Hermes Gmail

Privacy policy ยท Updated 2026-09-30

How Hermes Gmail handles data

This policy describes the personal Hermes Gmail integration operated by Joseph Follett. It is not a privacy policy for every installation of Hermes Agent or for the separate services used by the account owner.

Data accessed and purpose

With the owner's Google authorization, the integration can access Gmail labels, message and thread identifiers, headers such as sender, recipient, subject and date, message snippets, message content when needed, and mailbox state such as Inbox, unread and starred labels.

This data is used to audit and organize the owner's email: review label consistency, classify relevant messages, archive eligible individual messages, produce audit reports, and investigate errors. The integration does not request Calendar, Drive, Contacts, or other Google service scopes for this Gmail workflow.

AI processing and sharing

Relevant email content, metadata, and derived audit findings may be included in requests to the AI/model provider selected in the owner's Hermes configuration. This processing is used for the requested email-audit and organization functionality; it is not entirely on-device processing. That provider's retention and account settings also apply.

Gmail data is not sold, used for advertising, or used by this application to train a generalized AI or machine-learning model. Any provider receiving Gmail data must be configured consistently with Google's Limited Use requirements, including restrictions on generalized model training. If that cannot be assured, Gmail processing with that provider must be disabled.

Data is shared only as needed for the requested functionality, security or troubleshooting with the owner's authorization, or a legal obligation. This is a personal integration rather than a service through which unrelated people can inspect the owner's mailbox.

Storage, retention, and security

Google OAuth client credentials and refresh/access tokens are stored in local Hermes application files on the owner's computer. Local sessions, audit reports, logs, or backups may contain email-related metadata or excerpts. They remain until the owner removes them or applies the relevant local retention settings. AI-provider retention is separate and depends on the provider and account configuration.

Credentials and mailbox contents are not embedded in or uploaded to this public informational website. Google and AI-service requests use the services' encrypted network connections. Local file and backup protection depends on the owner's operating-system permissions and security configuration; this policy does not claim that local files are encrypted at rest.

Website hosting

Cloudflare hosts these informational pages and may process normal request information, such as IP addresses and browser request metadata, to deliver and secure the website. These pages contain no application analytics script, signup form, or mailbox connection endpoint.

Revocation, deletion, and contact

The owner can pause the scheduled job, revoke Hermes Gmail's access in Google Account third-party connections, and remove local credentials and email-related reports or backups. Revoking Google authorization stops future authorized access but does not automatically delete existing local files or data already retained by a provider.

Questions or requests: joseph.follett@gmail.com. Material changes to the integration's data practices require an updated policy.

Google API data commitments

Hermes Gmail's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.