Privacy Policy — Hermes Google Access
Effective Date
August 29, 2026
Overview
Hermes Google Access is a private, owner-operated local integration that connects a locally running Hermes Agent to the owner's own Google Workspace data after explicit Google OAuth consent. This website is a purely informational page describing that integration. It is operated by Gil Javelosa, who can be reached at giljavelosa@gmail.com.
About This Website
This informational website receives no Google user data. It sets no cookies and uses no analytics, trackers, or similar technologies of any kind. It serves static content only.
Google Data Accessed by the Local Integration
After the owner completes explicit Google OAuth consent, the local Hermes Agent may access the following Google Workspace services, limited to the owner's own data:
- Gmail — read, search, and manage email
- Calendar — view and manage events
- Drive — access and manage files
- Docs — view and edit documents
- Sheets — view and edit spreadsheets
- Contacts — view contact information only, on an optional, read-only basis, and only if separately granted by the owner
Access is used solely to fulfill the owner's own requests — such as email search, calendar scheduling, file retrieval, document assistance, and spreadsheet analysis — and for no other purpose.
OAuth Credentials and Tokens
OAuth tokens are stored locally on the owner's own machine with owner-only access permissions. They are transmitted only to Google OAuth and Google API endpoints, as required to authenticate and perform the owner's requested operations.
Limited Sharing for Explicit Owner Requests
When the owner explicitly asks the local Hermes Agent to perform a task that requires an AI model or external service, selected Google task data may be sent to the AI, model, or service providers the owner has configured — solely to fulfill that explicit request. Such processing is governed by the respective provider's own terms and privacy policies. Google user data is never sold, never used for advertising, and never used for any purpose unrelated to the owner's explicit requests.
Data Retention
Local OAuth tokens are retained on the owner's machine until the owner revokes access or deletes them. Task content (such as message or document excerpts processed during a request) is transient: it is handled only as needed to complete the owner's request, subject to local Hermes settings and the configured providers' policies.
Revoking Access
The owner may revoke the integration's Google access at any time via Google's account permissions page: https://myaccount.google.com/permissions.
Google API Services User Data Policy
The integration's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
For privacy-related questions or concerns, contact giljavelosa@gmail.com.