Privacy policy
Effective date: October 8, 2026.
Purpose and data accessed
This private integration searches and reads Gmail messages for tasks requested by the account owner. Retrieved information can include message identifiers, labels, senders, recipients, subjects, dates, and message bodies. Access uses Google's gmail.readonly OAuth scope.
Credentials and processing
OAuth credentials are stored separately for each account on the owner's Hermes server, protected by filesystem permissions. Google processes authorization and Gmail API requests. The server's hosting provider supplies the infrastructure. Message content supplied to Hermes may be processed by the AI provider selected for the session. This integration does not route Gmail requests through Composio.
Retention
The reader does not maintain a separate email archive. Credentials remain on the server until removed or replaced. Email content returned to Hermes may remain in Hermes session history, server backups, or AI-provider records according to their configuration and retention practices. Do not assume that closing a chat removes these records.
User controls
The owner can revoke the integration through the Google Account third-party access controls and remove stored credentials and session records from the Hermes server. Revoking Google access stops future authorized Gmail retrieval; it does not erase previously retained session content.
Security and permissions
Only the two selected accounts are configured in the reader. The reader checks each account identity and requires the exact gmail.readonly scope. OAuth files have restricted filesystem permissions. These measures reduce exposure but do not guarantee security of the server or AI processing.
Limited use
Google user data is used only to provide the requested email-reading functionality. It is not sold or used by this integration for advertising. Use of Google user data must adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Contact
Contact the owner using the support email displayed on the integration’s Google consent screen.