Hermes Agent GWS

Privacy Policy

Applies to the OAuth application Hermes Agent GWS. Last updated: 8 September 2026.

1. Who operates this application

Hermes Agent GWS is a single-user, self-hosted deployment of a personal assistant. It is operated by its owner, for the owner's own Google account only. It is not offered as a service to anyone else. Contact: hermes@baimuratov.app.

2. What Google user data is accessed

When the owner authorises the application, it requests access to:

The exact OAuth scopes are listed on Google's consent screen at the moment access is granted, and can be reviewed at any time at myaccount.google.com/permissions.

3. How the data is used

Data is used solely to carry out tasks the owner explicitly asks the assistant to perform: summarising and triaging mail, drafting or sending replies, managing calendar entries, and working with the documents, spreadsheets, presentations and tasks the owner points it to. There is no profiling, no analytics on message content, and no use unrelated to the owner's request.

4. How the data is stored

OAuth tokens are stored encrypted at rest on the owner's private server. Message, calendar and document content is processed in memory for the duration of a task and is not retained afterwards, except where the owner explicitly asks the assistant to save something (for example, a note or a summary the owner requested).

5. Sharing

Google user data is not sold, not shared with third parties, not used for advertising, and not used to train machine-learning models. To fulfil the owner's own request, relevant content may be transmitted to the language-model provider the owner has configured; that transmission is strictly limited to what the request requires.

6. Limited Use disclosure

Hermes Agent GWS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Revoking access

Access can be revoked at any time at myaccount.google.com/permissions. Once revoked, stored tokens become invalid immediately and the application can no longer access the account.

8. Deletion requests

To request deletion of stored tokens and any retained data, email hermes@baimuratov.app. Requests are honoured within 30 days.

9. Changes to this policy

This page is the canonical version of the policy. The "Last updated" date above changes whenever the policy does.