Legal

Privacy Policy

Pre-release draft describing Helmora's intended data practices. Self-service account export and deletion are not implemented in the current pre-alpha.

Last updated · July 30, 2026 Not effective · pre-release draft v0.3 — draft
!
This is a placeholder draft, not an operative privacy policy. It has not been reviewed by counsel, the controller entity and jurisdiction are still unset, and several operational details below require verification. Do not publish it as final or rely on it for a public launch.

At a glance

Helmora is a control surface for AI coding agents. The cloud services need account, device, routing, and operational metadata. Agent content is processed by your app, bridge, local agent runtime, and the model or service you invoke; the managed relay receives an endpoint-encrypted payload rather than protocol plaintext.

  • The managed relay does not maintain repository or transcript history. Agent history and repository content are primarily held by your bridge, local runtime, and any provider you invoke.
  • Helmora does not train a model on your code, prompts, or outputs. Third-party model providers apply their own terms and data controls.
  • We don't sell personal information. No advertising, no data brokers.
  • No self-service export or account deletion yet. Pre-alpha requests are handled manually through privacy@helmora.io; automated controls must ship before broader availability.

Scope & controller

This policy describes how Helmora ("we," "us") intends to handle personal information when you visit the Helmora marketing sandbox, use the web or iOS app, pair a bridge, or otherwise use the Service. The data controller is [Legal entity name and registered address — to be filled in by counsel].

Multi-user organization accounts are not part of the current pre-alpha offer. If organization features are introduced, the final policy and agreement must define controller and processor roles rather than inferring them from this draft.

Information we collect

Information you provide

CategoryExamples
AccountName, email, password hash, profile image when supplied by an identity provider, and authentication-session records.
Beta waitlistIf you join the waitlist on the marketing site, we store the email address you submit, the time, and which page the form was on — nothing else. It is used only to invite you when the beta opens and to notify the operator that a signup happened; it is deleted on request and is not added to any newsletter.
Devices & agentsApp and bridge identifiers, display names, platform metadata, pairing state, agent labels, adapter type, project-folder metadata, and presence.
Account tierCurrent free/pro state and entitlement metadata. There is no public paid offer today; payment details would be documented before billing is enabled.
Agent contentPrompts, files, tool output, diffs, questions, and responses are processed by the endpoint app and bridge. On the managed remote path, the relay receives a ciphertext envelope rather than this content in plaintext.

Information collected automatically

CategoryExamples
Network & logIP address, user agent, request timestamps, connection state, routing identifiers, frame size, errors, and service-health records.
Operational usageDevice presence, notification delivery, feature failures, latency, reliability, and bounded usage or metering signals needed to operate the private pre-alpha.
Local storageBrowser authentication state and device-local preferences or encrypted caches. See section 8.

Information from third parties

If you sign in through Google, GitHub, or Apple, the account service receives the profile and account-link data allowed by that sign-in scope. Model-provider and GitHub CLI credentials used by an agent remain on the bridge host; Helmora's current PR-check surface asks the bridge's existing gh session for repository and check metadata, then returns that result to the paired app.

How we use it

We use personal information to:

  • Provide, operate, and maintain the Service.
  • Authenticate you and protect your account.
  • Maintain subscription state and, only if a paid plan is later enabled, process billing under published terms.
  • Communicate with you about changes, security issues, and your support requests.
  • Diagnose problems, improve performance, and develop new features.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

We do not use your information for advertising, profiling for sale, or any purpose unrelated to operating the Service.

Sharing & subprocessors

We share personal information only in these circumstances:

  • Subprocessors — vendors that help us run the Service, under data-processing agreements.
  • Model providers — when you invoke a third-party model, your prompt and necessary context are sent to that provider, governed by their terms.
  • Code hosts & identity providers — only as needed to perform operations you initiate.
  • Legal requests — when required by law, subpoena, or court order, after notifying you where legally permitted.
  • Business transfers — in a merger, acquisition, or asset sale, with notice to you.

Draft vendor and data-flow inventory — not verified

VendorPurposeRegion
Fly.ioSandbox web, account, relay, and marketing hostingTo verify
ResendTransactional account emailTo verify
Expo / EAS and AppleiOS build distribution, updates, TestFlight, and APNs deliveryTo verify
SentryClient error reporting when enabled in the shipped buildTo verify
Google, GitHub, AppleOptional account sign-in providersTo verify
Anthropic, OpenAI, and other agent-selected providersModel or tool requests initiated through the local agent runtimeProvider-dependent

This is a working inventory, not a final disclosure. Vendor usage, legal entity names, regions, transfer mechanisms, and data-processing terms must be verified before a canonical subprocessor list is published.

