LEGAL
Last updated: August 4, 2026
Helm Software, LLC ("Helm," "we," "us," or "our") provides an AI work platform that helps businesses manage clients, projects, and operations. This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data.
This policy applies to gethelm.ai, the Helm application, and any related services (collectively, the "Service"). By using the Service you agree to the practices described here.
If you connect an integration (Google, Slack, GitHub, Stripe, HubSpot, etc.) we receive data from that provider limited to the scopes you authorize. You can revoke access at any time from the provider's settings or from the Integrations page in Helm. See "Google user data" below for the specific Google permissions Helm requests and how we handle them.
When you or your team use Helm's AI agents, chat, or automations, we send relevant workspace content to third-party AI providers (currently Anthropic and OpenAI) to generate responses. That content is not anonymized. It can include names, email addresses, and the text of records, documents, and messages in your workspace, because the request needs that context to produce a useful answer.
These providers act as sub-processors under commercial terms and do not use your content to train their models. They may retain it for a limited period under their own standard retention policies. You can turn AI agents off for your workspace at any time in workspace settings. That stops agent activity. The chat assistant is a separate feature and stays available, so turning agents off does not end all AI processing.
When you connect a Google account to Helm, we request only the permissions needed for the features you turn on. Helm requests these scopes and no others:
gmail.send). Used only to send messages you or your agents compose in Helm from your own mailbox, so replies thread correctly in the recipient's inbox. This scope does not permit reading, listing, or modifying existing mail, and Helm does not request any Gmail read scope.calendar.readonly). Used to import your existing Google Calendar events so they appear alongside your tasks in the Helm calendar.calendar.events). Used to create, update, and delete the events you schedule in Helm so those changes are reflected in Google Calendar.openid, email). Used to confirm which Google account you authorized.What we store. Encrypted OAuth access and refresh tokens, the email address of the authorized account, and identifiers for the messages and events Helm created, so message threading and calendar sync stay accurate. Helm does not copy your mailbox into the Service.
What we never do. We do not sell Google user data, use it for advertising, or transfer it to data brokers. We do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. Human access to Google user data is limited to actions you explicitly request in the product, security purposes such as investigating abuse, and cases where the law requires it.
How to revoke access. Disconnect the account from the integration settings inside Helm, or remove Helm from your Google Account permissions page. Revoking access deletes the stored tokens.
Helm's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We share information only in the following cases:
We do not sell your personal information and we do not share it with third parties for their own marketing.
We retain workspace data for as long as your account is active. When your account is deleted, workspace content is removed from production systems within 30 days and from backups within 90 days, except where longer retention is required by law (for example, financial records).
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, restrict or object to processing, and withdraw consent at any time. You can exercise most rights directly from User Settings. For anything else, email privacy@gethelm.ai and we will respond within 30 days.
California residents. Helm does not sell personal information. You may request disclosure of the categories of personal information we collect and request deletion of your data subject to CCPA/CPRA exceptions.
EEA/UK residents. The legal bases on which we process personal data are performance of a contract, legitimate interests, legal obligation, and consent. You have the right to lodge a complaint with your local supervisory authority.
Helm is operated from the United States and our sub-processors may process data in other jurisdictions. Where required, transfers outside your country rely on Standard Contractual Clauses or equivalent safeguards.
We use first-party cookies and local storage for authentication, session continuity, and remembering preferences such as your theme choice. We also use a limited set of analytics cookies to understand aggregate product usage. You can disable cookies in your browser, though parts of the Service may not function correctly.
We take reasonable administrative, technical, and physical measures to protect your data, including encryption in transit and at rest, role-based access controls, and workspace isolation via row-level security. For more detail see our Security page.
The Service is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, email us and we will delete it.
We may update this policy from time to time. Material changes will be announced by email or in-app notice at least 30 days before they take effect. Continued use of the Service after a change means you accept the updated policy.
Questions or requests? Email privacy@gethelm.ai or write to:
Helm Software, LLC
Attn: Privacy