Privacy Policy
Effective date: 6 October 2026
This Privacy Policy explains how Hermes Automation (“Hermes”, “we”, or “the system”) accesses, uses, stores, and protects information when its owner connects Google and YouTube accounts to automate the owner's video-production workflow. Hermes is privately operated and is not currently a public sign-up service.
1. Information accessed
When a channel owner authorizes a Google account, Hermes may process:
- OAuth access and refresh tokens needed to maintain the authorization granted by that account.
- YouTube video metadata supplied by the workflow, such as video title, description, tags, privacy setting, and scheduled publication time.
- Upload responses and video identifiers returned by the YouTube API so the workflow can record status and avoid unnecessary duplicate actions.
- Workflow logs and error details needed to operate, diagnose, and secure the automation.
Hermes requests only the Google API scopes configured for the workflow. Its current YouTube publishing integration is designed around the youtube.upload scope. It does not intentionally request Gmail, Google Drive, contacts, or unrelated Google account data for video publishing.
2. How Google user data is used
Google user data is used only to carry out functions the account owner has authorized, including uploading videos, setting video metadata, and scheduling publication to the YouTube channel associated with that authorization. Technical records may be used to troubleshoot failed requests, maintain workflow state, and protect against duplicate uploads.
Hermes does not sell Google user data, use it for advertising, or transfer it to data brokers. Google user data is not shared with third parties except as necessary to make the authorized API request, operate infrastructure selected by the owner, comply with law, or protect the system and its users. Any service provider used in the workflow is expected to process only information needed for its assigned task.
3. Separate channel accounts
GathaVrit and TechSavvy Indian are separate YouTube channels authorized through different Google accounts. Hermes is designed to store and select each channel's authorization independently. A token for one account is not intended to authorize uploads to the other channel.
4. Storage and retention
OAuth credentials and workflow records are stored in the owner's controlled operating environment and are intended to be protected by operating-system access controls. Tokens are not intended to be included in public logs or published source code. Video files, research artifacts, logs, and upload identifiers may be retained for as long as needed for production, scheduling, audit, recovery, or troubleshooting. The owner can delete local workflow artifacts when no longer needed.
5. Security
Hermes uses access separation between channel credentials and limits API access to the configured workflow. No method of electronic storage or transmission is perfectly secure. The owner should protect the Windows account and device, keep credentials private, and revoke authorization if compromise is suspected.
6. Your choices and revocation
The Google account owner can revoke Hermes access at any time through their Google Account security settings under third-party connections. Revoking access prevents future API operations that require the revoked authorization. The owner may also remove the corresponding local token and workflow records. Previously uploaded videos and their publication settings remain subject to the YouTube account's controls.
7. Children's privacy
Hermes is an internal creator-workflow tool and is not directed to children. It does not offer child user accounts.
8. Changes to this policy
This policy may be updated when the workflow, services, or data practices change. The effective date above will be revised when material changes are published. Use of Google data will remain subject to applicable Google API Services User Data Policy and Limited Use requirements.
9. Contact
For privacy questions or requests, contact the operator at gathavrit@gmail.com. This address is also configured as the current Google OAuth user-support contact. The operator should ensure this inbox is monitored for privacy requests and Google verification notices.
This policy describes the intended design of Hermes. Before production launch, the operator must confirm that the deployed system, storage, service providers, and actual data flows match these disclosures.