Privacy Policy
Hermes Bot · last updated 17 September 2026
Hermes Bot is a self-hosted assistant used privately by a small team. This policy describes what data it handles when a Google account is connected to it, and what happens to that data.
Who operates it
The service is operated privately by the team that uses it. Questions and data requests: ideas.n.strategy.group@gmail.com.
What data is accessed
Only data belonging to a Google account whose owner has explicitly granted access through Google's consent screen. Depending on the scopes approved, that can include:
- Gmail — message content and metadata, to search, summarise, draft and send mail at the user's request
- Calendar — events and busy/free times, to report availability and create or amend events
- Drive, Docs, Sheets, Slides — files the account can reach, to read and to create or edit documents
- Tasks — task lists, to read and update items
- Contacts — read-only, to match names to email addresses
Data is accessed only when carrying out an instruction from an authorised user. The assistant does not browse accounts on its own initiative.
Where it is processed and stored
The service runs on a private server rented from Hetzner in Germany. Message history between users and the assistant is stored there so that conversations keep context. Google account content is fetched when needed to answer a request; it is not copied into a separate long-term store beyond what appears in that conversation history.
Third parties
To generate responses, the assistant sends the relevant part of a request — which may include content retrieved from Google services — to the AI model providers it uses, currently Z.AI and OpenAI. That transfer happens solely to produce the output the user asked for, and the content is then subject to those providers' own terms and privacy policies.
Data is not sold, rented, or used for advertising, and is not shared with anyone else.
Retention and deletion
Conversation history is kept only as long as it is useful to the team and can be deleted on request. Revoking access removes the assistant's ability to reach the account's Google data. To request deletion of stored conversation history, write to the address above.
Withdrawing access
Access can be withdrawn at any time, without involving us, at myaccount.google.com/permissions — select Hermes Bot and remove access. This takes effect immediately.
Changes
If this policy changes materially, the date at the top of the page is updated and authorised users are told directly.