Privacy Policy

Hermes Agent — last updated 11 October 2026

This policy describes how Hermes Agent ("the application") accesses, uses, stores, and shares Google user data. The application is a personal tool operated by, and for, a single individual: the owner of the Google account that authorizes it.

1. What data the application accesses

With the account owner's explicit consent, the application accesses only data belonging to that owner's own Google account:

No other Google data is requested or accessed.

2. How the data is used

Data is used solely to carry out the tasks the owner asks of the application on their own account — for example finding a message, drafting a reply, listing today's events, or reading a document. The application performs no advertising, profiling, analytics, or marketing use of Google user data, and it does not attempt to determine sensitive personal characteristics.

3. How the data is stored

The application runs entirely on the owner's own computer. Retrieved data is held only in that machine's local memory or local storage for as long as needed to complete the owner's request. The credentials used to connect to Google are stored on the same machine, in a file readable only by the owner's operating-system user, and are encrypted in transit.

No copy of Google user data is uploaded to any external server, cloud service, or third-party database controlled by anyone other than the owner.

4. How the data is shared

It is not. Google user data is not sold, rented, traded, published, or disclosed to any third party. The application has no other users and no third-party integrations. Data leaves the owner's machine only when the owner explicitly sends it somewhere themselves — for example when they send an email.

5. Transfers

Data is not transferred to anyone. The only network transfers are those required to communicate directly with Google's own APIs over HTTPS on the owner's behalf.

6. Retention and deletion

7. Security

All communication with Google uses HTTPS. OAuth 2.0 is used for authorization, and the application never receives or stores the owner's Google password. Access tokens and refresh tokens are stored only on the owner's machine, with file permissions restricted to the owner's user account.

8. Google API Services User Data Policy

The application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the user-facing features described above; it is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior user notice; it is not used for advertising; and it is not read by humans except where the owner themselves requests it, where necessary for security purposes such as investigating abuse, or to comply with applicable law.

9. Changes to this policy

Any change in how Google user data is accessed, used, stored, or shared will be reflected in this document before that change takes effect.

10. Contact

Questions about this policy or about Google data handling: npquang.uns@gmail.com