Effective date: August 27, 2026
This Privacy Policy explains how Helix Systems LLC (“Helix,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit discoverhelix.com, create an account, or use the Helix web application and related services (collectively, the “Service”). It should be read alongside our Terms of Service.
The Service is built for business use. It is not directed to individual consumers or children, and it is not intended for anyone under 18.
1. Information we collect
Account information. When you sign up, we collect your name, email address, and business/organization details, and we use Supabase to manage authentication and store your account record.
Connected business data. The core of the Service is connecting to systems you choose to authorize, so we can process the data in them on your behalf. Depending on which integrations you connect, this may include:
- Email and calendar data (for example, via Microsoft 365/Outlook, connected directly or through our integration provider, Composio)
- CRM and other business-system data you connect through the Service’s Integrations page
- Financial/banking transaction data, if you choose to connect a bank account via Plaid for business-metrics features
We only access a connected system after you explicitly authorize it, and only to the extent needed to deliver the Service’s features.
Content you provide. Messages, prompts, and other input you send to the Service, including through its AI chat/assistant features.
Usage and log data. Technical logs of how the Service is used (for example, which tools or features were called and when), used for debugging, security, and reliability. Sensitive fields in these logs are redacted before storage.
Cookies. We use a small number of strictly necessary cookies to keep you signed in (session/authentication cookies set by Supabase Auth). We do not use third-party advertising or cross-site tracking cookies on the Service.
2. How we use information
We use the information described above to:
- provide, operate, and maintain the Service, including AI-driven triage, summarization, and recommendations on the business data you connect;
- authenticate you and secure your account;
- provide support and respond to your requests;
- monitor, debug, and improve the reliability and security of the Service; and
- comply with legal obligations.
We do not use your Customer Data to train or fine-tune AI models. Data you connect is processed only to deliver the Service to you — see Section 4 of our Terms of Service.
3. How we share information
We do not sell your information. We share it only as follows:
- Service providers (subprocessors). Companies that help us operate the Service under contractual confidentiality and data-protection obligations, including:
- Supabase — database, authentication, and storage infrastructure
- Vercel — application hosting
- Anthropic — the AI model provider used to power the Service’s AI features
- Microsoft — when you connect Microsoft 365/Outlook, for access to that mailbox via Microsoft Graph
- Composio — as an integration layer for connecting certain third-party business systems
- Plaid — if you choose to connect a bank account, for retrieving the resulting transaction data
- Resend — delivery of account-related emails (for example, sign-in and verification emails)
- Legal and safety reasons. If required by law, legal process, or to protect the rights, property, or safety of Helix, our users, or others.
- Business transfers. If Helix is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a policy at least as protective.
4. Data retention and deletion
We retain your account information and connected business data for as long as your account is active, so we can provide the Service. If you close your account or terminate the Service, we retain your data for 30 days to allow export, then delete it from active systems, except where we are required to retain it for legal, tax, or accounting purposes.
You can request earlier deletion of your data at any time by contacting us (Section 8).
5. Data security
We use administrative, technical, and organizational measures designed to protect your information, including encryption in transit, access controls, and redaction of sensitive fields in internal logs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Your rights and choices
Depending on where you’re located, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing (for example, under the California Consumer Privacy Act or, for individuals in the EU/UK, the GDPR). You can exercise these rights by:
- managing your connected integrations directly within the Service (disconnecting an integration revokes Helix’s access to it); or
- contacting us at info@discoverhelix.com.
If the Service processes data on behalf of a business customer (for example, data about that customer’s own employees or contacts), individuals should generally direct requests to that business, and we will assist our customer in responding as needed.
7. International data transfers
We are based in the United States and primarily process data in the United States through the service providers listed in Section 3. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have different data-protection laws than your jurisdiction.
8. Contact us
Questions about this Privacy Policy can be sent to:
Helix Systems LLC info@discoverhelix.com
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide notice by email or through the Service before the change takes effect. We will not retroactively expand how we use previously collected data (for example, to train AI models) without providing clear notice and, where required by law, obtaining your consent.