Last updated: 2026-08-04
This policy describes how Hermes ("the Service"), operated by TechNest
at hermes.technest.cloud, handles data when you connect a Google
account.
When you connect a Google account to Hermes, you choose which scopes to grant. Depending on your choice, Hermes may access:
gmail.modify, gmail.send, gmail.readonly)calendar, calendar.readonly)drive.file); broader access is opt-in per account and only offered where consistent with Google's verification requirementsData retrieved from your Google account is used only to carry out actions you or your AI assistant explicitly request in the moment — e.g. searching your inbox, drafting a reply, or checking your calendar. Hermes does not use your data for advertising, does not build behavioral profiles, and does not sell or rent data to third parties.
OAuth tokens are stored encrypted at rest in AWS DynamoDB, accessible only to the Hermes Lambda function under a least-privilege IAM role. Message and file content is fetched from Google's APIs on demand to serve your request and is not permanently copied into Hermes's own storage beyond what's needed for the immediate operation (e.g., pagination state).
We do not share your data with third parties, except:
Tokens and account records are retained until you remove the account from Hermes or revoke access. You can revoke access at any time from Google Account → Security → Third-party access, which immediately invalidates Hermes's ability to access that account.
All traffic to the Service is encrypted in transit (TLS). The Service's own client authorization uses OAuth 2.1 with PKCE, and access is gated behind a PIN and passphrase known only to authorized operators.
The Service is not directed at children under 13 and is not knowingly used to process their data.
If this policy changes materially, the "Last updated" date above will change accordingly.
Questions about this policy: admin@technest.cloud