Privacy Policy
This policy explains what Google user data Hermes - Google Apps Connector accesses, why it accesses it, how that data is stored, and what is never done with it.
1. Who this policy covers
Hermes - Google Apps Connector ("the Application") is a private, self-hosted integration operated by a single individual ("the Operator") for their own Google Account. The Application has exactly one authorized user: the Operator. It has no other users, and no third party can register for or sign in to it.
Because the Application serves only its Operator, the "user data" it handles is the Operator's own data. This policy is published so that the scope of that handling is transparent and auditable.
2. What data the Application accesses
The Application accesses the following categories of data from the Operator's own Google Account:
- Gmail: message metadata and content, and the ability to send and modify the Operator's own messages.
- Google Calendar: calendar names, events, times, locations, descriptions, and attendees.
- Google Drive: file and folder names, metadata, contents, and sharing permissions.
- Google Docs, Sheets, and Forms: document, spreadsheet, and form content and responses.
- Google Contacts: contact names and email addresses.
- Account identity: the email address of the authorized Google Account, used to confirm which account is connected.
The Application does not access data belonging to any other Google Account.
3. Why the Application accesses this data
Access exists solely to provide the Operator with the assistant functionality described on the home page. In each case the purpose is direct and operator-initiated: to read something the Operator asked about, or to carry out an action the Operator explicitly requested, on the Operator's own account.
The Application does not request access to data it does not use, and does not request access in anticipation of future features that do not exist yet.
4. How the data is used
- To answer the Operator's questions about their own email, calendar, files, documents, and contacts.
- To perform actions the Operator explicitly requests, such as sending a specified email, creating a specified calendar event, or uploading a specified file.
- To display results back to the Operator in their own assistant interface.
Data is processed only for these purposes. It is not used for profiling, scoring, advertising, resale, or any purpose unrelated to serving the Operator's requests.
5. How the data is stored and protected
- OAuth credentials are stored locally on infrastructure controlled by the Operator, in a file readable only by the Operator's operating system account.
- Data retrieved from Google APIs is held in memory only for as long as needed to answer the Operator's request. Where content is cached or written to disk, it stays on the Operator's own machine.
- Transit between the Application and Google APIs uses TLS, as provided by Google's API endpoints.
- The Application does not operate a server-side database of Google user data belonging to anyone other than the Operator.
6. Sharing and disclosure
Google user data accessed by the Application is not sold, rented, traded, or shared. Specifically:
- No transfer of Google user data to third parties such as advertising platforms, data brokers, or information resellers.
- No use or transfer of Google user data to serve advertising, including retargeting, personalized, or interest-based advertising.
- No use or transfer of Google user data to determine credit-worthiness or for lending purposes.
- No disclosure to any other person, except where required by applicable law.
The Application relies on Google's own APIs and, where the Operator's assistant invokes a third-party language model, on that provider's API. Where any Google user data is passed to such a provider, it is passed only to fulfill the Operator's specific request, and only to providers contractually bound not to use it for training or for any purpose other than returning the requested result. No Google user data is transferred for the purpose of training or improving machine learning models.
7. No human review
No person reads the Operator's Google user data except the Operator themselves. There is no support team, no moderation queue, and no administrative access by anyone else.
8. Retention and deletion
- Google user data is retained only as long as needed to fulfill the Operator's requests, or as long as it remains in a local cache on the Operator's own machine.
- The Operator can delete locally stored credentials and cached data at any time from their own machine.
- The Operator can revoke the Application's access at any time at myaccount.google.com/permissions. Revocation takes effect immediately and stops all further access.
- Requests relating to stored data can be sent to the contact address below.
9. Limited Use disclosure
Hermes - Google Apps Connector's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Children
The Application is not directed at children and is not available to anyone other than its single Operator.
11. Changes to this policy
This policy may be updated to reflect changes in how the Application works. The effective date at the top of this page will be revised when it changes, and the current version will always remain available at this URL.
12. Contact
Questions, or requests concerning Google user data, can be sent to hermesagentforazee@gmail.com.