Privacy Policy

Hermes Agent · Effective 24 September 2026

This privacy policy describes how Hermes Agent ("the application", "we") accesses, uses, stores, and protects information obtained from Google APIs when the owner of the application connects their Google account.

Summary: Hermes Agent is a private, single-user application. Google user data is used strictly to carry out actions the owner explicitly requests, is processed on the owner's own computer, and is never sold, shared, or used for advertising or model training.

1. Who this policy applies to

Hermes Agent is not a public or commercial service. It has exactly one user: the owner of the Google account that authorized it. No third party can create an account, and the application does not accept sign-ups from the public.

2. What Google user data is accessed

With the owner's explicit consent, the application may access the following, and nothing else:

Google serviceScope requestedPurpose
Gmailgmail.readonlySearch and read messages at the owner's request (e.g. inbox summary).
Gmailgmail.sendSend mail only when the owner explicitly asks for a message to be sent.
Gmailgmail.modifyApply or remove labels and change read state so requested triage persists.
CalendarcalendarRead events to prepare briefings; create or edit events on request.
DrivedriveLocate, read, and organize files the owner references.
SheetsspreadsheetsRead and update spreadsheets the owner asks to work with.
DocsdocumentsCreate and edit documents on request.
Contactscontacts.readonlyResolve contact names to email addresses. Read-only, never modified.

The application requests no Google scopes beyond those listed above, and does not access Google data belonging to anyone other than the authorizing owner.

3. How Google user data is used

4. Where data is stored and processed

The application runs on the owner's personal computer. Google user data is retrieved directly to that machine and processed there. There is no Hermes Agent server that collects, stores, or relays Google user data. No Google user data is transmitted to any third-party service, other than to a large-language-model provider for the sole purpose of generating the response the owner asked for; those providers are bound by their terms not to train on submitted data.

OAuth credentials (access and refresh tokens) are stored locally on the owner's computer in a protected file. They are never transmitted anywhere except to Google's own authorization endpoints.

5. Data retention and deletion

6. Security

7. Google API Services User Data Policy

Hermes Agent's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Children's privacy

This application is not directed to anyone under the age of 18 and does not knowingly collect data from children.

9. Changes to this policy

Any material change to this policy will be reflected on this page with an updated effective date. Because the application has a single user, changes are communicated directly to that owner.

10. Contact

Questions, concerns, or deletion requests regarding this policy or Google user data should be directed to admin@hulknetworks.com.