Hermes · Stephen A

Last updated · September 10, 2026

Privacy policy

This policy describes Hermes Personal Assistant Stephen A, a private assistant operated by Stephen Allinson for his own use.

Google information accessed

With account authorization, the assistant can search and read Gmail messages, including message metadata and body content returned by the Gmail API, and access Google Calendar event details such as titles, times, locations, descriptions and participants.

The configured OAuth scopes are gmail.readonly and calendar.events. Gmail sending and modification are not granted. The Calendar scope technically permits event writes; the assistant’s operating instructions restrict its calendar workflow to reading.

Purpose and use

Relevant information is used to answer Stephen’s requests, prepare briefings, identify commitments, and maintain private tasks and notes. Google data is not sold or used for advertising. The operator does not use Google data to train a general-purpose AI model.

Processing and sharing

Relevant email or calendar content may be included in prompts sent through OpenRouter to the selected inference provider so the assistant can fulfill requests. Provider selection can change. Processing may occur outside Canada; provider retention and processing depend on the selected provider’s terms and the account’s data settings.

Summaries may be delivered to Stephen through Telegram. Saved notes may synchronize through Obsidian Sync. Assistant state and notes are included in encrypted backups stored with FullHost in Canada. These services receive the information needed for their respective functions; private Google content is not published on this website.

Storage and retention

OAuth credentials, assistant sessions, tool results, notes and tasks may be stored on privately managed infrastructure. OAuth credentials are permission-restricted and backups are encrypted. Session history and notes may remain until removed by the operator; there is no single automatic deletion period for all assistant data.

Configured backup retention includes daily, weekly, monthly and yearly snapshots and a separately retained historical baseline. Deleting live data does not immediately remove it from older backups. External services apply their own retention rules.

Access, revocation and deletion

Stephen can disconnect the application through Google Account connections. Revocation stops future authorized Google API access but does not automatically delete previously saved notes, sessions or backups.

For questions or requests to inspect or remove retained application data, contact stephen.allinson@gmail.com. The operator can remove applicable live records and review remaining synchronized or backup copies.

This public website

These pages have no application login, forms, embedded trackers or analytics scripts. Cloudflare hosts the pages and may process connection information, such as IP addresses and request metadata, to deliver and secure them. See Cloudflare’s privacy policy.

Changes

This policy should be updated when the assistant’s Google permissions, data uses or service providers materially change.