Hermes Gmail Integration Privacy Policy

Last updated: September 9, 2026

Overview

Hermes Gmail Integration is a private productivity integration operated by Critical Target Testing. It allows authorized users to connect Hermes to Gmail using Google OAuth 2.0.

This Privacy Policy explains how the Hermes Gmail Integration accesses, uses, stores, protects, and shares information received through Google APIs.

Google Account Data We Access

When an authorized user grants access, Hermes may access Gmail information necessary to perform requested functions, including:

  • Email message metadata such as sender, recipient, subject, date, message ID, and thread ID.
  • Email message content when the user requests that Hermes read or process a message.
  • Gmail labels and mailbox state required for authorized mailbox-management actions.
  • Email drafts and replies created at the user’s request.
  • Email attachments when the user requests that Hermes list or save an attachment.

How Google User Data Is Used

Google user data is used only to provide Gmail functionality requested by the authorized user. This may include searching and reading messages, creating drafts and replies, managing selected mailbox actions, and working with attachments.

Hermes does not permanently delete Gmail messages. Sending email requires explicit user authorization. Mailbox-changing actions also require explicit confirmation.

OAuth Credentials

Hermes uses Google OAuth 2.0. OAuth credentials and refresh tokens are stored in protected server locations with restricted file permissions and are used only to authenticate authorized Gmail API requests.

Storage and Retention

Hermes processes Gmail information only as required to perform authorized operations. Operational records or session information may be retained where necessary for system functionality, troubleshooting, security, or recovery.

Email attachments are saved only when the authorized user explicitly requests and confirms the save operation.

Sharing of Google User Data

Critical Target Testing does not sell Google user data.

Google user data is not shared with third parties for advertising, marketing, data brokerage, or unrelated purposes. Information is processed only as necessary to provide and maintain the Hermes Gmail Integration and its authorized functionality.

Artificial Intelligence and Machine Learning

Google Workspace API data obtained through the Hermes Gmail Integration is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.

Google API Services User Data Policy

The Hermes Gmail Integration’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Security

Critical Target Testing uses technical and administrative safeguards designed to protect authentication credentials and Google user data. Access to Hermes configuration and credential files is restricted to authorized systems and users.

User Control and Revocation

Users may revoke the Hermes Gmail Integration’s access to their Google Account at any time through their Google Account security and third-party access settings.

After authorization is revoked, Hermes can no longer access Gmail through the revoked authorization unless the user explicitly authorizes the integration again.

Changes to This Privacy Policy

This Privacy Policy may be updated when the Hermes Gmail Integration, its data practices, or applicable Google API requirements change. The current version will remain publicly available on this page.

Contact

Questions regarding this Privacy Policy or the Hermes Gmail Integration may be directed to the support contact identified for the Hermes Gmail Integration.