Privacy Policy

Effective date: August 25, 2026

This policy describes how Hermes Personal Workspace Access handles Google user data. The application is a private, self-hosted utility operated solely by the owner for access to the owner’s own Google account. It is not offered as a public service.

Google data accessed

Depending on the operator’s request, the application may access Gmail messages and settings, Google Calendar events, Google Contacts, files and metadata in Google Drive, Google Docs content, and Google Sheets content.

How data is used

Google user data is used only to perform actions explicitly requested by the operator or personal automations configured by the operator. Examples include searching and composing mail, managing calendar events, finding documents, reading documents, and reading or updating spreadsheets.

Storage, processing, and disclosure

OAuth credentials and application state are stored on the operator’s self-hosted system with operating-system access controls. Requested Google content may appear in local Hermes session history and logs. To fulfil a request, relevant content may be processed by the AI model provider selected and configured by the operator, subject to that provider’s terms and privacy policy.

Google user data is not sold, used for advertising, or disclosed to unrelated third parties. It is not used to train a general-purpose AI model by the application operator.

Retention and deletion

Data is retained only in the operator-controlled local system and configured service providers for as long as needed for the operator’s workflows. The operator can delete local credentials, sessions, and logs at any time. Google access can also be revoked from the Google Account permissions page.

Security

The operator uses reasonable technical controls for the self-hosted system, including restricted filesystem permissions for OAuth credentials. No method of storage or transmission can be guaranteed to be completely secure.

Google API Services User Data Policy

The application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes and contact

Material changes will be published on this page. Questions can be submitted through the project issue tracker.

Back to the application homepage