Hermes Personal Assistant

Effective September 4, 2026

Privacy notice

This notice describes Harpreet Chima's personal Hermes installation and its Google Workspace integration. The assistant is privately operated and is not offered as a public service.

Information the integration can access

After the account owner authorizes Google OAuth access, the integration can read Gmail messages, threads, and attachments; manage mailbox items and send email; read and change calendar events; read and manage Drive files; read and edit Google Docs and Sheets; and read contacts. Access is limited by the Google permissions actually granted.

The installation's operating instructions require approval before sending email, changing calendar events, or editing Google Docs and Sheets. These are assistant behavior rules, not a claim that its OAuth permissions are read-only.

How information is used

Information is used to carry out the account owner's requests: finding relevant correspondence, preparing drafts and briefings, organizing records, maintaining task and project context, and performing approved changes. It is not sold or used for advertising.

Local storage and connected services

The assistant runs on the operator's computer. Google OAuth credentials are stored locally, and the assistant may retain local conversation history, working files, and memory. Credentials and private records are not deployed to this public website.

Relevant content may be sent to the configured cloud AI provider, currently OpenAI, to process requests and generate responses. Results or supporting material may also be stored in the operator's connected tools, including Roam Research, Slack, and Todoist, when used for the requested workflow.

These services process information under their own applicable terms and privacy policies. This installation does not claim that all processing stays local or that every provider offers zero retention. Google authorization can include sensitive information in messages, files, or calendar events; only accounts the operator is authorized to connect should be used.

Retention, deletion, and revoking access

Local history, downloaded records, and material saved in connected tools remain until the operator deletes them or the relevant service's retention settings remove them. There is no universal automatic deletion period across these destinations.

The account owner can revoke access at Google Account connections. Revocation prevents future access with that authorization; it does not automatically delete copies already saved locally or in connected services. Contact the operator to request review or deletion of retained information.

This public website

Cloudflare hosts these static information pages. The site has no account system, forms, advertising, or added analytics scripts. Cloudflare may process ordinary connection and security information, such as IP addresses and request metadata, to deliver and protect the site; see Cloudflare's privacy policy.

Do not send passwords, authentication codes, or private records to this website. Google authorization occurs separately through Google's consent flow.

Google API data

Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Contact and updates

Operator: Harpreet Chima. For privacy questions or requests, email harpreet.chima@gmail.com.

This notice will be updated when the installation's described data practices change. The effective date appears above.