Helm

Privacy & data handling

Last updated 25 August 2026

Helm is a learning tool for mapping how your work gets done. This page explains exactly what it stores, who processes it, and how to get it back or delete it.

What we collect

Only what you type into Helm, plus basic account and usage information:

  • Your account email and password (the password is stored hashed by our authentication provider, never in plain text).
  • Your workflow work: steps, descriptions, 5C answers, evaluations, coach conversations, reflections, and experiment plans.
  • Product usage events: which page or stage you opened, timings, and counts. These carry IDs, not your free-text answers.

Where it's stored

Your work is kept in your browser's local storage while you use Helm, and — once you have an account — mirrored to a managed Postgres database hosted on Lovable Cloud (Supabase on AWS). Traffic is encrypted in transit with TLS, and the database is encrypted at rest. Each account can only read and write its own row; this is enforced by row-level security in the database, so no other Helm user can see your work.

AI processing

To generate coaching, evidence readings, and experiment plans, the text you enter is sent to AI providers. We deliberately do not send your name, email address, or organisation name in those requests — only your role, comfort level, tools, and the workflow text itself. These providers operate on API terms that do not use submitted data to train their models.

Because your free text leaves Helm to be processed, please do not enter client, beneficiary, donor, health, or case-level personal information anywhere in the app.

Subprocessors

Lovable Cloud (Supabase / AWS)
Database, authentication, and hosting (United States).
Lovable AI Gateway (OpenAI models)
Coaching, suggestions, and plan generation (United States).
Perplexity
Web-search grounded evidence readings and up-to-date practice context (United States).
Slack
Only when you explicitly share a plan, and only to the channel you name.
Google Fonts
Serves the typeface; your IP address and browser are visible to Google on page load.

How long we keep it

Your work is kept for as long as your account exists. Deleting your account removes your stored work immediately and unlinks your usage events so they remain only as anonymous counts. Note that the managed database takes automated backups, so deleted data can persist in those backups for the platform's backup retention window before ageing out. AI providers keep their own request logs on their own schedules, and any plan you shared to Slack stays in that Slack workspace under its retention policy.

Your data, your call

You can download everything Helm stores about you, or permanently delete your account and its data, at any time from your progress page.

Go to your progress page

Questions

If you're evaluating Helm on behalf of an organisation and need more detail — data processing agreements, residency, or subprocessor terms — contact the Helm team before rolling it out to staff.