HHERMES AUTOMATION
LEGAL & TRANSPARENCY

Privacy Policy

Effective date: 9 October 2026

This Privacy Policy explains how Hermes Automation (“Hermes”, “we”, or “the system”) accesses, uses, stores, protects, and deletes information when its operator connects Google and YouTube accounts to the operator's video-production workflow. Hermes is privately operated and is not currently a public sign-up service.

1. Information accessed

When an account owner authorizes a Google account, Hermes may process:

The production publishing integration requests the https://www.googleapis.com/auth/youtube.upload scope. It uses that permission to upload videos and their metadata to the YouTube channel associated with the authorizing account. It does not intentionally request Gmail, Google Drive, contacts, or unrelated Google account data for publishing.

2. How Google user data is used

Google user data is used only to provide the operator-requested YouTube upload and scheduling workflow, track its results, diagnose failures, maintain workflow state, and prevent duplicate uploads. Hermes does not sell Google user data, use it for advertising, or use it to train generalized AI models.

Google user data is not intentionally disclosed to research, narration, image, or video-generation services. The YouTube API receives the video file and upload metadata as required to perform the upload. Google and YouTube process information under their own terms and privacy policies. No other third party is intended to receive OAuth token contents or raw Google API responses. If the architecture or providers change, this policy will be updated before the changed data flow is used.

3. Where information is stored and who can access it

OAuth token files, production records, and diagnostic logs are stored in the operator-controlled Windows environment on the operator's computer. The workflow is designed to keep the GathaVrit and TechSavvy Indian channel credentials in separate token files and to use each token only for its associated channel. Access to these local files is controlled through the computer's account and file-system permissions. The operator is responsible for securing the computer, its Windows account, and any backups.

The public website provides information about Hermes and its policies; it is not a public account-registration service. Website hosting, DNS, or tunnel providers may process ordinary connection and security metadata when a visitor accesses a website or a remote service. Hermes is not designed to send YouTube OAuth tokens or raw YouTube API responses to those providers.

4. Retention and deletion

To request deletion of locally held information, contact gathavrit@gmail.com and identify the relevant channel or workflow record. The operator will review and action the request within 30 days where the data is under the operator's control. Some information may remain temporarily in backups or be retained where required for security, dispute resolution, or legal compliance. Revoking OAuth access is separate from deleting previously uploaded YouTube videos; those videos remain subject to the YouTube account owner's controls.

5. Security

Hermes separates channel credentials and limits API access to the configured workflow. Local credential files are not intended to be included in public source code, website assets, or ordinary diagnostic output. No electronic storage or transmission method is perfectly secure. The operator should protect the computer, restrict file access, avoid sharing token files, and revoke access promptly if compromise is suspected.

6. Your choices and revocation

The account owner can review or revoke Hermes access through the Google Account settings for third-party connections. Revocation prevents future API operations that require that authorization. The operator can also remove the associated local token and workflow records. Revocation does not automatically delete videos previously uploaded to YouTube.

7. Children's privacy

Hermes is an internal creator-workflow tool and is not directed to children. It does not offer child user accounts.

8. Changes to this policy

This policy will be updated if Hermes's scopes, data uses, storage arrangements, service providers, or retention practices materially change. Google user data will be handled in accordance with the Google API Services User Data Policy and applicable Limited Use requirements.

9. Contact

For privacy questions or deletion requests, contact the operator at gathavrit@gmail.com. This is also the configured Google OAuth support contact.