Privacy notice and service-policy draft
NIZAM Hermes Drive
Published 6 October 2026. Pre-release notice: the website disclosures below describe this static site. Intended OAuth-service practices remain a draft, not an effective final service policy or a claim of Google approval.
1. Operator and contact
Operated by Seif ElSherbiny. For questions or privacy requests, email seif.elsherbiny13@gmail.com. The owner monitors this mailbox.
This is a private, single-owner project. No public registration, financial-account connection or Google authorization is offered by these pages.
2. Website delivery and connection information
This website is hosted on Cloudflare Pages. Requests pass through Cloudflare, which processes connection information such as IP addresses, requested paths, timestamps and browser information to deliver and protect the site. See the Cloudflare Privacy Policy for its practices and privacy choices.
The authored pages use static HTML and local CSS. They contain no JavaScript, analytics, advertising, forms, embedded third-party content or Google sign-in. The site has no application backend and does not receive Drive documents, financial records or OAuth tokens through an application interface.
No optional Cloudflare Web Analytics or Functions are included in this release. This does not mean Cloudflare keeps no delivery or security records. No fixed provider log-deletion period, processing country or guarantee of no security cookies is asserted here.
Ordinary external links load the linked provider only when you follow them. That provider has its own privacy practices. Search-engine exclusion requests are not access controls: these pages and the contact address are public.
3. Voluntary email correspondence
Emailing the contact address shares your email address, message and attachments with the operator and Google Gmail, which provides the mailbox. The owner monitors privacy requests. See the Google Privacy Policy for Google's processing.
Do not send passwords, tokens, financial statements or private Drive documents. The website does not read your mailbox or send an email automatically. A contact link opens your mail application; you decide whether to send anything.
No project-specific mailbox retention schedule or automatic deletion deadline has been adopted in this pre-release notice. Messages may remain in the mailbox until removed; Google's own retention and deletion practices also apply. You can ask the owner to review or remove correspondence, but this notice does not promise removal from all provider records or backups or a fixed response deadline.
4. Intended Google Drive access
The intended service uses only https://www.googleapis.com/auth/drive.file. This permits access to app-created and explicitly authorized files, not automatic recursive access to an entire folder or account. Reading, creating, changing and deleting are distinct operations; a scope grant does not establish which operations are implemented or enabled.
Depending on separately approved features, the connector would handle authorization records, file metadata, admitted contents and derived material, and operational or integrity receipts. Secrets, authentication codes, organizational data and strict-local content are excluded by the project's required boundaries. No live data inventory or enabled-operation list is certified by these pages.
5. Proposed use and recipients
The intended purpose is owner-requested use of permitted documents and approved archives. The proposed service commitments are no sale of Google data, no advertising or profiling use, and no use to train or fine-tune generalized AI models. Final adoption and implementation review remain outstanding; these are not promises about a provider's terms or observed runtime behavior.
Google is the intended authorization and Drive provider. Service hosting, messaging, model recipients and their actual data categories, processing locations, retention and controls still require release-specific disclosure. This website notice approves none of them to receive Drive content. Existing credentials or a model configuration do not establish such permission.
Raw financial records must remain outside general assistant/model contexts. Financial calculations must remain deterministic. Cross-agent signals must remain state-only, without figures, dates, identifiers, narratives or sensitive data. These are governing requirements, not live compliance evidence.
6. Proposed storage and security
The intended architecture separates connector credentials from general agent access. NIZAM-managed data written to Drive must be encrypted; keys, tokens and secrets must stay outside Drive, prompts and public source control. Required credential custody, content encryption, archive read-back and recovery are not certified by the metadata-only foundation or this website.
The reviewed foundation has injected metadata ports and in-memory receipts. Its SHA-256 metadata hashing is not content encryption. This description is limited to that reviewed component and is not an audit of every existing integration. No system can promise absolute security.
7. Service retention and deletion remain unresolved
The financial-store contract calls for specified financial history to be retained indefinitely without scheduled pruning, with corrections recorded by superseding entries. That is not a promise to retain all Google data forever or a legal exemption from deletion obligations.
Release-specific retention and deletion for downloaded contents, derived indexes, operational logs, conversations, archives and backups remain unresolved. A verified request-handling and deletion procedure must be established before those practices can be represented by a final service policy. No automatic purge, universal deletion or restoration-safe erasure is claimed.
Deleting a source file from Drive does not necessarily remove application copies. Revoking access does not itself erase previously stored records. Source documents, derived copies, canonical financial history and provider records need separate treatment.
8. Google access controls
You can review and remove application access through Google Account connections. Revocation stops future authorized access after it takes effect, but does not itself delete original Drive files or retained application copies. It may affect multiple integrations represented by the same application connection.
Connector-specific pause, credential removal and retained-data controls still require implementation and release evidence. The website itself has no connection to pause or account permission to revoke.
9. Google API policy and future changes
The proposed service commitment is that NIZAM Hermes Drive's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use. Adoption and actual-behavior review are still required before publishing the final OAuth-service policy.
A future final notice must identify actual enabled processing, recipients, retention and controls and carry its own effective date. New purposes or permissions require the applicable review and authorization before use. Publishing or revising these pages does not grant Google access or activate an application feature.
Return to the NIZAM Hermes Drive homepage.