Privacy policy

This policy covers Jeremiah’s personal Hermes installation, named Ruby, and its connection to Google services. It does not describe the practices of every Hermes installation.

Data accessed and purposes

With authorization, the assistant may access email content and metadata; calendar lists, events and attendees; task lists and tasks; and Drive file metadata and file content. It uses this data to answer the owner’s questions, prepare summaries and reminders, and perform requested email, calendar, task and file operations. OAuth tokens permit this authorized access.

Processing and sharing

Selected data relevant to a request may be sent to the AI providers configured in Hermes for inference. When the owner uses a messaging integration, requested responses may be transmitted through that messaging platform. The installation is currently configured to use OpenAI for assistant inference and WhatsApp for messaging. Google data is not sold or used by the operator for advertising. The operator does not use Google data to train generalized AI or machine-learning models.

Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and retention

Credentials and refresh tokens are stored in the owner’s local Hermes profile. Conversation history, logs, cached documents, summaries and backups may also retain information used in tasks. Revoking access stops future authorized API access but does not automatically erase previously stored local data or provider records. Local data remains until removed by the owner or applicable retention settings; external processors apply their own retention policies.

Security and your choices

Google credentials are not published on this site. The owner is responsible for protecting the computer, backups and provider accounts. No absolute security guarantee is made. Access can be revoked on the Google Account connections page. To request deletion of local records and saved credentials, contact the operator. Third-party records must be managed through the relevant provider’s controls.

Website

These static pages contain no analytics scripts, login forms or advertising. The hosting provider may process ordinary request logs, including IP addresses.

Contact and changes

Operator: Jeremiah. Privacy questions: Jeremiahjpw@gmail.com. This policy will be updated when the integration’s data practices change.