Hermes Privacy Policy

Last updated: September 22, 2026

Hermes is a personal automation and productivity assistant operated for the private use of its owner. This policy describes how Hermes handles data obtained through Google APIs.

Google data accessed

Hermes may request access to Google Drive, Gmail, Google Calendar, Google Sheets, Google Docs and Google Contacts/People. Access is limited to the permissions granted by the Google account owner and is used to provide Hermes features requested by that owner.

How Google data is used

Google data may be accessed to search, retrieve, read, organize, analyze or otherwise process information requested by the owner. Hermes does not sell Google user data and does not use Google user data for advertising or advertising profiling.

Storage and security

OAuth credentials and tokens are stored on the owner's private Hermes server and are protected by operating-system file permissions. Data retrieved from Google services may be processed or temporarily stored on that server as necessary to provide the requested Hermes functionality.

Sharing

Google data is not intentionally disclosed to unrelated third parties. Data may be sent to external services only when the owner explicitly uses a Hermes feature that requires such a service. Google APIs are used to access the owner's Google account.

Data retention and deletion

The owner controls the connected Google account and can revoke Hermes' Google access through Google account security settings. Locally stored Hermes data and credentials can also be removed by the owner from the Hermes server.

Changes

This policy will be updated if Hermes' handling of Google data materially changes.

Back to Hermes