HelixAI
Home Who We Are Blog Login Get Started
Legal

Privacy Policy

Effective Date: February 17, 2026  ·  Questions? david@helixai.media

Contents

  1. 1. Introduction and Scope
  2. 2. Information We Collect
  3. 3. How We Use Your Information
  4. 4. Cookies and Tracking
  5. 5. Third-Party Data Sharing
  6. 6. Data Retention
  7. 7. Your Privacy Rights
  8. 8. GDPR Compliance
  9. 9. CCPA Compliance
  10. 10. Children's Privacy
  11. 11. Data Security
  12. 12. Data Breaches
  13. 13. Content Moderation
  14. 14. Contact Information

1. Introduction and Scope

HelixAI ("we," "us," "our," or "Company") is a multi-tenant B2B Software-as-a-Service (SaaS) platform that provides AI-powered marketing content generation and optimization services. This Privacy Policy describes how HelixAI collects, uses, discloses, and safeguards information about you when you use our platform, including our website, application, and services (collectively, the "Services").

This Privacy Policy applies to all users of HelixAI, including account holders ("End Users"), tenant administrators, and individuals who may interact with our Services. HelixAI offers three service tiers: Free, Pro, and Enterprise. Data handling practices may vary slightly by tier, as noted throughout this policy.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Services. By accessing and using HelixAI, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.

2. Information We Collect

2.1 User-Level Data

HelixAI collects the following information at the individual user level:

  • Username and email address
  • First name and last name
  • Password (securely hashed using PBKDF2-HMAC-SHA256 with 600,000 iterations and unique salt per user)
  • JWT access tokens (valid for 1 hour)
  • Refresh tokens (valid for 7 days)
  • Session cookies and session data
  • Last login timestamp
  • IP address (collected during authentication and refresh token operations)
  • User-Agent string (browser and device information)

2.2 Tenant-Level Data

HelixAI collects the following information at the tenant (organization) level:

  • Company name and registered subdomain
  • Subscription tier (Free, Pro, or Enterprise)
  • Billing email address
  • Stripe customer ID and subscription ID
  • All AI-generated content created through the platform
  • Content generation history and metadata
  • Blog posts and marketing materials created or managed through HelixAI
  • NLP style profiles derived from user writing samples, including tone, vocabulary, readability, and stylistic preferences
  • Competitor analysis data (includes scraped publicly available information)
  • Sage AI chat history (all conversations with our AI assistant)
  • SEO metrics, keywords, and optimization data
  • Hashed API keys with associated scopes and rate limit configurations

2.3 Audit Logs

HelixAI maintains comprehensive audit logs that capture the following information for security and compliance purposes:

  • Tenant ID and User ID
  • Action type (creation, modification, deletion, access, etc.)
  • Resource affected (content, settings, API keys, etc.)
  • IP address
  • User-Agent string
  • Timestamp of the action

Audit logs are time-partitioned by month in our PostgreSQL database to optimize query performance and data management.

2.4 How Information is Collected

We collect information in the following ways:

  • Directly from you when you register for an account, complete your profile, or use our Services
  • Automatically through cookies, session data, and server logs when you access our platform
  • From third-party services, such as Stripe for payment processing
  • Through API integrations and content generation requests

3. How We Use Your Information

HelixAI uses the collected information for the following purposes:

  • Account Authentication and Management: To verify your identity, secure your account, and maintain session data
  • Service Delivery: To provide content generation, optimization, and AI-powered features
  • Personalization: To tailor the platform experience and provide NLP style profiles that match your writing preferences
  • Billing and Payment Processing: To process subscription payments and manage billing through Stripe
  • Audit and Compliance: To maintain detailed logs of user actions for security monitoring and regulatory compliance
  • Security and Fraud Prevention: To detect unauthorized access, prevent fraud, and protect against abuse
  • Service Improvement: To analyze usage patterns and improve our Services
  • Legal Obligations: To comply with legal requirements and respond to law enforcement requests
  • Content Moderation: To monitor for policy violations, especially regarding child safety
  • Communication: To send service updates, security alerts, and important notifications (opt-out available for non-critical communications)

4. Cookies and Tracking Technologies

HelixAI uses the following cookies to maintain functionality and security. All cookies are first-party cookies; we do not use third-party tracking, analytics, or advertising cookies.

4.1 Essential Cookies

  • session: HttpOnly, Secure, signed session token containing email, tenant_id, and role information. Expires in 1 hour. Cannot be accessed by JavaScript.
  • access_token: HttpOnly, Secure, JWT-based access token. Expires in 1 hour. Cannot be accessed by JavaScript.
  • refresh_token: HttpOnly, Secure, long-lived token for session renewal. Expires in 7 days. Cannot be accessed by JavaScript.

4.2 CSRF Protection

CSRF (Cross-Site Request Forgery) tokens are generated per session with a 1-hour expiration. These tokens are validated on all state-changing requests (POST, PUT, DELETE) to prevent unauthorized actions.

4.3 Cookie Consent

Since HelixAI only uses essential, first-party cookies necessary for authentication and security, we do not require explicit cookie consent. However, users may disable cookies in their browser settings, which may limit functionality.

