Official Documentation

Privacy & Security Policies

Discover how we safeguard your data, enforce privacy-first controls, and handle information.

Last Updated:

1Information Collection & Usage

At Helm, privacy is foundational. We collect only the information necessary to provide you with a reliable, secure daily progress desk:

  • Account Information: Your name, email address, profile picture, and authentication credentials provided via our authentication providers (e.g. OAuth).
  • Workspace Data: Task logs, work items, project categories, workspace metadata, and attachments created by you and your team members.
  • Technical Diagnostics: Anonymized error reports and operational performance metrics required to maintain system stability.

2MCP & AI Privacy Commitments

Helm integrates with Model Context Protocol (MCP) servers allowing local or custom AI assistants to interface with your workspace:

  • No Public AI Training: We do NOT sell, rent, or use your private workspace logs or customer content to train public AI models.
  • Scoped Access: MCP access tokens are encrypted and strictly isolated to the workspace scope defined by the workspace administrator.
  • Local-First Choice: Developers and teams can run self-hosted MCP agents, giving you complete physical control over AI data flows.

3Data Storage & Encryption

We employ modern security best practices to protect your data across all environments:

  • Encryption in Transit: All HTTP/WebSocket communication with Helm is encrypted using standard TLS 1.3 encryption.
  • Encryption at Rest: Database tables, storage buckets, and secrets are encrypted at rest using AES-256 standards.
  • Multi-Tenant Isolation: Workspace data is logically partitioned and protected by strict database access policies.

4Data Retention & Deletion

You maintain full control over your data retention lifecycle:

When a workspace or user account is deleted, associated entries, project tags, and integration connections are permanently removed or anonymized from our primary databases within 30 days.

5Cookies & Local Storage

Helm uses essential session cookies and local storage items required for user authentication, security verification, and active workspace preferences. We do not place third-party advertising tracking cookies.

6Contact Privacy Officer

If you have questions, data subject requests, or privacy concerns, please contact our Data Protection Officer at:

privacy@helm.dev