Hermes Agent · effective 16 September 2026 · last updated 16 September 2026
This policy explains how Lucas Vidmar ("the operator", "I") handles information accessed through Hermes Agent ("the app"), a private, self-hosted software agent installed on hardware owned by the operator in Buenos Aires, Argentina.
The app has a single user: its operator. It is not distributed, published in any app store, or made available to any other person, and no data from any Google account other than the operator's own accounts is ever accessed. There is no sign-up, no user registration, and no multi-tenant service.
When the operator connects a Google account through Google's OAuth 2.0 flow, the app is granted access to:
Basic account identifiers (email address, name, profile photo URL) are received as part of the sign-in. The app does not request or receive passwords, and the operator's Google password is never handled, stored or transmitted by the app.
Information from Google APIs is used exclusively to carry out the specific requests the operator makes in a conversation with the app — for example, "search for the last email from X and summarise it", "create this calendar event", or "upload this file to Drive". The app:
Language-model processing used to answer a request runs against inference providers chosen by the operator, and only the content minimally necessary to answer the request in progress is sent to them. No Google user data is sent to any provider for the purpose of model training.
Lucas Vidmar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
OAuth access and refresh tokens are stored on the operator's own server, in files with permissions restricted to the operating-system user that runs the app (mode 600). They are never committed to a public repository and never shared. Message and document content is requested from Google on demand at the moment of a request; it may persist locally inside the app's conversation history on that same server, under the same restricted permissions, so that the operator can review what was done.
The app runs on a privately owned server that is not accessible from the public internet except through a Cloudflare Zero Trust tunnel with identity-based access control. Stored tokens are protected by file-system permissions of the host, and access to the server itself requires the operator's own credentials and two-factor authentication.
The app is not directed at children and is not available to anyone other than its operator. It does not knowingly collect information from children.
If this policy changes, the "last updated" date above will be revised and the new version published at this URL.
Lucas Vidmar · [email protected]