Privacy Policy for Hermes Agent One
Effective date: August 27, 2026
This Privacy Policy explains how Hermes Agent One accesses, uses, stores, shares, retains, and deletes information received through Google APIs.
1. Application purpose
Hermes Agent One is a private, self-hosted personal automation assistant. It accesses Google Workspace services only to perform tasks explicitly requested or authorized by the application owner. The application is not offered as a public or commercial service.
2. Google user data accessed
Depending on the task authorized by the user, the application may access Gmail messages, message metadata, labels, and email addresses; Google Drive files, folders, file metadata, and permissions; Google Calendar events and related metadata; Google Docs and Google Sheets content; Google Contacts information; and basic Google Account information needed for authorization.
3. How Google user data is used
Google user data is used only to provide user-requested functionality, including searching, reading, organizing, and sending email; locating, creating, uploading, downloading, and managing files; viewing, creating, updating, and deleting calendar events; reading and updating documents and spreadsheets; and completing other personal automation tasks explicitly initiated by the authorized user.
Google user data is not used for advertising, marketing profiles, credit decisions, or sale.
4. Data storage and security
OAuth credentials are stored on a private server controlled by the application owner. The application may retain task outputs, operational logs, downloaded files, and other information when necessary to complete a user-requested task or maintain the application. Access to the server is restricted to the application owner and authorized administrators. Reasonable technical and organizational measures are used to protect stored credentials and data from unauthorized access, disclosure, alteration, or destruction.
5. Data sharing and transfer
Hermes Agent One does not sell Google user data. Google user data may be processed by Google APIs as required to access authorized Google services, the self-hosted Hermes Agent infrastructure controlled by the application owner, and AI inference providers configured by the application owner only when processing is necessary to execute an explicit user request. Data is not transferred to third parties for advertising or unrelated purposes.
6. Data retention and deletion
OAuth credentials are retained until access is revoked, authorization expires, or the credentials are deleted by the application owner. Task outputs, operational logs, and user-requested files may be retained on the private server for operational or record-keeping purposes. The application owner can delete this information from the server at any time.
Google access can be revoked through the Google Account permissions page. The application owner may also request deletion of locally stored application data by contacting the email address below.
7. Limited Use
Hermes Agent One’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Changes to this policy
This Privacy Policy may be updated if the application’s functionality or data practices change. The effective date at the top of this page will be updated when material changes are made.
9. Contact
Questions about this Privacy Policy or the application’s data practices can be sent to hermes.agent.one@gmail.com.