Privacy Policy
Effective September 7, 2026
Scope
This policy applies to VibeForge Personal Assistant, a private, single-user integration operated by its owner. It is not offered as a service to the public.
Google data accessed
With the owner’s authorization, the integration may access Gmail messages, metadata, labels, and sending functions, plus Google Calendar calendars and events. It requests only the OAuth permissions needed for owner-directed email organization and calendar planning.
How data is used
- Read and summarize email requested by the owner.
- Apply email labels or other mailbox changes only when directed by the owner.
- Read, create, update, or delete calendar information only when directed by the owner.
- Produce owner-requested briefings and scheduled personal routines.
Google user data is not used for advertising, sold, or shared with data brokers. This app’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage and processing
OAuth credentials and working data are stored in the owner’s local Hermes Agent profile on the owner-controlled computer. By default, the configured automation can use a local model. If the owner deliberately selects an external model or service, information included in that request may be processed by that provider under the provider’s terms and the owner’s configuration. This integration does not use Google user data to train a generalized AI or machine-learning model.
Disclosure
Data is disclosed only when required to execute an owner-requested action, to a provider explicitly configured by the owner, or when legally required. The integration does not independently transfer Google user data to unrelated third parties.
Retention and security
OAuth tokens remain on the owner-controlled computer until revoked or deleted. Temporary processing artifacts and logs are retained according to the owner’s local Hermes configuration. Access is restricted through Google OAuth, local device security, and messaging-platform allowlists.
Revocation and deletion
The owner can revoke Google access at Google Account permissions. The owner can also delete the local OAuth token from the Hermes profile. Revocation prevents further API access; locally retained artifacts can be deleted from the owner-controlled computer.
Changes and contact
Material changes will be published on this page with a revised effective date. Questions or deletion requests can be submitted through the project’s public support tracker; sensitive information should never be posted there.