1. Operator and scope
Hermes Gmail RO (“the utility”) is privately operated for personal invoice collection and accounting. It is not offered as a public or commercial service. This policy describes how the utility accesses, uses, stores, and shares Google user data.
2. Google data accessed
The utility requests only:
https://www.googleapis.com/auth/gmail.readonly
For Google accounts explicitly authorized by their owner, the utility may access:
- the Gmail account identity used to verify the selected account;
- message metadata such as sender, recipient, subject, date, message identifier, and existing labels;
- message bodies needed to identify approved invoice links or attachments;
- invoice attachments and approved provider-hosted invoice documents; and
- OAuth access and refresh credentials required to maintain authorized read-only access.
The Gmail permission does not authorize the utility to send, reply, forward, delete, archive, label, or change the read/unread state of messages.
3. How Google data is used
Google user data is used only to:
- search for invoice messages from senders specifically configured by the operator;
- validate provider-specific sender, subject, attachment, host, path, and retrieval boundaries;
- retrieve invoice documents;
- extract and verify accounting fields, totals, service periods, and payment or due-date information; and
- create private local invoice files and structured accounting records.
Google user data is not used for advertising, marketing, credit decisions, surveillance, or profiling, and is not sold.
4. Processing and service providers
The utility runs through Hermes Agent on an owner-controlled system. Selected invoice text or rendered invoice pages may be transmitted to the AI inference provider configured in Hermes solely to extract or visually verify accounting information. Such processing is subject to the configured provider’s terms, privacy policy, retention controls, and account settings.
Google user data is not otherwise shared with third parties except when necessary to operate the requested invoice-processing function, comply with law, protect security, or act on the account owner’s explicit direction.
5. Storage and security
OAuth credentials, downloaded invoices, rendered verification images, and accounting records are stored on an owner-controlled system. Credential and artifact files are protected with owner-only filesystem permissions where supported. Email content is treated as untrusted source data; embedded scripts, macros, document actions, QR codes, and instructions are not executed.
6. Retention
OAuth credentials are retained until they are replaced, expire, or are revoked. Invoice documents and accounting records are retained until the operator deletes them for accounting, tax, or personal recordkeeping purposes. Data transmitted to a configured AI inference provider may be retained according to that provider’s terms and the operator’s account settings.
7. Revocation and deletion
An authorized user can revoke the utility’s Google access at any time from Google Account third-party access settings. Revocation prevents future Gmail API access but does not automatically delete previously downloaded local artifacts.
To request deletion of locally stored OAuth credentials, invoices, rendered pages, or accounting records, contact shafrana@gmail.com. Because this is a private owner-operated utility, deletion requests are handled directly by the operator.
8. Google API Services User Data Policy
Hermes Gmail RO’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes to this policy
This policy may be updated if the utility’s data practices, service providers, or authorized Google scopes change. The effective date at the top of this page will be updated when material changes are published.
10. Contact
Privacy questions and deletion requests: shafrana@gmail.com.