Hermes Agent — Google Workspace Integration · Last updated: 5 October 2026
This policy explains how Hermes Agent ("the integration", "we") accesses, uses, stores and shares information obtained from Google APIs when its owner connects a Google Account.
The integration is a private tool used by its owner and a small number of Google accounts the owner explicitly authorises. It is not a public service and has no user registration.
With the owner's explicit consent, the integration requests access to the following Google services and scopes:
gmail.readonly, gmail.send, gmail.modify: to search and read messages, and to send or reply to email when the owner instructs it to.calendar: to read the owner's events and to create or delete events on request.drive: to search, read, upload and organise files the owner has access to.Google user data is used only to perform the actions the owner requests through the integration — for example, summarising unread mail, listing upcoming meetings, or filing a document. The data is not used for advertising, profiling, or any purpose unrelated to those requests.
OAuth access and refresh tokens are stored on the owner's own private infrastructure, local to the machine running the integration. Tokens are stored solely so the integration can remain connected without repeated sign-in, and are deleted when the owner disconnects the account or revokes access.
Message, calendar and file content is processed transiently to fulfil a request and is not retained in any database or sold or transferred to third parties.
We do not sell, rent, or share Google user data with third parties. Data is not transferred to advertisers, data brokers, or any party for purposes unrelated to operating the integration. Data may be processed by the underlying AI model provider strictly to generate the response the owner requested; no Google user data is used to train models.
Credentials and tokens are kept in access-restricted files on the owner's private system and are never published or transmitted to unauthorised parties. Communication with Google APIs takes place over HTTPS using Google's official OAuth 2.0 endpoints.
The owner can revoke the integration's access at any time at myaccount.google.com/permissions. Revoking access immediately invalidates the stored tokens and stops all further access.
To request deletion of any stored credentials or data, contact us at the address below and it will be removed.
Hermes Agent's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This policy may be updated; the "Last updated" date above will reflect any change. Continued use of the integration after an update constitutes acceptance of the revised policy.
Questions or data requests: [email protected]