Legal · Privacy

Privacy policy

This policy covers hash-hermes, a private integration between a single Google account and a locally-run AI agent. It describes exactly which Google data the integration can reach, what it does with that data, where the data lives, and how access is removed.

Last updated 28 September 2026 · Applies to hash-hermes

01 Scope

One user, one account There are no other users, no sign-up form, and no public interface. The only account this could ever apply to is the one that approves the consent screen.

hash-hermes is an internal tool built by Hashline so that its founder can work with his own Google account through a local AI agent — finding a message, checking a schedule, reading a document, updating a spreadsheet. It is operated by Hashline, Islamabad, Pakistan. It is not offered to the public, and no third party's Google data is processed by it.

This policy applies to the OAuth application named hash-hermes, the desktop OAuth client it uses, and the local agent software that acts on the access it grants.

02 Access

What it can reach Google grants these permissions per service rather than per file, so the list is broad. In practice the agent touches only what the account owner points it at.

  • 01 Gmail. Read, search, label and archive mail, and send mail from the account it is connected to.
  • 02 Google Calendar. Read the calendar to answer questions about the schedule; create or delete an event when asked to.
  • 03 Google Contacts. Read names, email addresses and phone numbers. Read-only.
  • 04 Google Drive. Search, download, upload and organise files, and share a single file when asked to.
  • 05 Google Sheets. Read and write spreadsheets.
  • 06 Google Docs. Read, create and append documents.

No other Google service is requested. The integration cannot create accounts, cannot change account settings, and cannot read anyone else's data.

03 Purpose

What the data is used for One purpose: doing the thing the account owner asked for.

Google data is read only to carry out a direct instruction from the account owner — search this mailbox, summarise this thread, what is on the calendar, read this document, update this sheet, draft a reply. Nothing beyond that instruction is done with it.

  • No advertising or profiling. Google user data is never used to build profiles, target ads, or measure anyone.
  • No model training. Data obtained through Google APIs is not used to train, fine-tune or evaluate machine-learning models.
  • No resale. It is not sold, rented or transferred to anyone.
  • Limited Use. hash-hermes's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
04 Storage

Where the data lives On the account owner's own machine. There is no server component, so there is no infrastructure holding your data.

  • Access token. The OAuth credential is stored as a file in the agent's local configuration directory on the owner's machine. It is never uploaded to Hashline or anyone else, and it refreshes automatically.
  • Data read from Google. Held in memory while a task runs. Excerpts may be written to the agent's local session log on the same machine, so that the owner can read back what it did. That log never leaves the machine on its own.
  • Sharing. Google user data is not disclosed to any third party, except when the account owner expressly asks for an action that involves one — for example, sending a message to a named recipient — or where disclosure is required by law.
05 Retention

Retention and removal Access lasts exactly as long as the owner allows it.

  • Revoke at any time. Removing hash-hermes at myaccount.google.com/permissions takes effect immediately: the refresh token stops working and no further Google data can be read.
  • Delete the local token. Deleting the agent's google_token.json removes the stored credential from the machine as well as the access it carries.
  • Nothing is held elsewhere. Because there is no backend, there is no retained copy to request the deletion of. The local session log can be deleted by the account owner at any point, since it sits on his own machine.
06 Security

How it is protected The smallest surface that will do the job.

  • Transport. All requests go to Google over HTTPS; nothing is proxied through a third party.
  • Credentials. The integration never handles account passwords, payment details or verification codes.
  • Access. The token file sits on the owner's machine under his own filesystem account, and the machine is the boundary.
07 Changes

Changes to this policy A new date, and a note of what moved.

Any material change to what hash-hermes can access, or to what happens with the data, is published here with a new "last updated" date. Since the tool has a single user, the only person affected by a change is the person who reviews it.

08 Contact

Questions Write to us and a person will answer.

Developer contact
Location
Islamabad, Pakistan
App name on the consent screen
hash-hermes