HELM — Privacy Policy

Draft — pending owner review before public launch. Last updated June 2026.

What HELM does with your email

HELM connects to email accounts you authorise and processes incoming messages to produce summaries, draft replies and tasks. The AI must read message content to do this work — but before any content reaches an AI model, HELM runs a best-effort de-identification pass that masks the identifying details it can detect (names, email addresses, phone numbers, organisations, and card, bank or government ID numbers), replacing them with placeholder tokens. No automated system catches every identifier, so this is a strong safeguard rather than a guarantee, and the AI still processes the message’s content to do its work. Each message is processed in isolation: the AI holds no memory between messages, and the AI provider does not retain content after responding.

Storage & retention

Email content is stored encrypted at rest and erased automatically according to your configured retention period. One-time passcodes (OTPs) are erased within 24 hours. Credentials for your email accounts are encrypted with AES-256-GCM and are never exposed through any interface.

What we never do

We never sell or share your email, and we never use it to train AI models. Before anything reaches an AI provider, we run a best-effort de-identification pass that masks the personal details we can detect — names, contact details, and financial or government ID numbers — replacing them with placeholders. No automated system catches everything, so we treat this as a strong safeguard, not a guarantee, and the AI still processes your message’s content to summarise and draft. Providers do not retain your content after responding. (This is pseudonymisation — the placeholders map back to the originals on our side — not irreversible anonymisation.)

Your rights

You can export all your data as JSON or permanently delete your account at any time from Settings → Data & GDPR.