Hermes Workspace Tools
Privacy Policy
Last updated: August 22, 2026
This policy explains how Hermes Workspace Tools, a private personal automation app operated by Christopher Winig, accesses, uses, stores, and shares Google user data. The app is not offered to the public and is used only by Christopher Winig with his own Google account.
Limited Use: Hermes Workspace Tools’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google data accessed
Depending on the workflow explicitly authorized by the owner, the app may access:
- Gmail: messages, threads, headers, labels, attachments, drafts, and sending or modifying mail.
- Google Calendar: calendars, events, attendees, and event details.
- Google Drive: file and folder metadata and file contents.
- Google Docs and Sheets: document text, spreadsheet values, and related metadata.
- Google Contacts: names, email addresses, phone numbers, and contact metadata.
- Basic account information: the authenticated account’s email address and identity information needed to connect the account.
How Google data is used
Google user data is used only to complete personal productivity actions requested or configured by Christopher Winig. These actions may include searching and summarizing email, preparing or sending owner-approved replies, organizing messages, reviewing calendars, managing files, reading or updating documents and spreadsheets, and looking up contacts.
Google user data is not sold, used for advertising, used to build marketing profiles, or used to train generalized artificial intelligence or machine-learning models.
Data sharing
Google user data is not shared with unrelated third parties. Data may be transmitted only to service providers needed to run an owner-requested workflow:
- Google APIs, to retrieve or update the owner’s Google Workspace data.
- Private hosting and storage infrastructure controlled by the owner, to run the app and retain workflow data.
- AI service providers selected and configured by the owner, such as OpenAI or Anthropic, when an explicit workflow requires language processing.
These providers receive only the data needed for the requested task. Access is not granted for advertising, independent profiling, resale, or generalized model training.
Storage and protection
The app runs on private, access-controlled systems operated for the owner. OAuth credentials and tokens are stored in restricted credential files or secret stores, are not published in application code, and are transmitted over encrypted connections. Access is limited to the owner and the software components required to perform authorized workflows.
Retention and deletion
Temporary API responses, caches, and operational logs are retained only as needed to operate and troubleshoot the app and are periodically pruned. Workflow outputs, local copies, and derived personal knowledge may be retained on the owner’s private systems until the owner deletes them.
Because Christopher Winig is the app’s only user and operator, he can delete stored data directly, disconnect the Google account, or revoke the app’s access at any time through Google Account permissions. Deletion requests may also be sent to chris.winig@gmail.com. Requests will be handled within 30 days.
Changes
This policy may be updated if the app’s data access or processing changes. The current version and its effective date will remain published on this page.
Contact
Christopher Winig
chris.winig@gmail.com