Luoyichao Hermes Gmail Readonly
Privacy Policy
Effective and last updated: September 7, 2026
This policy covers the personal Gmail integration operated by Luoyichao and this public information website. The integration is intended for the account holder's private use, not for public registration.
1. Google account access
Google OAuth is used to obtain the account holder's consent. The dedicated connector requests only https://www.googleapis.com/auth/gmail.readonly. It does not receive the Google account password.
The integration can access the connected email address, mailbox totals, message and thread identifiers, labels, sender and subject information, timestamps, and message snippets. Read-only access can also permit reading message bodies and attachments when the account holder requests them. Standard search and monitoring scripts use metadata and snippets.
The integration does not request permission to send, modify, archive, or delete email, or to mark messages as read. This connector does not request access to Drive, Calendar, Contacts, or other Google Workspace services.
2. Why data is processed
Google user data is processed to carry out the account holder's email searches, reading requests, counts, summaries, and configured important-mail notifications. Mailbox profile information is also used to check connectivity. Message identifiers and polling timestamps help avoid duplicate notifications.
The integration does not sell Google user data or use it for advertising. Access and transfer of information received from Google APIs are subject to the Google API Services User Data Policy, including its Limited Use requirements. Google user data must not be used to train generalized AI or machine-learning models.
3. Servers and external services
The connector runs on an operator-controlled server. OAuth requests and Gmail API requests are sent to Google. Network traffic may pass through the operator's configured network proxy.
When an account-holder request or configured monitoring workflow invokes an AI model, relevant email information can be included in the request to the configured model provider or API gateway. Summaries and notifications can be sent through the configured private Feishu channel. These services process data under their own terms and the operator's account settings; their retention settings must be considered before enabling these workflows.
Public visitors to this website are not given access to email, OAuth credentials, the private assistant, or any Gmail API endpoint. There is no public account-connection form on these pages.
4. Storage and retention
OAuth access and refresh tokens are stored in private credential files on the connector server. Connector configuration, polling timestamps, and a bounded list of processed message identifiers are also stored locally. The current monitor keeps up to 5,000 processed identifiers.
Email excerpts, summaries, and attachment files may remain in private assistant conversations, generated files, logs, backups, or messaging history after a request. This deployment does not promise an automatic deletion deadline for all such records. Retention in model services and Feishu depends on those services and their configured policies.
Access to the server and credential files is restricted. Credentials and stored email data are not included in this public website. No system can guarantee absolute security.
5. Withdrawal, deletion, and contact
The account holder can withdraw access at any time in Google Account third-party connections. Revocation prevents future authorized Gmail access but does not automatically erase previously generated summaries, downloaded files, conversation history, or service logs.
To disable monitoring or request deletion of stored integration data, contact Luoyichao through the existing private Hermes or Feishu conversation used for this personal integration, or the support contact displayed on the Google consent screen. Records held by Google, a model provider, or Feishu may also need to be managed through the relevant service.
6. This information website
These pages contain public service information only. No advertising, analytics, or tracking scripts are intentionally added to them, and they do not request Gmail data. The hosting and network providers may process ordinary web-request information, including IP addresses, request times, and browser information, to deliver and protect the website.
7. Changes
This policy may be updated when the integration's data handling changes. The date above identifies the latest revision. A change requiring broader Google permissions must go through a separate Google consent flow; publishing this policy does not grant additional permissions.