The HERMES Dashboard ("HERMES", "the app", "we") is a research tool that visualizes network-anomaly detections computed over publicly available M-Lab measurement data in Google BigQuery. This policy explains what data the app accesses when you sign in with Google, how it is used, and how to revoke access.
When you choose to sign in, Google asks for your consent to share the following with HERMES:
openid, email) —
used only to show who is signed in and to label your session in the interface.https://www.googleapis.com/auth/bigquery) — used to execute the
data queries that power the per-event drilldown views. Queries run as you
against the shared M-Lab BigQuery project, so they are billed to and constrained by
your own M-Lab quota. HERMES cannot access any Google data beyond running these
BigQuery queries.HERMES stores the minimum needed to operate and to account for query costs. The complete set of data retained on our servers is:
Query results are processed only in memory to render the visualization you requested, and are never written to disk, to a database, or to a log file. We do not build user profiles or advertising identifiers, we do not sell, rent, or trade personal information, and we do not use any data obtained through Google APIs to develop, improve, or train generalized artificial-intelligence or machine-learning models. Data obtained through Google API scopes is never transferred to third parties except as required by law.
Google user data is used solely to authenticate you and to execute the BigQuery queries you request. It is not used for any other or unrelated purpose.
The sensitive Google user data handled by HERMES includes your Google account information (email address), the OAuth credentials used to authorize BigQuery requests on your behalf, the BigQuery query results returned to your browser, and the query metadata (email address, timestamp, and billed bytes) recorded in the usage ledger. OAuth credentials are never stored, and query results are processed only in memory to generate the requested visualization and are never written to disk, to databases, or to log files. We apply the following safeguards:
Authorization header — never in URLs, query strings, or referrers. All
server-to-Google calls (BigQuery, token introspection) likewise use TLS.openid,
email, and bigquery — the minimum required for sign-in and to
run queries on your own quota. It requests no Gmail, Drive, Calendar, Contacts, or
other Workspace scopes, and it cannot read any Google data outside BigQuery.These protections apply to all Google user data and associated metadata retained by HERMES, including the usage ledger and the application logs that may contain personal information.
If we become aware of a breach affecting personal data obtained through Google APIs, we will investigate immediately, revoke the affected credentials, and notify affected users and Google without undue delay and in any case within 72 hours of becoming aware. Suspected vulnerabilities can be reported to [email protected].
HERMES does not share, sell, rent, trade, or otherwise transfer Google user data to any third party. There is no advertising network, no analytics vendor, no data broker, and no other external recipient in this application. Google user data is never transferred for any purpose other than providing the app's functionality to you. The only exceptions, both inherent to how the app works, are:
The underlying measurement data that HERMES visualizes is public data collected and published by M-Lab under its own privacy policy; it is not derived from your Google account.
You can revoke HERMES's access to your Google account at any time from Google Account → Third-party access, or by clicking Sign out in the app. Revoking access does not affect data already displayed in your current session.
HERMES's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If we change how HERMES accesses, uses, stores, or shares Google user data, we will update this page and revise the "Last updated" date above before the change takes effect. For any material change — a new scope, a new category of data, a new recipient, or a longer retention period — we will additionally notify signed-in users through a notice in the app interface, and where the change requires it, request your consent again through Google. Continued use of HERMES after such a notice indicates acceptance of the updated policy.
HERMES is a research tool built and operated by Loqman Salamatian at Columbia University in collaboration with M-Lab. Questions about this policy, requests for deletion, or any other privacy matter can be directed to [email protected].