Privacy Policy
This page is the privacy policy for two things that share one operator: Hermes, a personal automation assistant that can be connected to a Google account (Part A), and this website, willsun.win (Part B). Both parts are published here, at https://willsun.win/privacy, which is the privacy policy address registered for the Hermes application.
Part A — Hermes (the application)
A1. Who operates Hermes, and how to reach the operator
Hermes is operated privately by:
William Sun
Germany
Email: [email protected]
That email address is the contact point for every question, request or complaint about this policy and about the processing it describes.
A2. What Hermes is
Hermes is a personal automation assistant. It is not a public or commercial service: it has exactly one user — its operator — and it runs on that person's own computer. There is no Hermes server on the internet, no Hermes account to register for, and no way for anybody else to submit data to it. Its operator asks it to carry out tasks, and with the operator's explicit authorisation it can reach the services used to do so, including Google services.
A3. Which Google data Hermes accesses
Hermes can reach a Google account only after the person who owns that account has authorised it themselves on Google's consent screen, and only within the scopes granted there. In the configuration in use today those are:
-
Gmail — read messages, threads and labels; send and reply to
email; mark messages as read or unread and apply or remove labels
(
gmail.readonly,gmail.send,gmail.modify). -
Google Calendar — read the calendars and events, and create or
delete events (
calendar). -
Google Drive — search for files, read and download them, upload
new files, create folders, change sharing permissions and delete files
(
drive). -
Google Docs — read documents and create or edit their content
(
documents). -
Google Sheets — read and write the values in spreadsheets
(
spreadsheets). -
Google Contacts — read the contact list
(
contacts.readonly).
Nothing outside those granted scopes is reachable, and access can be withdrawn at any time (see A10).
A4. Why Hermes accesses that data
Only to carry out tasks that the account's owner has asked for, one at a time — for example: checking and summarising incoming mail, drafting or sending a reply that was requested, looking at what is on the calendar, finding a file in Drive, or reading and updating a named spreadsheet or document. There is no other purpose. Hermes is not used to build profiles, to monitor anybody, or to process the data of anyone who has not connected their own account to it.
The data is processed on the legal basis of consent (Article 6(1)(a) GDPR), given by the account owner on Google's consent screen and withdrawable at any time.
A5. How the data is used
The data is used to answer the request in question and to show the result back to the person who made it. It is read into the assistant's working context for as long as that task takes, and nowhere else. It is not used for advertising, not used for profiling or scoring, not used to train any model by the operator, and not used for any purpose beyond the requested task.
Producing a result requires computation, and Hermes uses a third-party AI model for that. The parts of the content that the task actually needs may therefore be sent to the AI model provider that Hermes is configured with — currently the DeepSeek API (api.deepseek.com) — solely to generate the requested output, and subject to that provider's own terms. What is sent is limited to the content needed for the task at hand.
A6. Whether the data is stored
No Google data is uploaded to any server of mine — there is no such server. Hermes itself is a program on a single personal computer, and the data it reads from Google stays on that machine or is sent straight back to Google's own APIs.
Three things do remain on that computer, locally:
- The conversation record. So that a request can be continued later, the assistant keeps its own working history — including, where it was part of a task, excerpts of the data that task touched — in a local file on the same computer. This record is never published, never uploaded to a service of mine, and is deleted on request.
- Local copies of files. If a task requires a file to be read or produced (a document, a spreadsheet, an attachment, a photograph), a copy may be written to the local disk or saved back to the operator's own Google Drive — the same account it came from.
- Technical logs. Ordinary application logs on the same computer, used for error diagnosis, and rotated away over time.
There is no fixed retention period for the local record, because there is no business need for one: it exists only for the operator's own convenience. Ask for it to be deleted and it is deleted — write to [email protected].
A7. How the Google authorisation (OAuth token) is stored
The authorisation is an OAuth 2.0 token issued by Google: a short-lived access
token and a refresh token that lets Hermes obtain a new access token without asking
the account owner to sign in again. It is stored as a small JSON file on the
operator's own computer, outside this website, in the assistant's local
configuration folder (the file is named google_token.json).
- The token lives only on that machine. It is never published, never embedded in this website, and never transmitted anywhere except to Google's own token endpoint, in order to refresh it.
- Access tokens expire automatically (within about an hour); the refresh token is long-lived and exists only so that access does not have to be re-granted by hand every hour.
