Privacy Policy
This policy covers the two private applications that use Google sign-in registration
orbit-staging-2facfc: Hermes and Orbit. Both are
operated by Fernando Rodriguez (the operator) for his own use. The only Google accounts connected
are his own. Each statement below describes how the software works today.
1. Google permissions requested
| Application | Permission | Used for |
|---|---|---|
| Hermes | gmail.modify | Read mail, apply labels, archive or restore on instruction, save drafts. Sending is technically possible with this permission, so Hermes blocks it unless the operator approves the specific message. |
| Hermes | calendar | Read events; create, move, update or cancel an event after the operator approves it. |
| Hermes | drive.readonly | Search, read and export files on request. No Drive changes are possible. |
| Orbit | gmail.readonly, openid, userinfo.email | Read mail; identify which account was connected. |
| Orbit | calendar.events.readonly, calendar.calendarlist.readonly | Read events. Built, but not connected today. |
Orbit's code also contains two features that use this registration but have never been
connected: saving Gmail drafts (gmail.compose) and linking a Google Gemini account
(cloud-platform, generative-language.retriever). If either is turned on,
this policy will be updated first.
2. How Gmail data is accessed
Hermes
- On a schedule, Hermes reads recent message headers (sender, recipients, subject, date, labels, read/unread state) and the short preview text Gmail provides.
- It stores the headers. The preview text is used once, in memory, to sort the message, and is not saved. Sorting uses fixed rules written in code; no AI model is used to sort mail.
- When the operator asks about a thread or asks for a reply draft, Hermes reads that thread's text. Draft replies are stored on the Hermes server, and with the operator's go-ahead they can be saved to Gmail Drafts. The text of messages received is not stored in the draft store.
- Labels and archiving are applied only on the operator's instruction. Automatic archiving is turned off.
- Hermes sends an email only after the operator approves that exact message on his private, password-protected control page. The assistant itself cannot approve a send.
Orbit
- Orbit reads full messages from connected accounts. For each message it stores the sender, the To and Cc recipients (Bcc is discarded), subject, labels, timestamps, attachment names and sizes, and the plain-text body, up to 20,000 characters.
- From these, Orbit builds thread summaries and classifications, such as "needs a reply". It does not use an outside AI model to classify mail.
- Orbit never changes, labels, archives, deletes or sends mail.
3. How Calendar data is accessed
- Hermes reads upcoming events from the operator's calendars when building his agenda or answering a question. It keeps no separate calendar copy; events it reads appear in his Hermes conversation history. It creates, moves, updates or cancels an event only after he approves that change.
- Orbit is built to store event titles, times, attendees and locations, but not event descriptions. It is not connected to any calendar today.
4. How Drive data is accessed
- Hermes searches Drive and reads a file only when the operator asks. The text or summary appears in his conversation history. Scanned pages may be turned into images on the server so they can be read. Images older than one hour are deleted the next time a document is opened.
- Hermes cannot create, change, share or delete Drive files.
- Orbit does not use Google Drive.
5. Where data is stored
- Hermes: a private Linux virtual server rented from a hosting provider and used only by the operator. Mail headers, draft replies and conversation history are kept in local databases there. Google sign-in tokens are kept in files only the Hermes service account can read.
- Orbit: Google Cloud, region
us-west1(Oregon, USA): Cloud Run for the service and Cloud SQL (PostgreSQL) for data. Google sign-in tokens are encrypted with Google Cloud Key Management Service, and only the encrypted form is stored. Other secrets are kept in Google Secret Manager. - Results are shown to the operator through his own channels: Hermes's private control page, iMessage and Slack. Summaries he asks for may therefore pass through Apple and Slack.
6. External AI services
- Hermes: when the operator asks about his mail, calendar or files, the relevant content is sent to OpenRouter, which routes it to Google's Gemini model to write the answer. OpenRouter is set to use only providers that do not collect request data. Hermes can also hand a task to an OpenAI model, and Google data reaches OpenAI only if that task includes it.
- Orbit: its "Ask" feature sends Orbit data to Google Gemini through the operator's own Gemini account, and that data may include context derived from mail. Mail classification uses no outside model.
- These providers handle data under their own terms. Neither application trains AI models on Google data, sells it, or uses it for advertising.
7. Data retention and deletion
- No automatic expiry: stored mail records, draft replies and conversation history are kept until the operator deletes them. That applies to Hermes and to Orbit.
- Orbit deletion: Orbit's stored mail is deleted when its connection record or Orbit account record is deleted. Orbit does not yet have a disconnect button.
- Removing access: visit myaccount.google.com/connections, select this app and remove its access. Because both applications share one Google registration, this stops new access by both Hermes and Orbit for that account. It does not delete data already stored. To have stored data deleted, use the contact below.
8. Security controls
- Narrow permissions: Hermes requests only the permissions listed above, and it refuses a Google grant that includes more than it asked for.
- Sending needs approval: Hermes blocks sending email unless the operator approves the specific message. Automatic archiving is off.
- Separate restricted account: Hermes's AI tools run under a separate, restricted operating-system account that cannot read Google tokens.
- Private control page: Hermes's control page accepts connections only from the server itself and requires an access token.
- Orbit: tokens are encrypted with Google Cloud Key Management Service. Sign-in callbacks use HTTPS only.
- No guarantees: no system is perfectly secure. These measures reduce risk but do not guarantee against unauthorized access.
9. Sharing
Google user data is not sold, rented or shared with anyone, except the service providers named above that are needed to run the applications (the hosting provider, Google Cloud, OpenRouter and the AI model providers it routes to, OpenAI when a task is handed to it, Apple and Slack), or where the law requires it.
10. Changes
This page will be updated before either application starts using Google data in a new way. The date at the top shows the latest version.
11. Contact
Fernando Rodriguez: fernando.rodriguez045@gmail.com