Privacy policy for Hermes-agent
What Hermes-agent is
Hermes-agent is a personal AI assistant operated by Brian Østberg for his own use. It runs on a privately owned server in Denmark. It has exactly one user, the operator, and is not offered to the public. This policy exists because the assistant connects to Google services through Google's OAuth consent flow, and Google requires that the handling of that data is described openly.
What Google data it accesses
With the operator's consent, Hermes-agent may access the following data in the operator's own Google account:
- Gmail: read messages, send messages on the operator's behalf, and change labels (for example archiving a message or marking it as handled).
- Google Calendar: read and create events.
- Google Drive, Docs and Sheets: read and create files the operator asks it to work with.
- Google Contacts: read-only, to recognise who a message is from.
It never accesses any account other than the operator's.
How the data is used
The data is used solely to provide the assistant's features to the operator: triaging incoming mail, answering questions about mail and calendar, drafting and sending replies the operator has asked for, and filing messages. It is not used for advertising, profiling, resale, or training of any AI model.
To carry out these tasks, relevant excerpts (for example the text of an e-mail the operator asks about) are sent to third-party large-language-model providers for processing, under those providers' API terms, which exclude use of the content for model training. No other transfer to third parties takes place.
Where the data is stored
Data is processed and, where cached, stored on the operator's own server in Denmark. Access tokens are stored encrypted on that server. Backups are encrypted. Nothing is stored in a hosted database operated by anyone else.
Retention and deletion
Cached mail metadata and processing logs are kept only as long as the assistant needs them and are pruned automatically. The operator can delete all stored data at any time by removing the assistant's local data store. Revoking access (below) immediately invalidates all stored tokens.
Revoking access
Access can be withdrawn at any time at myaccount.google.com/permissions by removing "Hermes-agent". The assistant then loses all access to Google data.
Google API Services User Data Policy
Hermes-agent's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about this policy: brian.oestberg@gmail.com.