Privacy Policy

Hermes Agent · effective 16 September 2026 · last updated 16 September 2026

This policy explains how Lucas Vidmar ("the operator", "I") handles information accessed through Hermes Agent ("the app"), a private, self-hosted software agent installed on hardware owned by the operator in Buenos Aires, Argentina.

1. Scope

The app has a single user: its operator. It is not distributed, published in any app store, or made available to any other person, and no data from any Google account other than the operator's own accounts is ever accessed. There is no sign-up, no user registration, and no multi-tenant service.

2. Information the app accesses

When the operator connects a Google account through Google's OAuth 2.0 flow, the app is granted access to:

Basic account identifiers (email address, name, profile photo URL) are received as part of the sign-in. The app does not request or receive passwords, and the operator's Google password is never handled, stored or transmitted by the app.

3. How the information is used

Information from Google APIs is used exclusively to carry out the specific requests the operator makes in a conversation with the app — for example, "search for the last email from X and summarise it", "create this calendar event", or "upload this file to Drive". The app:

Language-model processing used to answer a request runs against inference providers chosen by the operator, and only the content minimally necessary to answer the request in progress is sent to them. No Google user data is sent to any provider for the purpose of model training.

Lucas Vidmar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Storage

OAuth access and refresh tokens are stored on the operator's own server, in files with permissions restricted to the operating-system user that runs the app (mode 600). They are never committed to a public repository and never shared. Message and document content is requested from Google on demand at the moment of a request; it may persist locally inside the app's conversation history on that same server, under the same restricted permissions, so that the operator can review what was done.

5. Retention and deletion

6. Security

The app runs on a privately owned server that is not accessible from the public internet except through a Cloudflare Zero Trust tunnel with identity-based access control. Stored tokens are protected by file-system permissions of the host, and access to the server itself requires the operator's own credentials and two-factor authentication.

7. Children

The app is not directed at children and is not available to anyone other than its operator. It does not knowingly collect information from children.

8. Changes

If this policy changes, the "last updated" date above will be revised and the new version published at this URL.

9. Contact

Lucas Vidmar · [email protected]