actions involve sharing with recipients selected by the owner, such as sending an email, inviting someone to an event, or sharing a file. These actions are carried out only at the owner's direction.

Any external processing service, including an AI service, used for an owner-requested task must be authorized by the owner, receive only the data needed for that task, and handle it consistently with this policy and Google's Limited Use requirements. Such processing does not permit independent advertising use or training of generalized AI models.

Data retention

Data is retained only as needed for the requested task and any output or history the owner chooses to keep. Temporary working data is removed when no longer needed. Saved outputs and task history may remain until the owner deletes them.

Retention depends on the assistant's storage configuration and the task. If backups exist, retained copies follow the owner-controlled backup lifecycle; deleting an active copy may not immediately remove a backup. No fixed automatic deletion period is promised by this policy.

User control and revocation of access

The owner controls which Google account is connected and which permissions are granted. Access can be revoked at any time through Google Account connections and permissions by selecting Hermes Assistant and removing its access.

Revocation stops future authorized access through those credentials. It does not automatically delete data already retained by the assistant or outputs saved in Google services. The owner can separately delete retained task data and stored tokens from the infrastructure they control, and remove saved outputs from the relevant Google service.

Questions or requests about retained data can also be sent to herm.ai.assistant@gmail.com.

Security

Reasonable safeguards are used to limit unauthorized access, including restricted access to owner-controlled infrastructure, secure handling of OAuth credentials, and encrypted connections to Google APIs. The appropriate safeguards depend on the system's configuration.

No method of storage or transmission can guarantee complete security. If unauthorized access is suspected, the owner can revoke Google permissions and replace affected credentials.

Changes to this policy

This policy may be updated if the assistant's functionality or data practices change. The latest version will be published on this page with a revised update date. Before accessing additional data or using Google data for a new purpose, the owner must authorize that change.

Contact

For questions about Hermes Assistant or this policy, contact the owner at herm.ai.assistant@gmail.com.