Code & model training

Helmora does not use your code, prompts, or outputs to train a Helmora model. The agent runtime on your bridge sends the context required for a request to the provider you selected. Helmora does not make a blanket promise about that provider's retention or training practices.

Your subscription, enterprise agreement, API key, local model, and provider settings determine the upstream terms and data controls. Review them before sending sensitive content.

Cookies & analytics

We use a small number of cookies and similar technologies:

  • Strictly necessary — for authentication and security. These cannot be disabled.
  • Device-local storage — to remember preferences and hold encrypted caches or transport state on your device.
  • Error reporting — a shipped app build may send technical crash or error information to the configured error-reporting service. The final event inventory and opt-out requirements remain a launch gate.
  • Marketing pageview counts — the marketing pages send a first-party, cookie-less beacon that increments an aggregate counter per day, page path, and referrer domain. No IP address, user agent, cookie, or per-visitor record is stored with it, and internal navigation is not attributed to a referrer.
  • Product analytics — beyond the aggregate pageview counters above, no broader marketing or product-analytics program should be inferred from this draft. Any future vendor, event inventory, consent requirement, and opt-out control must be documented before launch.

We do not use advertising cookies and do not embed third-party trackers on our marketing pages.

Security

We protect personal information with technical and organizational measures appropriate to its sensitivity:

  • TLS on public network paths; local bridge secrets and relay ratchet state are sealed at rest. Production database at-rest controls still require deployment evidence.
  • Token-based authentication with rotation; secrets stored in a managed vault.
  • Account- and device-scoped authorization at cloud boundaries.
  • Automated test, dependency, and secret-scanning checks in the development workflow.
  • Pre-release security reporting through the contact below. Independent penetration testing and a reviewed incident-response policy remain launch gates.

No system is perfectly secure. To report a vulnerability, please email security@helmora.io.

Retention & deletion

The final retention schedule has not been approved. Current implementation boundaries that counsel and operations must turn into a documented schedule are:

  • Account data — retained while the account is active. Closure and deletion are manual in pre-alpha; no 30-day deletion commitment has been operationally validated.
  • Session content — agent history and repository content are primarily held by the user's bridge and agent provider. The managed relay forwards encrypted payloads in memory rather than maintaining a message-history store.
  • Cloud metadata and logs — account/device/agent metadata, notification records, subscription state, and operational logs may be retained. Exact periods and deletion jobs must be documented before launch.
  • Legal records — billing, fraud, security, and compliance records may need longer retention where applicable law requires it; the controlling jurisdiction is still unset.

Account settings currently do not provide export or account deletion. During the approved pre-alpha, contact privacy@helmora.io for a manual request. Do not advertise automated fulfillment or a fixed response schedule until the workflow is implemented and reviewed.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your information ("right to erasure").
  • Restrict or object to certain processing.
  • Receive your information in a portable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise a right that applies to you, contact privacy@helmora.io. The final policy must state the verified controller, jurisdiction-specific process, identity-verification steps, and legally applicable response periods.

California residents (CCPA/CPRA)

California law may grant rights to know, delete, correct, and opt out of certain "sale" or "sharing" depending on Helmora's final entity and applicability analysis. The current product does not sell personal information or use it for cross-context behavioral advertising; the final policy must state the verified scope and request process.

International transfers

The controller country and complete vendor-region inventory are not yet set. The current pre-alpha uses providers that may process data in other countries. Before launch, Helmora must verify those locations and document any required transfer mechanism; this draft does not claim that Standard Contractual Clauses or another safeguard has already been executed.

Children

The Service is not directed to children under 16. If you believe a child has provided personal information, contact privacy@helmora.io; we will investigate and take the action required by applicable law and the verified deletion process.

Changes to this policy

This non-operative placeholder may change at any time. The final policy must define how material changes are communicated and when an updated policy takes effect. The "Last updated" date above reflects revisions to this draft only.

Contact

Questions, requests, or concerns about your privacy? Reach us at privacy@helmora.io. For security reports, please use security@helmora.io.

H

Helmora — Privacy Office

[Legal entity name and registered address — to be filled in by counsel]
privacy@helmora.io