Google OAuth verification material

Scope justification

Hermes Gmail follows the principle of least privilege. Scopes must only be enabled when their related feature is actually available.

gmail.send

This scope is used only when a user explicitly asks Hermes to send an email from the user’s own Gmail account. The product presents the intended recipient and message content for confirmation before sending.

gmail.readonly

This scope is used only when a user asks Hermes to search, summarize, or analyze messages in the user’s own Gmail account. The application does not use Gmail data for advertising or sale.

gmail.modify

This scope is used only when a user explicitly requests mailbox actions such as applying labels, marking messages, or archiving. If these features are not available at launch, this scope must not be requested.

Launch decision

The intended launch scope is gmail.send only, with explicit confirmation before every send. Read or modify scopes are not to be requested unless their related function is implemented, tested and explained to users.

Account isolation

Each user authorizes their own Gmail account for their own Hermes profile. OAuth tokens must be isolated by profile and must not be copied between users. The OAuth client credentials identify the application; they do not by themselves grant access to user mailboxes.