Privacy Policy
This policy explains how Hermes Assistant, a privately operated tool within Hermes Agent Factory, processes information when its operator connects an authorized Google account. The public website is informational only. It does not provide sign-in to the assistants, accept files, or run a Google OAuth flow.
1. Who operates the service
Hermes Assistant is personally operated by Dzm Mal, the public-facing name selected by the individual operator. The contact for privacy and data requests is [email protected]. If a processing activity concerns records of a separate business, the responsible business and legal roles must be determined for that activity; this public website does not itself confer rights to business data.
2. Google data we may access
Access depends on the connected account, OAuth permissions and the specific enabled workflow. Authorized functions may process:
- Gmail: message identifiers, headers, senders, subjects, text and relevant attachments for invoice monitoring and authorized correspondence.
- Sheets: invoice tracking rows, status and approved structured workflow records.
- Drive and Docs: specifically authorized files and their contents for retrieval, analysis or approved document actions.
- Calendar and Contacts: events or contact information only if an authorized function requires them.
Not every feature is active and not every permission requested by a previously issued token is required for each feature. The operator intends to reduce access to the least permissions necessary. Google account owners can revoke the application's access at any time.
3. Why and how the data is used
Google user information is used only to deliver an explicitly authorized feature, including locating potential invoices, extracting fields, classifying records, avoiding duplicate processing, updating permitted tracking sheets and sending authorized status notifications. Python components initially process Gmail messages and permitted document text locally. Records may be retained as required to make the workflow reliable and auditable.
4. AI processing and third-party recipients
Some invoice classifications use an external AI-assisted step. The local process selects relevant lines and applies token substitution to certain recognized sender and financial fields before building the model request. The model request can still contain document-derived text, contextual business information and potentially personal information. Tokenization reduces exposure but is not a guarantee of anonymity. Not all records require an AI request.
For this workflow, the configured route is the local Hermes Proxy and Nous Portal (Nous Research), which may use downstream model providers to produce a response. The operator has enabled the Nous Portal Privacy Mode for the account. According to Nous Research's published policy, this setting restricts its storage and use of inference payloads, subject to security, operational and legal exceptions. That setting does not by itself control the practices of downstream model providers. The identity and processing terms of a downstream model may depend on routing and service configuration; no universal zero-retention assurance is made here.
Any transfer of Google Workspace user data for AI processing must be necessary to provide an authorized user-facing feature and comply with Google's Limited Use rules. Google user data is not sold, used for advertising, used to determine creditworthiness, or made available to train or improve generalized/non-personalized AI models. A service provider that cannot meet the applicable restrictions must not be used to process such data.
5. Where information may be stored and for how long
Credentials and workflow state may be held in the operator-controlled Hermes environment. Approved invoice outputs can be written into the connected Google Sheets or other approved documents. Technical logs record service errors and job outcomes; backups support recovery. Standard website connection metadata may be processed by Cloudflare to deliver and protect the public pages.
Information is retained only for the period reasonably needed for the authorized workflow, security, recovery or applicable record-keeping obligations. In particular, invoices or accounting entries can require longer retention under applicable law. OAuth credentials are retained until replaced, revoked or no longer needed. Backup copies may persist until the applicable rotation cycle and cannot always be removed immediately. There is currently no single retention duration that accurately applies to all record categories. For a specific deletion or retention request, contact the operator at the address above.
6. Sharing and Google Limited Use
Information is disclosed only to the connected Google services, necessary infrastructure providers (including Cloudflare for the public website), and the AI processing services described above when an authorized feature requires that disclosure; or when legally required. Use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Access is not granted for unrelated marketing, resale or independent profiling.
7. Security and limitations
Measures include account-based authorization, access restrictions, keeping credentials out of the public site, tokenization of selected values, verification before remote model requests, and protections for system logs. No software or network service can guarantee absolute security or complete anonymization. This informational website does not provide public access to the underlying agents.
8. Your choices and requests
You can review or revoke Google access using Google Account connections. Revoking access stops future authorized API retrieval, but does not automatically erase historical records held for a permitted reason. For questions, access, correction, restriction or deletion requests, email [email protected]. Requests are handled subject to applicable laws and legitimate record-keeping duties.
9. Changes
This policy may be updated when enabled features, service providers or data-handling practices change. Material changes will be disclosed before the relevant feature is enabled, and consent or authorization will be obtained where required.