Summary: Hermes AI Agent is a private, operator-controlled automation service. Google user data is accessed only for authorized workflows, is not sold, is not used for advertising, and is not used to train generalized artificial-intelligence or machine-learning models.
1. Scope and operator
This Privacy Policy describes how the privately operated Hermes AI Agent application accesses, uses, stores, and shares information when an authorized Google account is connected. The application is not offered for general public registration.
Privacy questions can be sent to sunsetcongict@gmail.com.
2. Google user data accessed
After the account holder grants OAuth permission, the application may access Gmail data needed for configured workflows, including:
- The authorized account’s email address and basic Gmail profile identity.
- Messages, headers, recipients, subjects, and delivery identifiers.
- Email bodies and attachments relevant to an enabled workflow.
- Gmail labels and message organization state.
The application requests Gmail modify access because an approved workflow may send email, read relevant incoming messages, download attachments, add or remove labels, archive messages, or move approved messages to Trash. It does not require Gmail’s permanent-delete permission.
3. How Google user data is used
Google user data is used only to provide operator-configured functionality, including:
- Sending generated meeting documents to confirmed recipients.
- Verifying delivery and preventing duplicate sends.
- Receiving and processing expected workflow-related email and attachments.
- Applying labels, archiving, or moving specifically approved messages to Trash.
- Maintaining security, troubleshooting failures, and recording a limited operational audit trail.
Google user data is not used for personalized advertising, credit decisions, surveillance, or unrelated profiling.
4. Storage and retention
OAuth credentials, workflow state, delivery identifiers, document checksums, and approved downloaded attachments may be stored on the operator’s private virtual server. Access is restricted to the operator and the application processes that need the information.
Data is retained only as long as reasonably needed to operate the workflow, prevent duplicate actions, investigate delivery failures, satisfy an operator-directed recordkeeping need, or maintain security. Messages remain primarily within Gmail and are subject to the account holder’s Gmail retention choices. Approved cleanup favors reversible actions such as labels, archive, and Trash rather than permanent deletion.
5. Sharing and disclosure
Google user data is not sold, rented, or shared with data brokers. Information is disclosed only:
- To Google as necessary to use Gmail and OAuth services.
- To the intended email recipients selected by the workflow operator.
- To infrastructure providers strictly as necessary to host and secure the private application.
- When required by law or necessary to protect the security and integrity of the service.
Google user data is not transferred to train generalized AI or machine-learning models.
6. Security
The application uses HTTPS for network transport, OAuth rather than storing the Gmail password, restricted credential files, narrow service exposure, and access controls on the hosting server. No system can guarantee absolute security, but the operator uses reasonable technical and administrative safeguards appropriate to this private application.
7. User control and revocation
The account holder can revoke the application’s OAuth access at any time from the Google Account security page under third-party connections. Revocation prevents new API access. The account holder may also contact the operator to request deletion of locally retained Google user data, subject to limited security, legal, and audit-record needs.
8. Google API Services User Data Policy
Hermes AI Agent’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve prominent, user-facing features that are visible and relevant to the authorized account holder.
9. Children’s privacy
This application is not directed to children and does not permit public registration. It is operated only for explicitly authorized private workflows.
10. Changes to this policy
This policy may be updated when the application’s functionality or legal requirements change. The effective date at the top of this page will be updated when material changes are published.