Privacy Policy
Hermes personal assistant · last updated 11 September 2026
Hermes is a self-hosted personal assistant operated by a single individual for their own use. It has one user: its operator. There is no sign-up, no other users, and no third-party access.
What data is accessed
Hermes accesses only the Google account of its operator, using these permissions:
| Permission | Why |
|---|---|
gmail.readonly, gmail.modify |
Read mail to summarise what needs attention; apply labels, archive, and organise. Used to triage the inbox. |
gmail.compose |
Create draft replies. Drafts are reviewed and sent by a human. |
calendar, calendar.events, and related read scopes |
Read the schedule, summarise the day, detect conflicts, and create or update events on request. |
openid, userinfo.email, userinfo.profile |
Identify which account is connected. |
What Hermes deliberately cannot do
- Send email. The send permission is not granted. Hermes writes drafts only.
- Permanently delete mail. Full-mailbox access is not granted.
- Change mail settings. It cannot create filters or set up forwarding.
These limits are deliberate. An assistant that both reads an inbox and can send from it is a risk if it is ever misled by the contents of that inbox.
Where data goes
- Data is fetched directly from Google's APIs to hardware the operator controls.
- It is not sold, shared, or transferred to anyone.
- There is no analytics, advertising, tracking, or profiling.
- No data is collected from visitors to this website. It is static; there are no cookies and no logins.
Storage and retention
Message and calendar content is processed to produce summaries and drafts. Working copies and OAuth tokens are stored on the operator's own machine with owner-only file permissions, and are deleted when no longer needed or when access is revoked.
Revoking access
The operator can revoke Hermes' access at any time at myaccount.google.com/permissions. Revoking immediately invalidates the stored credentials.
Limited Use disclosure
Hermes' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data is used only to provide the features described above, is not transferred to others except as required by law, is not used for advertising, and is not read by humans other than the operator whose account it is.