privacy policy
Hermes privacy policy
Effective October 5, 2026
This policy explains how Andreas Granqvist's private Hermes installation handles Google user data. It is a personal integration for the owner's use only, not a public service.
Scope
This policy applies only to the owner's configured Hermes integration with Google services. It does not govern the underlying Hermes agent software, Nous Research, Google, OpenAI, other service providers, or the rest of this informational website. The public website does not provide access to the assistant and does not receive Google OAuth tokens or Google account data through these pages.
Google data accessed
Depending on the task requested and permissions granted by the owner, the integration may access:
- Gmail: email content, message and thread metadata, and attachments.
- Google Calendar: event details, attendees, dates, times, locations, descriptions, and related metadata.
- Google Drive: file contents, file names, folder information, and other file metadata.
Access is limited to the Google OAuth permissions granted by the owner and the information needed to carry out requested tasks. Depending on those permissions and requests, Hermes may search, read, summarize, create, send, update, or delete relevant emails, files, and calendar events.
How data is used and processed
Google user data is used to answer the owner's requests and perform owner-directed tasks. Relevant content may be transmitted to configured external AI providers, including OpenAI, when needed to process a requested task. Those providers handle data under their applicable service terms, account terms, and settings.
This integration does not use Google user data to train generalized AI models. Google user data is not sold, used for advertising, or shared with data brokers.
Storage and retention
Google OAuth tokens are stored on the owner's controlled system, not on this public website. Local conversations, logs, memory, and backups may retain Google-derived content until the owner deletes it. There is no promised fixed retention period or automatic deletion schedule.
The owner can delete stored records and backups according to the system's available capabilities. Questions or deletion requests can be sent to andreasgranqvist@gmail.com.
Revoking access
The owner can revoke the integration's Google access at any time from Google Account connections and can remove the local OAuth credentials from the owner's system.
Revocation stops future access through those credentials. It does not automatically delete information previously retained in local records or backups, or information already processed or retained by an external provider. Those records must be deleted separately where the applicable system and provider capabilities allow.
Security
Reasonable technical and organizational safeguards are used to protect credentials and stored data, including limiting access to the owner-controlled environment. No system or transmission method can guarantee absolute security.
Google API Services User Data Policy
This integration's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including its Limited Use requirements.
Contact
This private integration is operated by Andreas Granqvist. For privacy questions, contact andreasgranqvist@gmail.com.