Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. AI and Automation
  5. Data Sharing
  6. Third-Party Integrations
  7. Data Storage and Security
  8. Data Retention
  9. Your Rights (GDPR)
  10. Cookies
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact and Data Deletion

1 Who We Are

HELM OS is an AI-powered revenue operating system for field sales teams and business owners. We help you manage leads, tasks, pipelines, team communication, and AI-assisted outreach from one platform.

Controller: HELM OS ("we", "us", "our")
Contact: privacy@helmos.io
Platform: helmos.ie

2 Data We Collect

2.1 Account Data

DataSourcePurpose
Email addressRegistrationAuthentication, account management, billing
Display nameProfile setupShowing your identity to teammates
Role and industryOnboardingPersonalising AI recommendations
Revenue goal and ICPOnboardingBuilding your revenue plan and AI context

2.2 CRM and Business Data

DataSourcePurpose
Lead records (names, companies, phone numbers, emails)You enter or importCRM core functionality
Call logs, notes, follow-up datesYou enterSales activity tracking
Pipeline stages and deal valuesYou enterRevenue forecasting
Tasks and prioritiesYou createTask management
Imported CSV or spreadsheet dataYou uploadBulk lead import

2.3 AI Memory Data

HELM's AI brain builds a persistent memory of your business to improve recommendations over time. This includes:

Important: AI memory is scoped to your workspace only. No memory is shared across workspaces or with other HELM users.

2.4 Integration Data (Optional)

IntegrationData AccessedStored?
GmailEmail subject lines and thread context linked to leadsMetadata only — no email body stored server-side
Google CalendarEvent titles, times, and attendees linked to follow-upsMetadata only
Google SheetsLead data you explicitly importImported into your CRM only
AirtableLead data you explicitly importImported into your CRM only

All OAuth tokens are stored encrypted. We request the minimum permissions necessary and never read data you have not explicitly connected.

2.5 Usage and Analytics Data

We collect anonymised usage events (e.g. "dashboard viewed", "AI chat used") to improve product features. This data contains no personal information about your leads or prospects.

2.6 Billing Data

Payments are processed by Stripe. We store only your subscription status, plan tier, and Stripe customer ID — never your card number or payment details.

3 How We Use Your Data

We do not use your lead data, call logs, or AI conversations to train shared AI models. Your business data stays in your workspace.

4 AI and Automation

HELM Brain uses the Anthropic Claude API to generate responses, recommendations, and actions. When you chat with HELM or trigger an AI action:

What HELM AI can see: Only data in your workspace — your leads, tasks, pipeline, and memory. It cannot access other users' workspaces or any external data unless you have explicitly connected an integration.

5 Data Sharing

We never sell your data. We share data only with the following categories of recipients, all bound by data processing agreements:

RecipientPurposeData Shared
SupabaseDatabase and authentication infrastructureAll app data (encrypted at rest)
AnthropicAI inference (HELM Brain)Workspace context included in prompts
StripePayment processingEmail, subscription metadata
NetlifyApp hosting and CDNWeb traffic only (no app data)
Google APIsGmail and Calendar integrations (optional)Only if you connect your Google account

If we are required by law or legal process to disclose your data, we will notify you where permitted.

6 Third-Party Integrations

When you connect external services, those services own privacy policies apply to data held on their platforms. HELM only accesses data from these services when you initiate an action (e.g. "read my inbox"). Relevant links:

7 Data Storage and Security

8 Data Retention

Data TypeRetention Period
Account and CRM dataDuration of account + 30 days after deletion request
AI conversation memoryShort-term: 7 days · Long-term business memory: until you delete it
Billing records7 years (legal requirement)
Anonymised usage analytics24 months
OAuth tokensUntil you disconnect the integration
Error logs30 days

9 Your Rights (GDPR)

If you are located in the EU/EEA or UK, you have the following rights under the General Data Protection Regulation:

To exercise any right, email privacy@helmos.io. We respond to all requests within 30 days.

Data deletion in-app: You can delete your account and all data directly from Settings → Account → Delete Account. This permanently removes all your leads, tasks, AI memory, and workspace data within 30 days.

10 Cookies

HELM OS uses minimal cookies for authentication session management only (Supabase Auth). We do not use tracking cookies, advertising cookies, or third-party analytics cookies that follow you across sites.

CookiePurposeDuration
sb-access-tokenAuthentication sessionSession / 1 hour
sb-refresh-tokenSession refresh7 days

11 Children's Privacy

HELM OS is a professional business tool not intended for users under 18. We do not knowingly collect personal data from minors. If you believe a minor has registered, contact privacy@helmos.io.

12 Changes to This Policy

We may update this policy as we add features. Material changes will be notified by email to registered users at least 14 days before they take effect. The current version is always at helmos.ie/privacy.html.

13 Contact and Data Deletion

For privacy questions, data requests, or to request account deletion: