Privacy Policy

Hermes — personal assistant integration · Last updated 11 September 2026

Hermes is a private, self-hosted application used by a single individual to manage their own email and calendar. This policy explains what data the application handles and how.

1. Who operates this application

Hermes is operated solely by its owner for their own personal and business administration. There are no other users, no customers, and no public sign-up.

2. What data is accessed

Only after the owner grants access via Google's OAuth consent screen, and only for the owner's own account:

No other Google services or data are accessed.

3. How the data is used

Data is used exclusively to perform tasks the owner requests, such as:

4. Storage and retention

Authentication tokens and any cached working data are stored locally on hardware owned and controlled by the owner. Data is retained only as long as it is useful for the tasks above and can be deleted by the owner at any time; revoking access in the owner's Google Account immediately ends all further access.

5. Sharing and disclosure

Google user data is never sold, rented, transferred or disclosed to any third party. It is not used for advertising, marketing, profiling, or to train machine-learning models. The application's use of Google user data is limited to the purposes described in this policy, in line with the Google API Services User Data Policy, including its Limited Use requirements.

6. Security

Access is protected by Google OAuth 2.0. Tokens are held locally on the owner's own hardware, are not embedded in client-side code, and are not transmitted to any party other than Google's APIs. Access can be revoked at any time from the owner's Google Account permissions page.

7. Changes

Any change to this policy will be published on this page with an updated date.

8. Contact

Questions about this policy can be sent to sean.newmee@gmail.com.