CLOUDKAVE / HERMES

Cloudkave / Hermes

Privacy policy

Effective 6 September 2026

This policy describes the personal-use Hermes Gmail Reader integration operated by Mohit Madaan, and its public information website at cloudkave.com.

Information accessed

After the account holder grants Google permission, the integration can access Gmail message headers, recipients, subjects, bodies, attachments, labels, drafts, and message or thread identifiers. It stores OAuth credentials needed to maintain the authorized connection. It does not ask for or store Google account passwords.

Purpose and use

Gmail data is used to carry out the account holder’s email requests: searching, reading, summarizing, composing, replying, forwarding, organizing, and deleting messages as instructed. Scheduled reviews use message information to identify potentially actionable email and provide private notifications. Full mail access is used for these email-assistance features.

Processing and sharing

The assistant runs on an operator-controlled server. Relevant email information can be included in requests to the AI provider configured in Hermes; this installation uses OpenAI for agent processing. Selected alert information can be delivered to the operator through Telegram. Email sent at the account holder’s request is shared with its intended recipients. These services process information under their own applicable terms and privacy policies.

The operator does not sell Gmail data, use it for advertising, or use it to train a generalized AI model. Gmail data is not published on this information website. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Storage, retention, and security

OAuth credentials are stored in permission-restricted files on the operator’s server and used over encrypted connections to Google. Hermes conversation history, tool results, private alerts, and requested saved files may retain email content until removed by the operator. Service backups or provider retention policies may retain copies for longer. The email action audit records account labels, action types, times, and outcomes rather than message bodies.

The public information website does not require a login or collect mailbox data. Hosting services may process standard request information such as IP address, browser information, and access logs to deliver and protect the website.

Control, revocation, and deletion

The account holder may stop using the integration and revoke its Google connection at Google Account connections. Revocation stops future authorized access but does not automatically remove existing conversation history, Telegram alerts, saved files, or backups. The operator can remove local credentials and stored data, delete applicable alerts, or request deletion through the contact below.

Contact and changes

For privacy questions or deletion requests, contact mohitmadaan@gmail.com. This policy may be updated when the integration’s data practices change; the effective date will be updated here.

Return to app information