Hermes Google Drive privacy
Updated 9 October 2026
Hermes is a private assistant workspace. This page describes its separate Google Drive connection for the workspace owner's personal and Blueprint Google accounts. Connecting either account is optional and requires selecting that account and consenting through Google.
Information accessed and purpose
Google sign-in supplies the account email and a Google account identifier so Hermes can verify the selected account. Hermes requests read-only Google Drive access. This permission allows access to files the selected account can read; Hermes further limits each operation to the account, thread or project and read operation approved by the owner.
Hermes can list file names, identifiers, types, modification dates and links. With separate content approval, it can read bounded text from Google Docs and Slides, selected Sheet cells, and supported PDF or text files. These reads support requested answers, summaries and source-backed Home panels. This connection does not edit, delete or share Google files and does not request Gmail or Calendar access.
Where information goes
OAuth access and refresh credentials are stored in the protected credential holder on the operator's Legion server. Hermes on x1 receives account status and approved results over a signed private HTTPS connection; provider credentials are not returned to the browser or placed in chat.
Approved file metadata and content can enter the workspace's task and language-model processing to carry out the requested work. Results, source receipts, approvals, chat and panel history may be saved in the workspace's durable records. The configured model service may process that information under its own terms; this integration does not establish a provider-wide retention or training policy. The connection has no advertising or data-resale feature.
Retention and controls
Credentials remain available while the account is connected so approved reads can continue after an access token expires. Disconnecting an account in Hermes clears its stored credential from the active connection record, cancels pending connection transactions for that account and invalidates the connection's existing read approvals. A disconnected account's identity, connection status and history remain recorded. Disconnecting does not erase previously saved task, chat, panel, approval or source-receipt history.
This implementation has no automatic fixed retention period or complete account-history deletion workflow. Access approvals expire and are checked again during reads; expiry is an access limit, not a promise that saved records have been deleted. Signing out or stopping a task prevents that task from using its old authorization, but does not disconnect the Google account or erase saved data.
You can also remove Google's authorization through your Google Account connections. Hermes disconnect does not itself call Google's token-revocation endpoint. For questions or a request to review retained workspace data, contact the workspace operator at bogdan@blueprint-ca.ro. A data-review request is not an automatic erasure operation.
Protection and scope
The credential holder requires owner-only files and directories. Reads verify the current workspace owner, selected Google principal, consent generation and approved file operation; content results include source and integrity receipts. PDF and text processing is bounded by file type and size limits. These controls reduce unauthorized access; they are not a guarantee against every security risk.
This page describes this Google Drive connection only. Other independently authorized workspace integrations have separate permissions. See the Google API Services User Data Policy for Google's requirements.