Privacy Policy
Last updated: September 15, 2026
This policy explains how lauroguedes.dev and the personal Google OAuth integration operated by Lauro Guedes through Hermes Agent access, use, store, and share information. The integration is currently intended for the account owner's personal workflows, not as a public software-as-a-service product.
Information processed
The information processed depends on the Google services and permissions authorized by the account owner. It may include:
- Gmail message content, headers, metadata, labels, and message state;
- Google Calendar calendars and event information;
- Google Drive file metadata and file content;
- Google Sheets and Google Docs content when those services are explicitly enabled;
- OAuth account identifiers, access tokens, and refresh tokens needed to maintain the authorized connection.
The integration does not request or store the user's Google password.
How information is used
Google user data is used only to perform workflows requested or configured by the authorized account owner, such as:
- searching, reading, summarizing, drafting, sending, or organizing email;
- reading or managing calendar events;
- searching, reading, creating, or organizing files and documents;
- running explicitly configured personal automations and scheduled digests;
- diagnosing authentication and integration failures.
Google user data is not sold, used for advertising, or used to build advertising profiles.
Service providers and AI processing
Hermes Agent runs on private infrastructure controlled by the account owner. When a workflow asks an external AI model to analyze Google data, the minimum relevant content may be transmitted to the configured model provider solely to complete that request. Local or script-only workflows may process data without sending it to an AI provider. Google and infrastructure providers process information as necessary to provide their respective services.
Google user data is not transferred to unrelated third parties except when required by law, needed to protect the service or account, or explicitly directed by the authorized user.
Storage and retention
OAuth credentials and tokens are stored in owner-restricted files on the private Hermes server and are not committed to public source repositories. Google content is normally processed only for the requested operation. Some explicitly configured workflows may retain source or derived files for a documented period, after which their task-specific cleanup policy applies.
Tokens are retained until they expire, are replaced, are revoked, or are no longer required. Diagnostic logs are designed to exclude passwords, tokens, authorization codes, and other secrets.
Security
Reasonable technical measures are used to restrict access, including owner-only credential permissions, private service access, least-privilege OAuth scopes where practical, and explicit approval requirements for sensitive actions. No system can guarantee absolute security.
Google API Services User Data Policy
The use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including its Limited Use requirements.
Your choices and revocation
The authorized account owner can:
- decline requested OAuth permissions;
- limit the enabled services and scopes;
- ask for stored workflow data to be reviewed or removed, subject to legal and operational requirements;
- revoke the integration from the Google Account's third-party connections page.
Revoking access prevents future Google API requests but does not automatically remove information previously retained by an explicitly configured workflow.
Changes
This policy may be updated when the integration, scopes, providers, or retention practices change. The latest revision date appears at the top of this page.
Contact
Questions about this policy or the integration can be sent tome@lauroguedes.dev.
Read the related Terms of Service or theGoogle OAuth production setup guide.