PRIVACY POLICY
How Google user data is handled
1. Application scope
Hermes Personal Assistant is operated by and for one individual. It supports personal productivity workflows involving Gmail, Google Calendar, Google Drive, and Google Tasks, including scheduled personal briefings and user-requested file backups.
2. Google data accessed
- Gmail: message metadata and content needed to search, read, summarize, draft, send, reply, or change message labels when the user requests those functions.
- Google Calendar: calendars and events needed to review schedules, identify conflicts, and create, update, or delete events when directed by the user.
- Google Drive: metadata and contents of files selected for search, reading, creation, download, upload, or backup at the user's direction.
- Google Tasks: task lists and task details needed to review or manage personal tasks at the user's direction.
- OAuth account information: authorization tokens and granted scopes required to maintain the connection.
3. How data is used
Google user data is used only to provide or improve user-facing features explicitly requested or configured by the user. Typical uses include producing personal summaries, identifying upcoming commitments, carrying out approved Google Workspace actions, and backing up user-selected files.
The application does not use Google user data for advertising, credit decisions, surveillance, sale, or unrelated analytics.
4. Processing and disclosure
Relevant data excerpts may be processed by the AI model provider configured by the user, solely to generate the requested answer, summary, classification, or action. Data may also be transmitted to Google APIs to perform the requested Google Workspace operation. The application does not disclose Google user data to data brokers, advertisers, or unrelated third parties.
Any processing is limited to providing the application's user-facing functionality and is subject to the configured service providers' applicable security and privacy terms.
5. Storage and protection
OAuth credentials and operational state are stored on the user's personal computer. Requested outputs, logs, and summaries may also be retained locally. Files that the user explicitly chooses to back up may be stored in the user's own Google Drive. The application does not maintain a separate public user database.
Access is protected by the security controls of the user's operating system, Google account, and configured service providers. No method of storage or transmission can be guaranteed to be completely secure.
6. Retention and deletion
OAuth credentials are retained until the user revokes access, disconnects the integration, or deletes the local credential file. Local outputs and logs remain until the user deletes them under the user's local retention settings. Google Drive files remain until the user removes them.
The user may request deletion help by emailing tyahn6658@gmail.com. Because this is a single-user personal application, the user may also directly delete local files and Google Drive content at any time.
7. User controls
The user can review or revoke Google access at Google Account permissions. Revoking access prevents future API access but does not automatically delete files or summaries already created at the user's request.
8. Google API Services User Data Policy
The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Children and public users
This application is not offered to the public and is not directed to children. It is used only by its adult owner.
10. Changes
This policy may be updated when the application's data practices or Google API access changes. The effective date at the top of this page will be updated when material changes are made.