Skip to the policy
bunad hermes
  • Privacy
  • Terms
  • Contact

Privacy policy

Last updated: August 27, 2026

On this page
  • Scope
  • Google data
  • How it is used
  • Processing and sharing
  • Storage and retention
  • Your choices

This policy explains how Bunad Hermes Agent accesses, uses, processes, stores, and deletes information from Google accounts. Bunad Hermes Agent is a private, self-hosted personal assistant operated by Bernard G. Tapiru, Jr. Questions can be sent to [email protected].

Who and what this policy covers

This policy covers Google accounts that Bernard explicitly authorizes for use with his private Hermes instance, including his personal Google account and an Ateneo de Manila University account he is permitted to use. It does not authorize access to another person's account without their permission.

The public website you are reading is hosted on Cloudflare Pages. It serves only the homepage, this privacy policy, the terms, and static assets. It does not sign users in, call Google APIs, or receive Google Workspace content from the Hermes integration.

Google data the integration can access

The exact access available depends on the account and permissions Bernard approves on Google's consent screen.

Gmail

  • Messages, threads, message headers, bodies, attachments, and search results.
  • Labels and label membership.
  • Drafts needed for review or preparation.
  • Categorization filters and filter settings.

By design, this integration cannot send Gmail messages and does not delete Gmail messages or drafts. Categorization filters are limited to organization, and creating or deleting a filter requires Bernard's confirmation.

Google Calendar

  • Calendar names, settings, and calendar-list membership.
  • Events, times, descriptions, locations, attendees, and availability.
  • Changes Bernard requests, including creating, updating, or deleting events.

Calendar actions that invite, notify, remove, or otherwise affect another person require confirmation before they are made.

Google Drive, Docs, and Sheets

  • File and folder names, IDs, types, ownership, timestamps, and other metadata.
  • File, document, and spreadsheet contents needed for a request.
  • Permissions and sharing information.
  • Edits, uploads, downloads, folder creation, and other changes Bernard requests.

Sharing a file, changing permissions, or deleting a Drive item requires confirmation. Deletion uses the reversible trash operation unless Bernard explicitly approves permanent deletion.

Google Contacts

The integration can read names, email addresses, phone numbers, and related contact details so it can identify people relevant to a request. Contact access is read-only.

How Google data is used

Google user data is used only to provide functions Bernard asks for, such as:

  • finding, reading, summarizing, and organizing email;
  • preparing drafts and categorization rules for review;
  • checking requirements, announcements, schedules, and due dates;
  • viewing and managing calendar events;
  • finding, reading, creating, or editing files and documents;
  • identifying a contact involved in a request; and
  • maintaining local conversation context, memory, or files that Bernard requests.

Google user data is not sold, used for advertising, used for surveillance, or used to build unrelated profiles. Bunad Hermes Agent does not use Google user data to train or improve a generalized artificial intelligence or machine-learning model.

Bunad Hermes Agent's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Read the Google API Services User Data Policy.

Processing and sharing

The normal data path is:

  1. Google authorization. Bernard grants specific permissions through Google's OAuth consent screen.
  2. Private Hermes server. Google APIs return only the information needed for the operation Bernard requested.
  3. Model processing when necessary. Content needed to understand or fulfill an explicit request may be sent to the configured model provider, currently OpenAI.
  4. Result and local context. The result returns to Bernard, and requested information may be stored in local conversation history, memory, or files.

OpenAI processes submitted content to provide the requested model response under the operator's account and applicable service terms. Hermes sends only the content reasonably needed for the task. Cloudflare Pages is not in this Google-data path.

Bernard may view the data while using, maintaining, or troubleshooting his own assistant. Service providers may process data only as needed to host, secure, or operate the services Bernard has configured. Data may also be disclosed when required by law, to address a security incident, or when Bernard explicitly directs it. It is not otherwise shared with third parties.

Storage, retention, and deletion

OAuth tokens and operational state are stored on the private self-hosted Hermes server, not in this public repository or on this public website. Tokens remain until access is revoked, the account is disconnected, the token expires, or the local credentials are deleted.

Data fetched for a single operation may be transient. When a request places Google data into local conversation history, memory, documents, or other files, that copy can remain until Bernard deletes it or it is no longer needed for the purpose for which it was stored.

To request deletion of locally retained Google data, email [email protected] and identify the account and data to remove. Bernard will remove the requested local copy unless retention is required by law or needed to resolve a security issue. Deleting local data does not delete the source data in Google unless a separate, confirmed Google action is requested.

Security

The integration uses Google's OAuth flow rather than collecting Google passwords. The private server uses access controls, restricted secret handling, HTTPS in transit, and limited scopes and confirmations where practical. No internet-connected system is perfectly secure. Suspected unauthorized access or another privacy incident should be reported promptly to [email protected].

Your choices and controls

Review or revoke Google access

You can review or revoke the app's Google Account access at Google Account permissions. Revocation prevents future API access but does not automatically erase local copies already created for a request. Use the deletion contact above for those.

Disconnect locally

Bernard can also remove the relevant OAuth token and account configuration from the private Hermes server. This stops that local integration from making further requests with the removed credentials.

Changes to this policy

This policy may change when the integration, its Google permissions, or its service providers change. The updated policy will be posted here with a new date. Material changes to how Google user data is used or shared will be made clear before the new practice is used when notice is reasonably possible.

Contact

Privacy questions, deletion requests, or security reports can be sent to [email protected]. The operator is Bernard G. Tapiru, Jr.

Bunad Hermes Agent is operated by Bernard G. Tapiru, Jr.

Home Privacy Terms [email protected]