Hermes-Agent Aitor CM →

Hermes-Agent / Effective September 10, 2026

Privacy policy

This policy explains how Hermes-Agent accesses, uses, stores, and shares Google user data while managing its owner's calendar.

Policy index

  1. Overview
  2. Data accessed
  3. Use
  4. Sharing
  5. Retention
  6. Security
  7. Your control
  8. Changes

1. Overview

Hermes-Agent is a personal tool operated by Aitor CM. It uses Google OAuth to manage the operator's Google Calendar from direct instructions. It is not offered as a public or commercial service.

2. Google data accessed

Hermes-Agent accesses only the Google Calendar data needed to complete an instruction. Depending on the requested action, this may include calendar lists, availability, and event details such as titles, descriptions, dates, times, locations, and attendees.

The application also uses OAuth access and refresh tokens to keep the authorized Google Calendar connection available.

3. How Google data is used

Calendar data is used solely to review availability and to read, create, update, or delete events when instructed by the operator. It is not used for advertising, profiling, or unrelated purposes.

Hermes-Agent's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. AI processing and sharing

Hermes-Agent sends the event details and instructions required for a requested action to OpenAI. OpenAI processes this information to interpret the instruction and produce the structured result needed by Hermes-Agent. This transfer is limited to providing the application's calendar-assistant functionality.

Infrastructure providers may process technical request and security information while operating the application. Google user data is not sold, used for advertising, or shared with unrelated third parties.

5. Storage and retention

Hermes-Agent does not retain copies of Calendar event content after completing a request. OAuth credentials are retained only while needed to maintain the authorized connection. Technical logs may retain request timing, status, and diagnostic information, but are configured not to contain Calendar event content.

6. Security

Access is limited to the application's operator. OAuth credentials are protected from public access, and access to Google data is limited to the permissions configured for Hermes-Agent. No method of storage or transmission is completely secure, but reasonable safeguards are used to protect the connection and its credentials.

7. Access and deletion

Google access can be revoked at any time from the Google Account connections page. Revocation prevents future Calendar access. Stored OAuth credentials can also be deleted by the operator. Privacy questions can be directed through the AitorCM GitHub profile.

8. Changes to this policy

This policy may change if Hermes-Agent's functionality or data practices change. The effective date above identifies the latest version.

Hermes-Agent
Privacy Terms
© 2026 Aitor CM