- The file is not encrypted — its protection is that it exists solely inside the operator's user account on a single personal computer. Removing the Google authorisation (A10) makes the refresh token unusable and the file can then be deleted.
A8. What is not done with Google user data
- Google user data is not sold or rented, and no money or other value is received for it in any form.
- Google user data is not used for advertising — not for targeted advertising, not for retargeting, not for building advertising audiences, and not for measuring advertising.
- Google user data is not used to determine creditworthiness or for lending, and is not used for any kind of automated decision-making about a person.
- Google user data is not shared or transferred to third parties for their own purposes. It is never passed to data brokers, advertisers, analytics providers or any similar recipient. The only recipients of anything derived from it are the services strictly required to carry out the task that was asked for: Google's own APIs, and — as described in A5 — the AI model provider that produces the requested output. Neither receives it for any purpose of its own.
- Data is not transferred to anyone else's Google account, and this website plays no part in the processing: it is static, sets no cookies, and collects nothing.
A9. Google API Services User Data Policy
Hermes' use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A10. How to revoke Hermes' access to a Google account
Access can be withdrawn at any time, without giving a reason, and it takes effect immediately:
- From the Google account. Open myaccount.google.com/connections (Google Account → Data & privacy → Third-party apps & services), select Hermes and choose Remove access. Google then invalidates the token, and Hermes can no longer read or change anything in that account.
- From Hermes. Ask Hermes to revoke the Google authorisation, or delete the local token file named in A7; the assistant then has no credential left to reach Google with.
- Deleting what remains. Removing access stops future processing. To have the locally stored conversation record and the token file deleted as well, write to [email protected].
A11. Rights, and how to exercise them
The data protection rights described in Part B, section 6, apply here as well — information, correction, erasure, restriction, portability and objection — and so does the right to complain to a supervisory authority. To exercise any of them, write to [email protected].
Part B — This website (willsun.win)
1. Who is responsible for this website
This website at willsun.win is a personal professional landing page. It is operated by:
William Sun
Germany
Email: [email protected]
He is the controller within the meaning of the General Data Protection Regulation (GDPR).
2. Purpose of this website
This site presents professional information about its operator. It has no user accounts, no registration, no newsletter and no contact forms — there is nothing on this site that you can submit personal data to.
3. What data is processed
Access data. When you open this website, the hosting provider technically processes the information your browser transmits, so that the page can be delivered and the service kept secure. This normally includes:
- your IP address
- the date and time of the request
- the page or file requested
- the referring page, where your browser sends one
- your browser type and operating system
Legal basis: Article 6(1)(f) GDPR — the legitimate interest in operating a functioning and secure website. This data is kept only for a limited period and is then deleted or anonymised.
Email. If you write to the address above, your message and your email address are processed in order to answer your enquiry. Legal basis: Article 6(1)(f) GDPR, or Article 6(1)(b) GDPR where the enquiry relates to a contract or its preparation.
4. Cookies
This website sets no cookies of its own and stores nothing in your browser. There is no cookie banner because there is nothing to consent to.
5. Third-party services
This site is delivered through Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA), which provides the hosting, content delivery and network security. Cloudflare processes the access data described above on the operator's behalf and may process it outside the European Union. That transfer is covered by appropriate safeguards, in particular the EU Standard Contractual Clauses and Cloudflare's Data Processing Addendum.
No other third parties are involved. This site uses no analytics, no tracking pixels, no advertising, no social media plugins, no embedded audio or video, no external fonts and no content loaded from any other provider.
6. Your rights
Under the GDPR you have the right to:
- obtain information about the personal data processed about you (Art. 15)
- have inaccurate personal data corrected (Art. 16)
- have personal data erased (Art. 17)
- have the processing of your data restricted (Art. 18)
- receive your data in a structured, portable format (Art. 20)
- object to processing carried out on the basis of legitimate interests (Art. 21)
To exercise any of these rights, write to [email protected].
You also have the right to lodge a complaint with a data protection supervisory authority — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.
The supervisory authority responsible for the operator is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
Telephone: +49 511 120 4500
[email protected]
www.lfd.niedersachsen.de
7. Links to other websites
This site links to external websites, including LinkedIn. Once you follow such a link, the privacy policy of that provider applies. No data is transmitted to those providers unless you actively click the link.
8. Changes to this policy
This policy will be updated if the website or the application changes. The version published here at the time of your visit applies.