Hermes Assistant. Last updated 15 September 2026.
Hermes Assistant is operated by Jozef Cambora as a private, self-hosted tool for his own personal use. There is exactly one user, the operator. The application is not offered to the public and has no other users.
With the operator's explicit OAuth consent, the application accesses:
No other Google data is requested. The application does not access Google Drive, Docs, Sheets, Photos or Contacts.
The application runs on a Raspberry Pi owned by the operator and kept at his home. OAuth tokens and conversation history are stored on that device's local disk, readable only by the dedicated system account the application runs under. No copy of the operator's Google data is kept on any third-party server by this application, and there is no hosted backend, no analytics and no advertising.
To generate replies, the text the operator sends to the assistant, together with any calendar entries or email content relevant to the request, is transmitted to a third-party language-model API (OpenRouter and the inference provider it routes to) over an encrypted connection. This account is configured to use only zero-data-retention endpoints, and to refuse providers that train on request data. Content is processed to produce a response and is not retained by those providers.
Data is not sold, rented, published, or shared with any other party. It is not used for advertising, profiling, or building any product. It is used solely to carry out the tasks the operator asks of the assistant.
This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Conversation history and cached results are retained only while useful to the operator and may be deleted at any time. Revoking access at myaccount.google.com/permissions immediately and permanently ends the application's ability to reach Google data. Local tokens can be destroyed by the operator at will.
The device is not reachable from the public internet. Administrative access is by SSH public key over a private WireGuard network, with password authentication disabled. The application runs as an unprivileged account with no administrative rights.
Material changes will be published on this page with a new date. Questions: jozef.cambora@gmail.com.