Privacy Policy

Last updated: 13 September 2026

1. Scope

This policy applies to the Hermes Personal Assistant application ("the Application"), a self-hosted personal assistant operated by a single individual ("the Owner") for their own personal use. The Application is not offered to the public and has no users other than the Owner.

2. Data the Application accesses

With the Owner's explicit authorisation via Google OAuth 2.0, the Application may access the following data belonging to the Owner's own Google Account:

The Application accesses only the Google Account of the Owner who authorised it. It does not access any other person's Google Account.

3. How data is used

Data is used solely to perform tasks the Owner requests — for example summarising email, scheduling calendar events, drafting replies, and maintaining the Owner's personal notes. Data is not used for advertising, profiling, or any purpose unrelated to these functions.

4. How data is stored

The Application runs on a private server controlled by the Owner. OAuth credentials are stored in a restricted-permission file on that server. Content derived from Google services may be written to the Owner's personal notes archive on the same server. No data is stored on infrastructure belonging to any other party, except as described in section 5.

5. Third-party processing

The Application uses a third-party large language model provider to process text. Content the Owner asks the Application to work with may be transmitted to that provider for processing. The Owner accepts this on their own behalf. No data is sold, rented, or shared for advertising purposes, and no data is transferred to any other third party.

6. Data sharing

Data is not shared with any person or organisation other than as described in section 5. The Application has no other users with whom data could be shared.

7. Data retention and deletion

The Owner may revoke the Application's access at any time at myaccount.google.com/permissions, which immediately invalidates its credentials. Stored data may be deleted by the Owner at any time by removing it from the server.

8. Limited Use disclosure

The Application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide or improve user-facing features that are prominent in the Application's functionality, is not transferred to others except as necessary to provide those features or as required by law, is not used for advertising, and is not read by humans except with the Owner's consent, for security purposes, or as required by law.

9. Changes

This policy may be updated. The revision date at the top of this page indicates the most recent change.

10. Contact

This application has a single user, who is also its operator. Enquiries about this policy can be directed to the contact address published for the application on its Google OAuth consent screen.