Privacy Policy
Pre-release draft describing Helmora's intended data practices. Self-service account export and deletion are not implemented in the current pre-alpha.
At a glance
Helmora is a control surface for AI coding agents. The cloud services need account, device, routing, and operational metadata. Agent content is processed by your app, bridge, local agent runtime, and the model or service you invoke; the managed relay receives an endpoint-encrypted payload rather than protocol plaintext.
- The managed relay does not maintain repository or transcript history. Agent history and repository content are primarily held by your bridge, local runtime, and any provider you invoke.
- Helmora does not train a model on your code, prompts, or outputs. Third-party model providers apply their own terms and data controls.
- We don't sell personal information. No advertising, no data brokers.
- No self-service export or account deletion yet. Pre-alpha requests are handled manually through privacy@helmora.io; automated controls must ship before broader availability.
Scope & controller
This policy describes how Helmora ("we," "us") intends to handle personal information when you visit the Helmora marketing sandbox, use the web or iOS app, pair a bridge, or otherwise use the Service. The data controller is [Legal entity name and registered address — to be filled in by counsel].
Multi-user organization accounts are not part of the current pre-alpha offer. If organization features are introduced, the final policy and agreement must define controller and processor roles rather than inferring them from this draft.
Information we collect
Information you provide
| Category | Examples |
|---|---|
| Account | Name, email, password hash, profile image when supplied by an identity provider, and authentication-session records. |
| Beta waitlist | If you join the waitlist on the marketing site, we store the email address you submit, the time, and which page the form was on — nothing else. It is used only to invite you when the beta opens and to notify the operator that a signup happened; it is deleted on request and is not added to any newsletter. |
| Devices & agents | App and bridge identifiers, display names, platform metadata, pairing state, agent labels, adapter type, project-folder metadata, and presence. |
| Account tier | Current free/pro state and entitlement metadata. There is no public paid offer today; payment details would be documented before billing is enabled. |
| Agent content | Prompts, files, tool output, diffs, questions, and responses are processed by the endpoint app and bridge. On the managed remote path, the relay receives a ciphertext envelope rather than this content in plaintext. |
Information collected automatically
| Category | Examples |
|---|---|
| Network & log | IP address, user agent, request timestamps, connection state, routing identifiers, frame size, errors, and service-health records. |
| Operational usage | Device presence, notification delivery, feature failures, latency, reliability, and bounded usage or metering signals needed to operate the private pre-alpha. |
| Local storage | Browser authentication state and device-local preferences or encrypted caches. See section 8. |
Information from third parties
If you sign in through Google, GitHub, or Apple, the account service receives the profile and account-link data allowed by that sign-in scope. Model-provider and GitHub CLI credentials used by an agent remain on the bridge host; Helmora's current PR-check surface asks the bridge's existing gh session for repository and check metadata, then returns that result to the paired app.
How we use it
We use personal information to:
- Provide, operate, and maintain the Service.
- Authenticate you and protect your account.
- Maintain subscription state and, only if a paid plan is later enabled, process billing under published terms.
- Communicate with you about changes, security issues, and your support requests.
- Diagnose problems, improve performance, and develop new features.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not use your information for advertising, profiling for sale, or any purpose unrelated to operating the Service.
Legal basis (EEA/UK)
The controller, jurisdiction, approved terms, and data inventory are not final, so this placeholder does not establish Helmora's legal bases under the GDPR. Counsel must map each verified purpose to an applicable basis before launch. Candidate categories may include:
- Contract — where processing is necessary to provide an agreed service.
- Legitimate interests — where verified security, abuse-prevention, or product purposes pass the required balancing test.
- Consent — for optional processing where valid consent is collected.
- Legal obligation — where an identified law requires processing.
Code & model training
Helmora does not use your code, prompts, or outputs to train a Helmora model. The agent runtime on your bridge sends the context required for a request to the provider you selected. Helmora does not make a blanket promise about that provider's retention or training practices.
Your subscription, enterprise agreement, API key, local model, and provider settings determine the upstream terms and data controls. Review them before sending sensitive content.
Security
We protect personal information with technical and organizational measures appropriate to its sensitivity:
- TLS on public network paths; local bridge secrets and relay ratchet state are sealed at rest. Production database at-rest controls still require deployment evidence.
- Token-based authentication with rotation; secrets stored in a managed vault.
- Account- and device-scoped authorization at cloud boundaries.
- Automated test, dependency, and secret-scanning checks in the development workflow.
- Pre-release security reporting through the contact below. Independent penetration testing and a reviewed incident-response policy remain launch gates.
No system is perfectly secure. To report a vulnerability, please email security@helmora.io.
Retention & deletion
The final retention schedule has not been approved. Current implementation boundaries that counsel and operations must turn into a documented schedule are:
- Account data — retained while the account is active. Closure and deletion are manual in pre-alpha; no 30-day deletion commitment has been operationally validated.
- Session content — agent history and repository content are primarily held by the user's bridge and agent provider. The managed relay forwards encrypted payloads in memory rather than maintaining a message-history store.
- Cloud metadata and logs — account/device/agent metadata, notification records, subscription state, and operational logs may be retained. Exact periods and deletion jobs must be documented before launch.
- Legal records — billing, fraud, security, and compliance records may need longer retention where applicable law requires it; the controlling jurisdiction is still unset.
Account settings currently do not provide export or account deletion. During the approved pre-alpha, contact privacy@helmora.io for a manual request. Do not advertise automated fulfillment or a fixed response schedule until the workflow is implemented and reviewed.
Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your information ("right to erasure").
- Restrict or object to certain processing.
- Receive your information in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise a right that applies to you, contact privacy@helmora.io. The final policy must state the verified controller, jurisdiction-specific process, identity-verification steps, and legally applicable response periods.
California residents (CCPA/CPRA)
California law may grant rights to know, delete, correct, and opt out of certain "sale" or "sharing" depending on Helmora's final entity and applicability analysis. The current product does not sell personal information or use it for cross-context behavioral advertising; the final policy must state the verified scope and request process.
International transfers
The controller country and complete vendor-region inventory are not yet set. The current pre-alpha uses providers that may process data in other countries. Before launch, Helmora must verify those locations and document any required transfer mechanism; this draft does not claim that Standard Contractual Clauses or another safeguard has already been executed.
Children
The Service is not directed to children under 16. If you believe a child has provided personal information, contact privacy@helmora.io; we will investigate and take the action required by applicable law and the verified deletion process.
Changes to this policy
This non-operative placeholder may change at any time. The final policy must define how material changes are communicated and when an updated policy takes effect. The "Last updated" date above reflects revisions to this draft only.
Contact
Questions, requests, or concerns about your privacy? Reach us at privacy@helmora.io. For security reports, please use security@helmora.io.
Helmora — Privacy Office
[Legal entity name and registered address — to be filled in by counsel]
privacy@helmora.io