Privacy policy

Privacy — personal Hermes connector

Operator: Aaron Mullane.
Contact: mullaneaa@gmail.com.
Effective date: 10 October 2026.

1. Scope

This policy describes Aaron’s personal Google Workspace connector running through Hermes. It is not the privacy policy for all Hermes software, Google, or any AI provider. The connector is intended for Aaron’s own account, not public registrations.

2. Information accessed

Depending on a task and the permissions granted, the connector can access email messages and attachments; calendar details and events; Drive file metadata and contents; contact names and contact details; and Google Docs and Sheets contents. Gmail, Calendar, Drive, Docs and Sheets permissions also allow changes. Contacts access is read-only.

3. Purpose and use

Google data is used to fulfil Aaron’s requested personal-assistant tasks, such as search, summarisation, organisation, drafting and explicitly approved actions. Google data must not be sold, used for advertising, or used to develop or train general-purpose AI models.

4. AI processing and sharing

Hermes may send task-relevant Google content to its configured third-party AI model provider as part of prompts and tool results. The provider for the current setup is OpenAI; provider settings can change. The provider’s own terms and retention controls apply to processing on its systems. This connector does not promise that all Google content stays on the workstation.

Sending email, adding attendees or sharing files can disclose data to the recipients Aaron selects. OAuth tokens and client-secret values are not intended to be included in model prompts or public pages.

5. Storage and retention

OAuth credentials are stored locally in Aaron’s Hermes profile. Task history, logs, generated files and cached tool results may also contain Google data and may remain on the workstation until deleted. This policy does not promise a fixed automatic deletion schedule or zero retention by an AI provider. Source data remains in Google unless Aaron requests a change or deletion.

6. Security and access

The connector uses Google OAuth rather than storing Aaron’s Google password. Access depends on the permissions granted to the OAuth client. Workstation access, local files, account security and any backups remain the operator’s responsibility. No claim of guaranteed security or end-to-end encryption is made.

7. Disconnecting and deleting

Aaron can revoke the connector’s Google access through Google Account third-party connections. Disconnection does not automatically delete copies already retained in task history, generated files or provider systems. Local copies must be removed separately, and any provider-side deletion is subject to that provider’s controls and terms. Requests about this connector can be sent to the contact above.

8. Google API Limited Use

Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

9. Changes

This policy must be updated if the connector’s purposes, account audience, providers, data handling or retention practices materially change. The effective date is shown above.