Privacy at Helm

The short version: your business information belongs to you. We built Helm for operators who need to trust the tools they use.

What stays private

Everything you share with Helm — your onboarding answers, files in your Vault, and conversations with your advisors — is private to your account. No other user can see your information. Our team does not read your conversations.

What we never do

We will never sell your data to anyone, for any reason.

We will never share your business information, files in your Vault, or conversations with third parties outside of the infrastructure providers that run Helm.

We will never use your data to train AI models.

The AI training question — answered directly

This is the question we hear most often, so we want to be specific.

Helm uses Anthropic's Claude API to power your advisors. Under Anthropic's commercial API terms, your data is never used to train AI models. This is not an opt-out setting — it is a firm contractual guarantee that applies to all API usage.

This is meaningfully different from consumer AI products. If you use Claude.ai directly on a personal account, Anthropic may use your conversations for model training by default. When you use Helm — which runs on the commercial API — that policy does not apply.

Anthropic also does not retain your conversation content after your request is completed. Data sent to the API is automatically deleted within 7 days.

You can verify this directly in Anthropic's official documentation: platform.claude.com/docs/en/manage-claude/api-and-data-retention

How your data is protected

All data is encrypted in transit using TLS and encrypted at rest. Your Vault and conversations are stored in isolated, per-user storage — completely inaccessible to other Helm users.

Helm is built on Supabase for database and file storage. Supabase is SOC 2 Type 2 certified.

Your rights

You own your data. Full stop.

You can delete any file at any time from your Vault. Deleted files are removed immediately and permanently.

You can delete your account and all associated data by emailing chris@helmteam.app. We will permanently delete everything within 30 days.

Who sees your data

Your Helm advisors (powered by Anthropic's Claude API) process your business context to generate responses. That's it.

The infrastructure providers that run Helm:

Supabase — database and file storage

SOC 2 certified, data encrypted at rest

Anthropic — AI response generation

Commercial API, zero model training on your data

Vercel — application hosting

SOC 2 Type 2 certified

Google Places API — business identity lookup

Used only during onboarding to help you confirm which business is yours. See below for details.

We do not sell your business data, and nothing you put into Helm — Vault documents, financials, conversations — ever reaches an advertising platform. We do use standard marketing analytics (including Meta's Pixel and Conversions API) on our public pages and sign-up flow to measure ad performance. See below for exactly what that sends and where.

Meta Pixel & Conversions API

Helm runs Meta's Pixel (browser-side) and Conversions API (server-side) on our public marketing pages and sign-up flow — never inside the authenticated product itself, and never on anything you enter about your business. They exist to measure whether our advertising is working and to help Meta show our ads to people likely to be a good fit, not to build a profile of your product usage.

What's sent: page views on our marketing pages; when a trial starts and when onboarding finishes; and, for matching purposes only, your email address and account ID — both one-way hashed (SHA-256) before they ever leave our servers, never sent as plain text. We also send your IP address, browser user agent, and the _fbp/_fbc cookies Meta's own script sets, which are not hashed because Meta doesn't treat them as personal identifiers on their own.

This data goes to Meta, is governed by Meta's Privacy Policy, and is separate from — and never combined with — the business data you give Helm to generate advice.

Google Places

If you don't have a website to confirm your business, Helm can look it up on Google Places by name and general location during onboarding. Search results — business names, addresses, categories, and ratings — are requested live from Google and shown to you so you can confirm which listing is actually your business. This data comes directly from Google and is attributed as such wherever it's shown.

We do not store what Google returns. The only thing we keep, and only after you confirm a listing is yours, is Google's internal identifier for that place (a place_id) — not the name, address, rating, reviews, or photos. If you skip this step or don't see your business listed, nothing from Google is stored at all.

Your use of this feature is also subject to Google's Privacy Policy and the Google Maps Platform Terms of Service, both of which are incorporated into this Privacy Policy and our Terms of Service by reference.

A note from the founder

Helm was built for business operators who make real decisions with real information. We know you're sharing things like your P&L, your vendor contracts, and your team structure.

We take that seriously. The commitments on this page are not fine print — they are the foundation that makes this product worth building.

If you ever have a privacy question that isn't answered here, email us directly at chris@helmteam.app and you will get a real response from a real person.

Contact

chris@helmteam.app

Last updated: August 24, 2026

↑ Back to top