4.4 No Third-Party Tracking

HelixAI does not implement third-party tracking cookies, analytics cookies, or advertising cookies. We do not use Google Analytics, Facebook Pixel, or similar third-party tracking mechanisms on our platform.

5. Third-Party Data Sharing

HelixAI shares certain information with third-party service providers to deliver our Services. All third-party services are bound by confidentiality agreements.

5.1 Anthropic Claude API

User prompts, content inputs, and generated content are sent to Anthropic's Claude API for AI processing. This includes marketing copy, blog posts, SEO optimization requests, and Sage AI chat conversations. Anthropic processes this data according to their privacy policy and data retention practices. We recommend reviewing Anthropic's privacy documentation for details on how your data is handled.

5.2 Stripe Payment Processing

Payment information, including billing email and subscription details, is shared with Stripe for payment processing. Credit card information is never stored on HelixAI servers; Stripe handles all payment data. Stripe's privacy policy governs the handling of payment-related information.

5.3 Together AI (Optional)

Enterprise tier customers may optionally enable LoRA (Low-Rank Adaptation) model hosting through Together AI. If enabled, certain content and fine-tuning data is shared with Together AI according to your configuration. This is optional and is only activated with explicit tenant consent.

5.4 Law Enforcement and Legal Compliance

HelixAI may disclose user information to law enforcement agencies, government authorities, or other third parties when required by law, legal process, or government request. In cases of suspected child exploitation or other crimes, we will cooperate with law enforcement and may share relevant data including email addresses, IP addresses, User-Agent strings, and content accessed in violation of our policies.

5.5 Business Transfers

If HelixAI is acquired, merges with another entity, declares bankruptcy, or undergoes a change of control, your information may be transferred as part of the transaction. We will provide notice of any such change and any choices you may have regarding your data.

6. Data Retention

HelixAI currently maintains user data and audit logs on an indefinite basis. However, we recognize the importance of appropriate data retention periods and are actively developing a comprehensive data retention policy.

6.1 Current Retention Practice

  • User account data: Retained indefinitely while account is active; deleted upon account termination
  • Tenant data and content: Retained indefinitely while subscription is active; deleted upon account cancellation
  • Audit logs: Retained indefinitely (currently time-partitioned by month)
  • JWT tokens and session data: Automatically expired after 1 hour (access) or 7 days (refresh)
  • Content moderation violation logs: Retained indefinitely for law enforcement purposes

6.2 Recommended Retention Periods (Under Development)

We are implementing the following retention policy to balance regulatory compliance and user privacy:

  • Standard audit logs: 3 years
  • Content generation history: Configurable by tenant, default 2 years
  • Competitor analysis data: Refreshed periodically; older data deleted after 90 days if not actively used
  • Chat history: Configurable by tenant, default 1 year
  • User behavior analytics: 1 year
  • Violation and moderation logs: 7 years (for legal and compliance purposes)

6.3 Data Deletion

When you request deletion of your account or a tenant is terminated, we will delete associated personal data within 30 days, except where retention is required by law or for legitimate security purposes. Deletion of audit logs and violation data may be subject to legal holds and law enforcement requests.

7. Your Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your personal data.

7.1 Right to Access

You have the right to request and obtain a copy of the personal data HelixAI holds about you. To exercise this right, contact us at david@helixai.media with your request.

7.2 Right to Correction

You may request correction of inaccurate or incomplete personal data. You can update certain information (name, email, password) directly through your account settings. For other corrections, contact our privacy team.

7.3 Right to Deletion

You may request deletion of your account and associated personal data, subject to legal and regulatory requirements. Some data, such as audit logs for compliance purposes, may not be deleted immediately.

7.4 Right to Data Portability

You have the right to obtain your personal data in a structured, commonly used, machine-readable format. HelixAI will provide your data in JSON or CSV format upon request.

7.5 Right to Opt-Out

You may opt-out of non-essential communications, including marketing emails and optional analytics. You cannot opt-out of essential service communications or security alerts.

7.6 Exercising Your Rights

To exercise any of these rights, please submit a written request to david@helixai.media. Include sufficient information to identify your account and the specific right you are exercising. We will respond to your request within 30 days and may request verification of your identity before processing.

8. GDPR Compliance

For users in the European Union, United Kingdom, and other jurisdictions with GDPR or similar regulations, the following terms apply:

8.1 Lawful Basis for Processing

HelixAI processes personal data under the following lawful bases under GDPR Article 6:

  • Contract (Article 6(1)(b)): Processing is necessary to perform the Services you have requested and to manage your account
  • Legitimate Interests (Article 6(1)(f)): Processing is necessary for fraud prevention, security, service improvement, and audit compliance
  • Legal Obligation (Article 6(1)(c)): Processing is necessary to comply with law enforcement requests and legal requirements
  • Consent (Article 6(1)(a)): Processing optional data such as marketing communications only with your explicit consent

8.2 Data Protection Officer

HelixAI has appointed a Data Protection Officer (DPO) to oversee compliance with GDPR. To contact our DPO regarding privacy concerns, email david@helixai.media.

