Privacy Policy
Effective
This policy explains how Chiming Workspace Connector accesses, uses, stores, and shares Google user data.
1. Scope and operator
Chiming Workspace Connector is a private, non-commercial integration operated by Chiming Wang. It connects Google accounts controlled by or personally known to the operator with a self-hosted Hermes Agent installation. It is not offered to the public and does not accept public registrations.
2. Google user data accessed
Depending on the task or configured automation, the connector may access:
- Gmail: message metadata and content, threads, attachments, labels, and sending or mailbox-modification capabilities.
- Google Calendar: calendars, events, attendees, times, locations, descriptions, and related scheduling data.
- Google Drive: files, folders, metadata, permissions, and file content.
- Google Contacts: names, email addresses, phone numbers, and other contact fields, on a read-only basis.
- Google Docs: document metadata and content.
- Google Sheets: spreadsheet metadata, structure, and cell content.
3. OAuth permissions requested
The connector's current Google authorization requests these exact OAuth scopes:
https://www.googleapis.com/auth/gmail.readonlyhttps://www.googleapis.com/auth/gmail.sendhttps://www.googleapis.com/auth/gmail.modifyhttps://www.googleapis.com/auth/calendarhttps://www.googleapis.com/auth/drivehttps://www.googleapis.com/auth/contacts.readonlyhttps://www.googleapis.com/auth/spreadsheetshttps://www.googleapis.com/auth/documents
4. How Google user data is used
Google user data is used only to provide functionality knowingly selected, requested, or configured by the operator. This includes:
- searching, reading, summarizing, drafting, sending, and organizing email;
- running a selective email monitor configured by the operator;
- reading schedules and creating or managing calendar events;
- finding, reading, creating, organizing, sharing, downloading, uploading, or deleting Drive files when directed;
- reading contacts to support personal communication and context;
- reading, creating, and updating documents and spreadsheets; and
- maintaining the operational state needed to avoid duplicate actions and continue configured automations.
The connector does not use Google user data for advertising, profiling for advertising, credit decisions, or sale.
5. Storage and protection
OAuth credentials, configuration, synchronization cursors, action state, operational logs, and task outputs may be stored on the operator's private, self-hosted system. Access is restricted to the operator and the software processes the operator authorizes.
Stored information is retained only for as long as needed for the operator's personal workflows, continuity, security, and recovery. Retention periods may vary with the configured automation and local backup policy.
7. Google API Services User Data Policy
Chiming Workspace Connector's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Operator controls, revocation, and deletion
The operator can stop an automation, delete locally retained data, or revoke the connector's access through Google Account third-party connections. Revocation prevents future access through the revoked authorization but does not automatically delete data already present in local logs, task outputs, or backups. Those copies can be deleted through the operator's local retention and deletion procedures.
9. Security
Reasonable administrative and technical safeguards are used to protect credentials and Google user data. No system can guarantee absolute security, and access may be revoked immediately if misuse or compromise is suspected.
10. Changes to this policy
This policy will be updated if the connector's data practices materially change. The effective date at the top of this page identifies the current version.
11. Contact
Privacy and support questions can be directed to the user-support contact displayed on the connector's Google OAuth authorization screen.