Privacy notice

How Google Workspace data is handled.

This notice covers the Hermes Workspace integration and this informational website. The integration runs within the Hermes Agent environment configured by the account holder; it is not a central hosted service.

Last updated: 5 October 2026

Project contact

Project operator: Viacheslav Mikhailov. For privacy questions or requests, email viacheslav.mikhailov@gmail.com.

Google data the integration can access

After you grant OAuth permission, Hermes may access Google Workspace data needed for an action you request. The current permission set covers:

  • Gmail: message headers, snippets and content; searching, reading, sending, replying, and modifying message labels or state.
  • Calendar: calendar and event details; creating or managing events.
  • Drive: file names, metadata and file contents; searching, reading, downloading, uploading, organizing, sharing, or deleting files.
  • Contacts: contact names and contact details.
  • Sheets: spreadsheet data; reading, creating, updating, or appending values.
  • Docs: document text; reading, creating, or appending text.

Access is made through Google APIs from the Hermes runtime you configure and is used to provide the user-requested assistant feature. The integration is not intended to use Google user data for advertising, sell it, or train general-purpose AI models.

Where data is processed

The Hermes runtime makes API requests to Google and receives the requested results. Those results can become part of the conversation context and local Hermes session history. The OAuth token is stored by Hermes in the active profile on the device or server where that Hermes instance runs (the credential file is commonly named google_token.json).

If you configure a remote AI model, messaging channel, or remote Hermes gateway, relevant conversation content—including Google results you asked Hermes to use—may be transmitted to those providers to complete your request. Their own privacy, security, and retention terms apply. This integration does not control those providers’ processing.

The website host does not proxy Google API calls and does not receive Google Workspace content or OAuth tokens through this website.

Storage and retention

There is no central database for Google Workspace content operated by this project. Tokens and conversation data may remain in the Hermes profile and session history on the machine or server where you run Hermes, according to your Hermes configuration. Data sent to Google, an AI provider, a messaging platform, or a remote gateway may be retained under that provider’s own settings and policies.

The website is static and does not use an account, contact form, cookies, analytics, or advertising trackers. The web server records ordinary access information such as IP address, request path, timestamp, and browser user-agent for operation and security; those server logs are subject to the server’s configured log management.

Sharing and service providers

Google processes API requests under Google’s terms. Depending on your configuration, an AI model provider, messaging platform, or remote gateway may receive conversation content needed to answer your request. The project operator does not receive a copy of that Google content through this website. No Google data is sold by the project operator.

Your choices and deletion

  • Review the permissions shown by Google before authorizing. Do not connect an account unless you are comfortable with the requested access.
  • Revoke the integration in your Google Account’s third-party app access settings.
  • Remove the OAuth token and relevant session history from the Hermes profile or server you control. The exact location depends on your platform and active Hermes profile.
  • For data held by a model, messaging, or hosting provider, use that provider’s privacy controls and deletion process.

Revoking OAuth prevents future API access but does not remove content already present in local session history or held by third-party providers.

Security and contact

OAuth tokens should be treated as sensitive credentials. Protect the device or server running Hermes and limit access to its Hermes profile. This project does not claim that the token file is encrypted by this website. For a privacy request or question about the integration, contact viacheslav.mikhailov@gmail.com.