Hermes Agent — Personal Google Workspace Integration
Last updated: 1 October 2026
This policy describes how the Hermes Agent Google Workspace integration ("the integration") accesses, uses, stores, and shares data obtained from Google APIs. The integration is a private, single-user tool. It has exactly one user: its owner and operator, Ronald ("the owner"). It is not offered to the public and has no other users.
The integration requests the following OAuth scopes, and only these:
| Scope | What it allows | Why it is needed |
|---|---|---|
gmail.readonly |
Read Gmail messages and metadata | So the owner can ask the agent to find, summarise, or read their own email |
gmail.send |
Send email as the owner | So the owner can ask the agent to draft and send a reply or a new message |
gmail.modify |
Apply labels, mark read/unread, archive | So the owner can ask the agent to triage and organise their own inbox |
drive |
See, open, and manage the owner's Drive files | So the owner can ask the agent to find and read files they own |
spreadsheets |
Read and write Google Sheets the owner can access | So the owner can ask the agent to read or update their own spreadsheets |
documents |
Read and write Google Docs the owner can access | So the owner can ask the agent to read, draft, or edit their own documents |
calendar |
Read and manage the owner's calendars and events | So the owner can ask the agent to check, add, or change their own events |
contacts.readonly |
Read the owner's Google Contacts | So the agent can resolve names to email addresses when the owner asks it to |
No other Google scopes are requested. The integration does not access Google Photos, YouTube, Google Maps location history, Google Fit, or any other Google product or service.
Google user data is used for exactly one purpose: to carry out a task the owner explicitly requested in a chat session with their own agent. There is no background synchronisation, no periodic polling, no crawling, and no automated indexing of the owner's data.
Google user data is never used for:
The integration stores an OAuth refresh token and access token in a single file on a
private server controlled by the owner:
~/.hermes/google_token.json. The file permissions are restricted to the owner's system
account (chmod 600).
Google message bodies, calendar events, files, and contact records are not copied into a persistent database. They are fetched from the Google API at the moment of a request, used to answer it, and held only transiently in the agent's working memory for that session. Session transcripts may be kept locally on the owner's server so the owner can review their own history; these are stored on the owner's own hardware and are not transmitted anywhere.
Google user data is not shared with any third party. There are no analytics services, no telemetry pipelines, no advertising partners, and no sub-processors receiving Google user data. The only external system involved is the Google API itself, which is the source of the data.
To generate replies, the agent may send the content the owner is currently asking about to the language-model provider that powers the agent. This is necessary for the agent to function and happens only in response to an explicit owner request. The owner configures which provider is used. No Google credentials, tokens, or bulk data exports are ever sent to that provider.
The OAuth token is retained until the owner revokes it. The owner can delete it at any time by removing the token file or by revoking access at https://myaccount.google.com/permissions. Revocation takes effect immediately; the integration will stop being able to reach Google APIs.
Because Google data is not stored in a persistent database, there is no separate Google-data store to purge. Local session transcripts can be deleted by the owner at any time from the server.
The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
This integration is not directed at children and is not used by anyone other than its adult owner.
If the scopes requested, the storage location, or the handling of Google user data changes, this policy will be updated and the "Last updated" date revised.
Owner and data controller: Ronald.
Email: ronaldalexander.radjahaba@gmail.com