Privacy Policy
Last updated: August 24, 2026
1. Introduction
Helm (“we,” “our,” or “us”) operates the Helm financial intelligence platform at helmterminal.dev and the Helm Terminal iOS app. This Privacy Policy covers both. It explains what information we collect, how we use it, and your rights regarding your data. We are committed to protecting your financial information with the same diligence you'd expect from an institutional-grade platform.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Full name (optional)
- Encrypted password (we never store plaintext passwords)
- If you sign in with Apple or Google, we receive your email address and the name those services provide. We use them only to create and identify your account.
Subscriptions & Purchases
If you subscribe on the web, billing is handled by Stripe; we never see or store your card number. If you subscribe in the iOS app, billing is handled by Apple through your App Store account, and we receive purchase history and receipt information via RevenueCat to activate your subscription. We store which plan you are on, never your payment details.
Imported Screenshots (iOS app)
If you use the holdings-screenshot importer, the image you choose is sent to our server and read once by OpenAI to extract the positions in it. Helm does not save the image to your account. OpenAI may retain processed inputs for up to 30 days under its API data policy.
What We Send to AI Providers
Several Helm features are written by AI models run by OpenAI and Anthropic: your daily brief, the research chat, the evidence Helm files against a thesis, and the free stock analysis pages. To produce those, the positions in your portfolio are sent to the provider: tickers, values, weights, unrealized gain or loss, and the name of the institution an account is held at.
Your name, email address and account numbers are not included in those requests. Neither provider uses this data to train its models, and both may retain processed inputs for a limited period under their API data policies. The public stock analysis pages send no personal data at all; they analyze market data only.
Financial Data via Plaid
When you connect financial accounts through Plaid, we receive read-only access to:
- Account balances and account metadata (institution name, account type)
- Transaction history (merchant, amount, date, category)
- Investment holdings (ticker, shares, cost basis)
- Liability information (credit cards, loans)
We never receive or store your bank login credentials. Plaid handles authentication directly with your financial institution. See Plaid's privacy policy for details on their data handling.
Market Data
We fetch publicly available market data (prices, dividends, news, splits) from third-party providers to enrich your portfolio view. This data is not personal information.
Usage Data
We may collect anonymized usage analytics (pages visited, features used) to improve the product. You can disable this in Settings > Data & Privacy.
3. How We Use Your Data
We use your data exclusively to:
- Display your financial dashboard, portfolio, and analytics
- Generate financial insights and intelligence (spending patterns, tax opportunities, risk analysis)
- Detect recurring transactions and subscriptions
- Calculate net worth, financial health scores, and performance metrics
- Send transactional emails (password resets, account confirmations)
- Improve our product and fix bugs
We do not sell, rent, or share your personal financial data with third parties for advertising or marketing purposes. We do not use your data to make credit decisions, insurance underwriting, or employment screening.
4. Data Storage & Security
- All data is stored in Supabase (PostgreSQL) with Row-Level Security (RLS) enforced - you can only access your own data
- All connections use TLS 1.2+ encryption in transit
- Data at rest is encrypted via AES-256 by our infrastructure provider
- Authentication tokens are short-lived JWTs with secure HTTP-only cookies
- Auth events (logins, password changes) are logged for security monitoring
- Rate limiting protects against brute-force attacks
5. Data Retention
We retain your financial data for as long as your account is active. Transaction history and portfolio snapshots are kept to provide historical analytics and trend analysis.
When you delete your account, access is revoked immediately, all personal data is removed from active databases within 24 hours, and purged from encrypted backups within 30 days. See our Data Deletion page for the full timeline.
6. Your Rights
You have the right to:
- Access - Export all your data at any time via Settings > Data & Privacy > Export
- Correction - Update your profile information in Settings
- Deletion - Permanently delete your account and all associated data
- Portability - Download your data in JSON format
- Opt out - Disable analytics and crash reporting in Settings
7. Third-Party Services
Helm integrates with the following third-party services:
- Plaid - Account aggregation and transaction data
- Finazon - Market data, real-time quotes, and historical prices
- OpenAI - AI-powered financial analysis (your query and portfolio context are sent for analysis but never used for model training)
- Anthropic - AI-powered financial analysis (the same portfolio context is sent to write your daily brief and to read filings against your thesis, and is never used for model training)
- Supabase - Database and authentication infrastructure
- Vercel - Application hosting
- Stripe - Web subscription billing
- RevenueCat - iOS subscription management (purchase receipts from Apple)
- Apple & Google - Optional sign-in providers
Each service operates under its own privacy policy and data handling practices.
8. Children's Privacy
Helm is not directed at children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of Helm after changes constitutes acceptance.
10. Contact
For privacy-related questions or requests, contact us at support@helmterminal.dev.