Privacy Policy
Hermes Agent · Last updated: September 23, 2026
1. Who we are
Hermes Agent ("the app") is a private, self-hosted assistant operated by Green Dental Lab & Clinic, Egypt, for the internal use of its owner. Contact: dactoor2008@gmail.com.
2. Google user data we access
When the account owner signs in with Google and grants consent, the app may access:
- Google Calendar — to read upcoming events and to create, update or delete events the owner asks for.
- Gmail — to read messages in order to identify booking requests and urgent emails, and to create drafts or send replies that the owner requests or approves.
- Basic profile (email address) — to identify which account is connected.
3. How we use it
Google user data is used only to provide the assistant features visible to the owner: summarising the day's schedule, adding appointments, flagging urgent messages and preparing replies. It is processed on demand and is not used for any other purpose.
4. Storage and security
- OAuth tokens are stored encrypted on the app's private server (Hetzner, EU) and are never shared.
- Email and calendar content is not stored permanently; short-lived excerpts may be kept in the assistant's session history to answer follow-up questions and can be deleted at any time.
- To generate responses, relevant text may be sent to the AI model provider configured by the owner (e.g. OpenAI or Google) under their API terms, which do not permit training on this data.
5. Sharing
We do not sell, rent or share Google user data with third parties, and do not use it for advertising. Data is only transferred to the service providers listed above as needed to operate the app, or if required by law.
6. Limited Use disclosure
Hermes Agent's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is not used to develop, improve or train generalized AI or machine-learning models.
7. Retention and deletion
You can revoke the app's access at any time from myaccount.google.com/permissions. On revocation or on request to the contact email, stored tokens and any cached data are deleted within 30 days.
8. Changes
This policy may be updated; the date above will change accordingly.