Who operates Agents
Agents is a personal OAuth application operated by its owner for use with the owner's Hermes Agent installation. It is not a multi-user hosted service. The application has no separate server that receives Google Workspace content or OAuth tokens.
Google data accessed
When the owner grants access, Hermes may use the Google Workspace permissions configured for this application:
- Gmail: read messages, send messages, and modify messages and labels.
- Calendar: view and manage calendars and events.
- Drive: access and manage Drive files.
- Docs: read and edit documents.
- Sheets: read and edit spreadsheet data.
Hermes accesses this data only to carry out tasks requested by the account owner. The owner can review the exact permissions on Google's consent screen before granting access.
How data is processed and shared
Google Workspace data is retrieved by Hermes running in an environment controlled by the account owner. The Agents website does not receive, proxy, or store email, calendar events, files, document contents, spreadsheet contents, or OAuth tokens.
To answer a request, Hermes may include relevant Google data in prompts or tool calls sent to the AI model provider and other integrations configured by the owner. Those providers process data under their own terms and privacy policies. The owner should review those services and avoid connecting providers that are not appropriate for the data being handled.
Information received from Google Workspace scopes is used only to provide the user-facing features described here and in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising, or used to train or improve generalized AI or machine-learning models. If Hermes sends relevant data to a model provider, the account owner must use a provider and configuration that process it only to fulfill the owner's request and do not use it for model training or unrelated purposes.
Google processes authorization and API requests under Google's own privacy terms.
Storage and retention
OAuth credentials are stored by the Hermes installation on the owner's device or server, rather than on the Agents website. Google data may also remain in files, logs, or conversation history maintained by Hermes or by integrations configured by the owner. Retention depends on those local settings and connected providers.
The static Agents website uses Cloudflare Pages for hosting. Cloudflare may process standard technical request information needed to deliver and protect the site under its own service terms. The site does not use analytics cookies or advertising trackers.
Security
Google authorization uses OAuth 2.0. The owner is responsible for securing the device or server running Hermes, protecting local credentials, and choosing trusted model providers and integrations. No internet service can guarantee absolute security.
Revoke access or delete credentials
The account owner can revoke Agents in Google Account connections. The owner should also remove the stored Google credentials from the Hermes environment and delete any retained outputs or logs there. Revocation prevents future API access but does not automatically erase copies previously created by Hermes or another configured provider.
Changes to this policy
This policy may be updated if the OAuth permissions or data handling change. The latest version will remain available at this URL with its updated date.
Contact
For questions about this policy or the Agents OAuth application, contact tranphuocngoc27@gmail.com.