Hermes Personal Assistant — Privacy Policy
Effective date: September 15, 2026
This policy explains how Hermes Personal Assistant (the “Application”) handles Google user data. The Application is a private personal application used only by its owner.
Information collected
- Google Calendar event information, including dates, titles, descriptions, locations, and attendees within the authorized read-only scope.
- The subscribed Google Calendar list and metadata, including calendar names, identifiers, and access information within the authorized read-only scope.
- Gmail message information, including senders, recipients, dates, subjects, bodies, and thread information within the authorized read-only scope.
- Technical information required to operate the Application, such as synchronization results and last-update times.
Purpose of use
The information is used only to prepare the owner's daily plans, identify action items and deadlines, check source freshness, and maintain those functions.
Storage and protection
Data is stored on equipment controlled by the owner. The Application separates permissions according to least privilege and isolates credentials from publicly served web content. Google access and refresh tokens are never published on this website.
External processing and delivery
The Application uses Discord to deliver daily plans and notifications to the owner, and may use LINE for high-priority notifications. Action items, events, or summaries derived from Google user data are transmitted to those services when delivered. When the owner requests a conversational answer, Google user data or derived information needed for the answer may be sent to and processed by an AI model service configured by the owner. The scheduled daily plan is generated locally from a deterministic template and is not sent to an AI model service.
Transfers to external services are limited to what is necessary to provide the owner-requested feature. Each external service processes transmitted information under its own terms and privacy policy.
Sale, advertising, and other sharing
Google user data is not sold or used for advertising, marketing, or credit assessment. It is not otherwise shared with third parties except for the external services needed to provide the owner-facing features described above or where required by law. The Application's use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Data is retained only while needed for the Application's functions. The owner can delete locally stored data and revoke the Application's access from the Google Account security settings. Requests about deletion or stopping access can be made through the user support contact displayed on the Google consent screen.
Changes to this policy
If data-handling practices change, the revised policy and its effective date will be published on this page.