Hermes — Privacy Policy
Last updated: 27 September 2026
1. What this application is
Hermes is a private, single-user automation tool operated by one individual for personal use. It is not offered to the public, it has no other users, and it does not collect or process data belonging to anyone other than its owner.
2. What data it accesses
With the owner's explicit consent, Hermes requests read-only access to the following Google services:
- Gmail (
gmail.readonly) — to identify messages that need the owner's attention - Google Calendar (
calendar.readonly) — to list upcoming events - Google Drive (
drive.readonly) — to summarise recent file activity - Basic account profile (email address) — to identify which account has been authorised
Hermes never sends, modifies, or deletes any Google data, and it never creates or edits calendar events. Its access is strictly limited to reading.
3. How the data is used
Accessed data is used for one purpose only: to generate a private daily summary for the owner, delivered to the owner's own private messaging channel. Data is never used for advertising, marketing, profiling, or training machine-learning models.
4. Where data is processed and stored
Hermes runs on a self-hosted server controlled by the owner. The OAuth credential (a refresh token) is stored on that server with restricted file permissions and is never transmitted to any third party. Google data is processed only in memory while the summary is being produced; it is not sold, shared, or disclosed.
5. Sharing and third parties
No Google user data is shared with, sold to, or transferred to any third party. Hermes contains no analytics, no advertising, and no third-party data-broker integrations.
6. Google API Services — Limited Use disclosure
Hermes's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Revoking access
The owner can revoke Hermes's access at any time at myaccount.google.com/permissions. Revoking access immediately stops all further access; no further data will be requested or processed.
8. Security
OAuth credentials are stored only on infrastructure controlled by the owner and are never embedded in distributed software. Access to that infrastructure is protected by the owner's own network and authentication controls.
9. Changes to this policy
Any change to these practices will be reflected on this page, together with an updated revision date.
10. Contact
Questions about this policy or about data handling: hermes@andisblue.com