Legal

Privacy Policy

Last updated:

This Privacy Policy explains how My Personal Assistant (“the app”) accesses, uses, stores and protects Google user data. The app is a personal AI assistant (built on Hermes Agent) that runs only on its owner’s own computer and is used only by its owner. The owner of the app and its sole user are the same person.

In short: there is no backend. OAuth tokens stay on the owner’s machine. Google data is processed locally, in memory, only when the owner asks. Nothing is collected by, stored on, or shared with any server operated by the app. Google user data is never sold, never shared and never used to train models.

Google data the app accesses

The app requests the following Google OAuth scopes. Each is used only to perform actions the owner explicitly asks the assistant to perform.

Google API scopes requested and how each is used
Scope Data accessed and purpose
gmail.readonly Read and search email messages, threads and labels so the assistant can find, summarize and answer questions about the owner’s email.
gmail.send Send email on the owner’s behalf, only when the owner asks the assistant to send a message or reply.
gmail.modify Organize email: apply or remove labels, mark as read or unread, archive, and create drafts. The app does not permanently delete email.
calendar View, create and edit Google Calendar events, for example to check availability or schedule a meeting.
drive Find, open and organize files in Google Drive for document management.
spreadsheets Read and write Google Sheets, for example to look up or update values in the owner’s spreadsheets.
documents Read and write Google Docs, for example to read, draft or edit the owner’s documents.
contacts.readonly Read the owner’s contacts to resolve names to email addresses. Contacts are never modified.

Full scope URLs are prefixed with https://www.googleapis.com/auth/.

How data is handled

Limited Use of Google user data

My Personal Assistant’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Data retention and deletion

Nothing is retained by the app beyond the local token file. Email, calendar, file, document and contact data is not written to disk by the app; it is held in memory only while a request is being handled. Deleting the ~/.hermes directory removes everything the app has stored.

Revoking access

The user (who is also the app owner) can revoke the app’s access at any time at https://myaccount.google.com/permissions. Revoking access immediately invalidates the refresh token, and the app can no longer access any Google data.

Children

The app is a personal tool used only by its adult owner and is not directed at children.

Changes to this policy

If this policy changes, the updated version will be posted on this page with a new “Last updated” date.

Contact

Questions about this policy can be sent to the app owner at admin@boonj.cc.