Privacy Notice for Z2-1 Hermes
Effective October 5, 2026
This notice describes the personally operated Hermes Agent instance on the owner's home server and its Google Calendar integration. It is intended for the owner, not as a general privacy statement for the Hermes Agent project or for a public service offered to other users.
Google data accessed and purpose
The integration requests the Google OAuth scope https://www.googleapis.com/auth/calendar.events.owned. This allows Hermes to view, create, change, and delete events on Google calendars the owner owns. The current tools read event titles, dates and times, locations, and descriptions. They can add attendee email addresses to an event when the owner explicitly asks Hermes to invite those people. Hermes accesses Calendar data when the owner asks it to perform a Calendar task; it does not run a background calendar-sync job.
Calendar data is used to answer the owner's requests and, when requested, to create, update, or delete Calendar events. It is not used for advertising, sold, or shared for unrelated purposes.
Where data is processed and sent
The Hermes service and Google API connector run on the owner's home server. OAuth client credentials and refresh tokens are stored under the server's encrypted Hermes knowledge volume. Hermes also saves conversation history and tool results in its local session database. A conversation that contains Calendar details can therefore remain in that database according to Hermes' session-retention settings. The database is on the server's Hermes data directory; its protection follows the host's system-disk configuration.
The current Hermes model route uses OpenRouter. When an answer needs Calendar information, Hermes may include relevant event details in a model request sent through OpenRouter to the selected model provider. This transmission is part of providing the requested Calendar assistant feature. OpenRouter's privacy policy says it does not use API inputs or outputs for its own model training; model providers may have separate data practices, so their terms also apply. See the OpenRouter Privacy Policy.
If a local model is selected for a request, processing depends on the active Hermes routing configuration. This notice will be updated if the routing or connected services change. When Hermes is used through Slack, the messages and replies are also handled by Slack under its own privacy terms.
Storage, retention, and choices
The Google OAuth token and client credentials are stored on the encrypted volume on the home server. Conversation messages and tool results are stored separately in Hermes' local session database and are subject to the configured Hermes session-retention and deletion controls. Data already transmitted to Google, OpenRouter, or a model provider is subject to that service's retention and deletion practices; deleting a local Hermes session does not delete copies held by those services.
The owner can revoke Google's access for this app through Google Account third-party connections. The owner can also remove the local OAuth token and delete Hermes session history using Hermes' session controls.
Changes and contact
This notice will be updated if the Calendar scope, storage, or model-routing practices change. For a privacy question, contact the maintainer through the repository Issues page. Do not post private Calendar details in an issue.