Hermes Personal Assistant

Privacy Policy

Last updated: September 10, 2026

This policy explains how Hermes Personal Assistant (the “Application”), operated by Anthony Armfield, accesses, uses, stores, and shares information obtained through Google APIs. The Application is a private, personal-use productivity assistant and is not offered for general public registration.

In brief: Google data is accessed only with authorization, used only for tasks requested by the authorized user, never sold or used for advertising, and can be disconnected at any time.

1. Google data the Application may access

Depending on the permissions granted and the task requested, the Application may access:

  • Gmail: message metadata, message content, attachments, labels, and drafts needed to search, organize, draft, send, or reply to email.
  • Google Calendar: calendars, event details, and attendee information needed to review or manage events.
  • Google Drive: file and folder metadata and content needed to find, read, create, update, download, upload, share, or delete user-selected items.
  • Google Docs and Sheets: document and spreadsheet content needed for user-requested reading or editing.
  • Google Contacts: names, email addresses, phone numbers, and related details needed for user-requested tasks.

2. How Google user data is used

The Application uses Google user data only to provide features requested by the authorized user, such as locating information, summarizing content, preparing drafts, organizing records, managing schedules, and carrying out explicitly approved actions.

The Application does not use Google user data for advertising, sale, credit decisions, surveillance, or unrelated user profiling. The Application itself does not use Google user data to train generalized or publicly available artificial-intelligence models.

3. AI-assisted processing and service providers

When the authorized user asks the Application to analyze, summarize, draft from, or otherwise act on Google content, the minimum relevant content may be transmitted securely to the AI service provider configured for the Application. Such providers process that information solely to produce the requested result and under their applicable API terms and data-protection commitments.

Google user data is not shared with unrelated third parties. It may be disclosed if required by law or when necessary to protect the security and integrity of the Application, the authorized user, or others.

4. Storage and retention

OAuth credentials are stored in access-restricted files on systems controlled by the operator. The Application may retain user-requested outputs, operational logs, and conversation history locally to provide continuity and support troubleshooting. It does not intentionally create a separate bulk archive of Google account data.

Credentials and locally retained Application data are kept only for as long as needed for operation, security, and user-requested continuity. The authorized user may request deletion using the contact information below.

5. Security

Reasonable technical and organizational safeguards are used to protect Google user data, including encrypted network transport, access controls, restricted credential storage, and least-privilege authorization scopes where practical. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.

6. User control and deletion

The authorized user may review or revoke the Application’s access through the Google Account third-party connections page. Revoking access prevents future Google API access but does not automatically delete previously retained local outputs or logs.

To request deletion of stored credentials, conversation history, logs, or other retained data associated with the Application, email anthony.armfield@gmail.com. Requests will be handled within a reasonable period.

7. Google API Services User Data Policy

The Application’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Children’s privacy

The Application is not directed to children and is not made available for public registration. The operator does not knowingly collect children’s personal information through the Application.

9. Changes to this policy

This policy may be updated to reflect changes in the Application or legal requirements. The “Last updated” date will be revised when material changes are published.

10. Contact

Questions or privacy requests may be sent to Anthony Armfield at anthony.armfield@gmail.com.