Max Health — privacy notice
Effective date: 2026-10-02
Operator: Raitox
Contact: Contact@raitox.tech
Purpose and data
Max Health uses Google Health data to answer the account owner's requests and create personal summaries. Read-only scopes cover profile, settings, activity and fitness, health metrics and measurements, sleep, and nutrition. OAuth credentials support access. Do not put credentials in chat.
Data flow
The local connector requests data from Google's Health API. It returns results to Hermes Max. The current structured mode removes identity, GPS, and secret-bearing values from tool results. It retains physiological fields. This filtering does not make the results anonymous.
Cloud processing and replies
Health results can enter Max's cloud AI model context. Max currently uses OpenAI Codex. Provider handling depends on the account, service and settings in use. This notice does not promise that data is excluded from training or deleted after a fixed period.
If a request is made through Telegram, a reply may include health information in that Telegram chat. Telegram stores cloud-chat messages on its servers. Its deletion controls are separate from local Hermes storage.
Local storage and retention
OAuth tokens and client configuration are stored on the Mac. Token files are written with owner-only permissions. The connector uses structured privacy mode, which removes selected identity, GPS and secret fields but retains health measurements.
No connector health-cache database was found during review. Caching is off by default, and no cache override was found in the inspected configuration files.
Hermes retains local conversation state. Automatic session pruning is disabled, so there is no verified automatic deletion deadline. Copies may also exist in memories, exports, logs or backups. These copies require separate review.
Stopping access and deleting copies
Revoke Max Health in Google Account settings to stop future authorized access. The connector's revoke function also removes its local token file. This does not delete the source health records at Google.
To remove local copies, the operator can first review the affected Hermes sessions, then approve their deletion. Hermes supports deletion of session messages and associated transcript files. Memories, exports, logs, caches and backups need separate checks. Archiving a session does not delete it.
Telegram and AI-provider copies use their own deletion controls. Revocation and local deletion do not guarantee that every downstream copy has been removed.
Contact
For questions about data access or deletion, contact Raitox at Contact@raitox.tech. Do not include health records or credentials in an initial support email.