Privacy Policy
Application: Hermes Gmail Readonly
Operator: Aerialife Inc.
Hermes Gmail Readonly is a private, owner-operated application. It is used only by authorized account holders to retrieve and process their own Gmail information for private mail-evidence and briefing workflows.
Google data accessed
After an account owner grants explicit Google OAuth consent, the application may access Gmail profile information, message and thread identifiers, labels, headers, message bodies, MIME structure, and attachments needed for the owner-requested workflow.
OAuth permission
The application requests only:
https://www.googleapis.com/auth/gmail.readonly
This permission does not authorize the application to send, delete, modify, label, or mark email as read.
How Google user data is used
Google user data is used only to:
- retrieve mail selected by the authorized account owner;
- verify message and attachment completeness;
- produce private mail evidence, summaries, and briefing outputs requested by the owner;
- maintain audit records needed to prevent omissions and duplicate processing.
Storage and processing
OAuth credentials are stored on an owner-controlled local computer with restricted file permissions. Mail evidence and generated outputs may be retained locally for the owner's private continuity and audit needs.
When the owner requests an AI-assisted briefing, selected data may be processed by the owner's configured AI service provider solely to perform that requested function. It is not supplied for advertising or sold as data.
Sharing and disclosure
Google user data is not sold, rented, or shared with advertisers. It is not used for advertising, credit decisions, or unrelated profiling. Access is limited to the account owner, the owner-operated application, and service providers necessary to perform a function explicitly requested by the owner.
Data may otherwise be disclosed only with the user's consent, when required by law, or when necessary to investigate security abuse.
Retention and deletion
Data is retained only for the owner's private workflow, evidence continuity, and audit requirements. The account owner may request deletion of locally retained Google user data by contacting the operator.
Revoking access
An account owner may revoke access at any time through the Google Account third-party access settings. Revocation stops future Gmail API access.
Security
The application uses OAuth authorization, HTTPS transport, per-account credential separation, restricted local file permissions, and read-only Gmail access. No system can guarantee absolute security, but access is limited to what is necessary for the requested private workflow.
Google API Services User Data Policy
The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.
Contact
For privacy questions, access revocation assistance, or deletion requests, contact: sales@aerialife.com