Privacy & Security Policies
Discover how we safeguard your data, enforce privacy-first controls, and handle information.
1Information Collection & Usage
At Helm, privacy is foundational. We collect only the information necessary to provide you with a reliable, secure daily progress desk:
- Account Information: Your name, email address, profile picture, and authentication credentials provided via our authentication providers (e.g. OAuth).
- Workspace Data: Task logs, work items, project categories, workspace metadata, and attachments created by you and your team members.
- Technical Diagnostics: Anonymized error reports and operational performance metrics required to maintain system stability.
2MCP & AI Privacy Commitments
Helm integrates with Model Context Protocol (MCP) servers allowing local or custom AI assistants to interface with your workspace:
- No Public AI Training: We do NOT sell, rent, or use your private workspace logs or customer content to train public AI models.
- Scoped Access: MCP access tokens are encrypted and strictly isolated to the workspace scope defined by the workspace administrator.
- Local-First Choice: Developers and teams can run self-hosted MCP agents, giving you complete physical control over AI data flows.
3Data Storage & Encryption
We employ modern security best practices to protect your data across all environments:
- Encryption in Transit: All HTTP/WebSocket communication with Helm is encrypted using standard TLS 1.3 encryption.
- Encryption at Rest: Database tables, storage buckets, and secrets are encrypted at rest using AES-256 standards.
- Multi-Tenant Isolation: Workspace data is logically partitioned and protected by strict database access policies.
4Data Retention & Deletion
You maintain full control over your data retention lifecycle:
When a workspace or user account is deleted, associated entries, project tags, and integration connections are permanently removed or anonymized from our primary databases within 30 days.
5Cookies & Local Storage
Helm uses essential session cookies and local storage items required for user authentication, security verification, and active workspace preferences. We do not place third-party advertising tracking cookies.
6Contact Privacy Officer
If you have questions, data subject requests, or privacy concerns, please contact our Data Protection Officer at:
privacy@helm.dev