Last updated September 4, 2026
Privacy Policy
This policy explains how Hermes Agent accesses, uses, stores, and shares Google user data.
Application and operator
Hermes Agent is a privately operated personal assistant used only by accounts expressly authorized by its operator.
Data accessed
After explicit OAuth authorization, Hermes Agent may access files and metadata in Google Drive; content and structure in Google Docs, Sheets, and Slides; calendars and events; form definitions and responses; and Google Tasks data. Basic Google account identity information, including email address and profile information, is used to associate authorization with the correct account.
How data is used
Data is used solely to perform actions requested by the authorized user and to return relevant results. Depending on the request, this may include searching, reading, creating, updating, organizing, exporting, sharing, or deleting authorized Workspace resources. Destructive deletion and clearing of completed Google Tasks are disabled by the application configuration.
Processing and service providers
Google user data is processed by the privately operated Hermes Agent server. Content needed to interpret a request or produce a response may be transmitted to the AI inference provider configured by the operator. Google APIs receive data necessary to perform requested Google Workspace operations. Data is not sold, used for advertising, or intentionally used by the operator to train generalized AI models.
Storage and retention
OAuth credentials are stored on an access-restricted VPS controlled by the operator. Workspace content is generally retrieved on demand. Temporary attachments, conversation state, and operational metadata may be retained as needed to complete requests, maintain the assistant, and diagnose failures. Stored credentials and associated application data are retained until access is revoked, the integration is removed, or deletion is requested.
Security
The integration runs under a dedicated restricted system account. Its MCP endpoint is not publicly exposed, credentials are protected by filesystem permissions, and outbound network access is restricted to required Google endpoints. No security measure can eliminate every risk, but access is limited to the operator and authorized account.
User control and deletion
The user can revoke Hermes Agent from Google Account connections. Revocation prevents future token refresh. The authorized user can request deletion of locally stored OAuth credentials and related application data through their established private communication channel with the operator.
Google API Services policy
Hermes Agent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
This policy may be updated when the application's functionality or data practices change. The revision date at the top identifies the current version.