Early Access

Full platform access during Early Access 🚀

Privacy

Privacy Notice

What Helm AI collects, why it collects it, who can see it and what you can do about it — in plain language.

Effective 25 August 2026 · Version 2026-08-25 · Questions: helmaiteams@outlook.com

What we collect

Only what the platform needs to work for your vessel:

  • Account details: name, email address, optional phone number, company and role.
  • Sign-in identity: the identifier and verified email address supplied by Google or Apple when you use social sign-in, including an Apple private relay address if you choose Hide My Email.
  • Vessel data: vessels, equipment, systems, documents, certificates, inventory, maintenance history and improvements you record or upload.
  • Photographs and voice recordings you submit to an assistant, used to produce an interpretation or a transcript.
  • Activity: diagnoses, questions asked, searches, quote and service requests, notifications and Learning Center progress.
  • Approximate location, only when you grant your browser's location permission, used to rank nearby parts and service results.
  • Telemetry you choose to connect: readings sent by a vessel gateway, where you have set one up.
  • Technical data needed to run and secure the service: request timestamps, error reports and rate-limit counters.
  • Website analytics on our public pages: page views and basic interaction events collected through Google Analytics 4.

What we never do

  • We never sell your personal or vessel data.
  • We never use your vessel data to train third-party foundation models.
  • We never show your data to other users, suppliers, providers or partners unless you send them a request.
  • We never store your password — authentication is handled by our authentication provider.
  • We never listen continuously; a voice recording is only created when you press to dictate.

How AI processing works

To answer a question, run a diagnosis or produce a brief, relevant parts of your vessel record are sent to the AI model provider that serves that request, along with your question. The provider processes it to return an answer.

Requests are scoped: the platform sends the vessel, equipment and documents relevant to what you asked, not your entire account, and never another account's data.

Photographs and dictated audio are sent to the model provider that serves that request for interpretation or transcription only, and are not used to train models.

Who can see your data

Access is enforced in the database, not merely hidden in the interface. Your records are reachable by you, by crew or managers you have explicitly invited to that vessel, and — for a specific request you send — by the supplier, provider or expert you sent it to.

A small number of Helm AI administrators can access account records where necessary to operate the service, investigate abuse, restore an archive or comply with the law. Privileged administrative actions require two-factor verification and are recorded in an audit trail.

Processors we rely on

Helm AI runs on third-party infrastructure and uses named service providers, each receiving only the data needed for its function: our cloud platform for hosting, databases, authentication, file storage and managed email delivery; our platform's AI gateway for model inference, transcription and speech; Google and Apple for social sign-in, mediated by our platform's OAuth broker; Brave Search and Tavily for external web and marine-source retrieval when a search reaches outside Helm AI; Google Maps for mapping and place lookup; Sentry for error monitoring; Stripe for payment processing, currently configured in test mode only; and Microsoft Outlook as the human reply mailbox.

A web-extraction provider (Firecrawl) remains configured but is not currently used by any search path.

We use Google Analytics 4 on our public website to measure page views and basic interaction events. It is not enabled on local development, and we do not send your vessel records, documents or diagnoses to it.

Retention

Active account data is kept while your account is open. Deactivating your account moves eligible data into an isolated recovery archive so it can be reconnected if you return; it is not immediately destroyed. Deleting your account permanently, which you do yourself in Account Settings, removes your sign-in and your data in the app instead of archiving it: your profile and roles, vessels, equipment, maintenance logs, checklists and runs, documents, photos and uploaded files, diagnoses, briefs, emerging risks, telemetry history, inventory, parts, quotes, saved vendors, requests and the messages you sent.

Some records are retained after deletion where we are obliged to keep them: administrative audit entries, payment and payout records, completed Helm Expert engagements that also belong to the engineer, and email suppression records so unsubscribe requests keep being honoured. Nothing else about the account is retained.

Your choices

  • Read, correct and export: your data is visible and editable throughout the app, and vessel, maintenance, checklist and inventory reports can be exported as PDF, Word, Excel or CSV. A single combined archive of your whole account is available on written request.
  • Deactivate: close your account at any time from Account Settings, keeping a recovery archive.
  • Delete permanently: Account Settings → Your Account → Delete account permanently. You confirm by typing a phrase, it happens immediately, it removes your sign-in and your data in the app, and it cannot be undone. Records we are obliged to keep are listed under Retention. The same explanation is public, without signing in, on our Account & Data Deletion page at /account-deletion.
  • If you cannot sign in: send a request from /account-deletion or write to us, and we will carry out the same permanent deletion once we have verified that the account is yours. Nobody can delete an account from a public page without that verification.
  • Unsubscribe: every non-essential email carries an unsubscribe link that is honoured immediately.

Security

Traffic is encrypted in transit and data is encrypted at rest by our infrastructure provider. Row-level database policies isolate every account, uploads are validated server-side for type, size and structure before they can be indexed, sensitive endpoints are rate-limited, and two-factor authentication is available to everyone and required for administrators.

Error reports exclude cookies, headers and personal identifiers, and URLs are stripped of query parameters before they leave the browser.

No system is perfectly secure, and we make no certification or audit claims. If you believe you have found a vulnerability, please report it to us before disclosing it publicly.

Contact

Privacy questions, access requests and erasure requests: helmaiteams@outlook.com. We aim to respond within one business day and to resolve requests within 30 days.

If you signed in with Apple using Hide My Email, tell us the relay address you used so we can locate your account.