Hermes Agent · last updated 16 September 2026
Hermes Agent is a private, single-user personal assistant. It accesses one Google account — its owner's — with the owner's explicit consent, solely to carry out tasks the owner requests. The owner is the only data subject. This application does not sell, share, or transfer Google user data to anyone, does not use it for advertising, and does not use it to train or improve machine learning models.
Hermes Agent is operated by Mohammed Alfadl ("the owner") for personal use. It is not a commercial service, has no public sign-up, and is not offered to other users. All questions about this policy or about data handling can be sent to moala057@gmail.com.
The application requests the following Google API scopes, and uses each one only for the purpose stated:
gmail.readonly — to read email so the owner can be briefed on what
needs attention and asked to act on it.gmail.send — to send email on the owner's behalf, only when the owner
explicitly asks it to.gmail.modify — to label, archive, and mark email as read as part of the
owner's inbox triage requests.calendar — to read the owner's calendar and create or update events
when he asks, and to send reminders for upcoming commitments.drive — to access files in the owner's own Drive that he asks it to
work with.documents — to read and edit the owner's Google Docs.spreadsheets — to read and edit the owner's Google Sheets.contacts.readonly — to look up contact details so the owner can be
given accurate information about people he already knows.Google user data is used exclusively to perform the specific task the owner has requested, in the moment he requests it, or to run scheduled jobs he has configured (such as a daily briefing). There is no secondary use of the data.
To function, the application sends the owner's requests to the language-model providers that generate responses. Only the minimum content required to answer a request is sent, and providers are used under terms that do not permit that content to be used for training. Google user data is never provided to any party for their own independent use.
The application runs on a private computer controlled by the owner, reachable only over an encrypted private network. Google credentials are stored encrypted at rest, access is restricted to a single operating-system user, and no Google API endpoint is exposed publicly.
This application is not directed at children and does not knowingly process data belonging to anyone under 13.
If this policy changes, the revised version will be published at this address with an updated date.