Hermes Agent — last updated 11 October 2026
This policy describes how Hermes Agent ("the application") accesses, uses, stores, and shares Google user data. The application is a personal tool operated by, and for, a single individual: the owner of the Google account that authorizes it.
With the account owner's explicit consent, the application accesses only data belonging to that owner's own Google account:
gmail.readonly, gmail.modify, gmail.send) —
message headers, bodies, attachments, labels and mailbox state, in order to read, search,
organize, reply to and send the owner's own email.calendar) — the owner's own calendars and events,
in order to view and manage their own schedule.drive) — the owner's own files and folders, in order to
find, read, upload and organize their own files.contacts.readonly) — the owner's own contact list,
in order to resolve names and addresses.spreadsheets) and Google Docs
(documents) — the owner's own spreadsheets and documents, in order to read and
update them.No other Google data is requested or accessed.
Data is used solely to carry out the tasks the owner asks of the application on their own account — for example finding a message, drafting a reply, listing today's events, or reading a document. The application performs no advertising, profiling, analytics, or marketing use of Google user data, and it does not attempt to determine sensitive personal characteristics.
The application runs entirely on the owner's own computer. Retrieved data is held only in that machine's local memory or local storage for as long as needed to complete the owner's request. The credentials used to connect to Google are stored on the same machine, in a file readable only by the owner's operating-system user, and are encrypted in transit.
No copy of Google user data is uploaded to any external server, cloud service, or third-party database controlled by anyone other than the owner.
It is not. Google user data is not sold, rented, traded, published, or disclosed to any third party. The application has no other users and no third-party integrations. Data leaves the owner's machine only when the owner explicitly sends it somewhere themselves — for example when they send an email.
Data is not transferred to anyone. The only network transfers are those required to communicate directly with Google's own APIs over HTTPS on the owner's behalf.
All communication with Google uses HTTPS. OAuth 2.0 is used for authorization, and the application never receives or stores the owner's Google password. Access tokens and refresh tokens are stored only on the owner's machine, with file permissions restricted to the owner's user account.
The application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the user-facing features described above; it is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior user notice; it is not used for advertising; and it is not read by humans except where the owner themselves requests it, where necessary for security purposes such as investigating abuse, or to comply with applicable law.
Any change in how Google user data is accessed, used, stored, or shared will be reflected in this document before that change takes effect.
Questions about this policy or about Google data handling: npquang.uns@gmail.com