Hermes AgentPrivacy policy
This policy covers George Sazonov's private, self-hosted Hermes Agent integration, not other installations of Hermes Agent or the services of its software authors. Contact: sazonov.geo@gmail.com.
Data accessed and purpose
Depending on permissions granted and tasks requested, the integration accesses Google Calendar events and attendees, Gmail messages and metadata, Google Drive files, Docs and Sheets contents, and contact information. These data are used to perform the owner's requested tasks, such as calendar scheduling, birthday reminders, email assistance, and document work. Write access is used for authorized changes and configured automations.
Processing and disclosure
The assistant runs on the operator's server. Relevant task content may be sent to the configured AI inference provider to generate responses, and to the chosen messaging platform (such as Telegram) to deliver replies or reminders. Requested invitations and messages are sent to their intended recipients through Google. These disclosures are part of performing the requested task; the assistant should not be used with data the owner does not authorize those providers to process. Provider processing and retention are also governed by those providers' terms and settings.
The operator does not sell Google user data or use it for advertising. Google data are not collected for training a general-purpose AI model. Access and disclosure are limited to operating the requested assistant features, support, security, and applicable legal requirements.
Storage and security
OAuth credentials are stored on the server separately from this public website. Task data may be retained in conversation history, logs, downloaded files, and automation state. The public website contains no OAuth credentials or private task records. Server access and credential handling are restricted to authorized administration; no system can guarantee absolute security.
Retention and deletion
Task records may remain until deleted by the operator; there is no automatic short retention period promised here. The account owner may request deletion of stored credentials and task records via the contact above. Removing local records does not automatically delete copies retained by Google, messaging services, AI providers, or message recipients.
Control and revocation
The account owner can revoke access at Google Account connections. Revocation prevents further authorized API access but does not itself erase previously stored records. Deletion may be requested separately.
Google API policy
The integration's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Website hosting
These static information pages are hosted on Cloudflare Pages. Cloudflare processes ordinary web request information to serve and protect the website. The pages have no analytics scripts, forms, or advertising.