8.3 International Data Transfers

HelixAI's servers and operations are located in the United States. When processing data of individuals in the EU, UK, or other jurisdictions, such processing constitutes an international data transfer. HelixAI relies on Standard Contractual Clauses (SCCs) and appropriate safeguards to ensure adequate protection of your data. By using HelixAI, you consent to such transfers.

8.4 GDPR Rights

In addition to the rights described in Section 7, you have the following GDPR-specific rights:

  • Right to withdraw consent at any time
  • Right to restrict processing
  • Right to object to processing
  • Right to lodge a complaint with your local data protection authority

To exercise GDPR rights, contact our DPO at david@helixai.media or our privacy team at david@helixai.media.

9. CCPA Compliance

For users in California, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) apply.

9.1 Categories of Personal Information Collected

Under CCPA, HelixAI collects the following categories of personal information:

  • Identifiers: name, email, username, IP address
  • Commercial information: subscription tier, payment information, billing history
  • Internet activity: session data, User-Agent, access logs, audit logs
  • Geolocation data: IP-based location inferred from access logs
  • Professional information: company name, job role, writing style preferences
  • Content: generated marketing content, blog posts, chat history, competitor analyses

9.2 Sale or Sharing of Personal Information

HelixAI does not sell personal information as defined by CCPA. HelixAI shares personal information with service providers (Anthropic, Stripe, and optionally Together AI) necessary to provide Services. This sharing is not considered a "sale" under CCPA.

9.3 Right to Know

You have the right to request what personal information HelixAI has collected about you and how it is used. Submit a verified consumer request to david@helixai.media.

9.4 Right to Delete

You have the right to request deletion of personal information collected about you, subject to exceptions for legal obligations and service delivery.

9.5 Right to Correct

You have the right to request correction of inaccurate personal information held by HelixAI.

9.6 Right to Opt-Out

You have the right to opt-out of the sharing of your personal information with service providers for their own purposes. Note that opting out may limit your ability to use certain features.

9.7 Right to Non-Discrimination

HelixAI will not discriminate against you for exercising your CCPA rights. You will not be denied service, charged different prices, or subjected to different quality of service based on your privacy choices.

9.8 Exercising CCPA Rights

To exercise CCPA rights, submit a verified consumer request to david@helixai.media. Include your name, email, account username, and specific request. We will verify your identity and respond within 45 days.

10. Children's Privacy

HelixAI's Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a user is under 18, we will immediately delete their account and associated personal data. By using HelixAI, you represent that you are at least 18 years of age.

If you believe HelixAI is collecting data from a minor, please contact us immediately at david@helixai.media.

HelixAI has zero tolerance for child exploitation. Our content moderation system actively monitors for attempts to generate child sexual abuse material (CSAM) or other exploitative content. Any such attempts are immediately logged, the account is suspended, and law enforcement is notified.

11. Data Security

HelixAI implements comprehensive security measures to protect your data from unauthorized access, alteration, disclosure, and destruction.

11.1 Password Security

User passwords are hashed using PBKDF2-HMAC-SHA256 with 600,000 iterations and unique cryptographic salt per user. Passwords are never stored in plaintext and cannot be recovered by HelixAI staff.

11.2 Transport Security

All communication between your device and HelixAI servers is encrypted using HTTPS/TLS 1.2 or higher. We enforce HTTPS on all connections; unencrypted HTTP requests are automatically redirected.

11.3 API Key Security

API keys are hashed before storage and cannot be recovered in plaintext. Each API key has associated scopes and rate limit configurations to minimize the impact of key compromise.

11.4 CSRF Protection

All state-changing requests are protected against Cross-Site Request Forgery (CSRF) attacks through token validation and same-site cookie policies.

11.5 Security Headers

HelixAI implements the following security headers to protect against common web vulnerabilities:

  • Content-Security-Policy (CSP): Restricts resource loading to prevent XSS attacks
  • X-Frame-Options: DENY to prevent clickjacking
  • X-Content-Type-Options: nosniff to prevent MIME-sniffing attacks
  • X-XSS-Protection: Enabled for additional XSS protection
  • Strict-Transport-Security: Enforces HTTPS and prevents downgrade attacks
  • Referrer-Policy: strict-no-referrer to minimize referrer leakage
  • Permissions-Policy: Disables geolocation, microphone, camera, and payment APIs

11.6 Rate Limiting

HelixAI implements per-IP and per-session rate limiting to prevent brute-force attacks, abuse, and denial-of-service (DoS) attacks. Excessive requests may result in temporary IP blocking.

11.7 Multi-Tenant Isolation

Each tenant operates in a logically isolated environment with a separate PostgreSQL database. Shared authentication is managed in a separate database with row-level tenant scoping to prevent cross-tenant data access.

11.8 Limitations

While HelixAI implements comprehensive security measures, no system is completely secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your passwords and account credentials.

12. Data Breaches and Notifications

In the event of a data breach that compromises the confidentiality, integrity, or availability of personal data, HelixAI will take the following actions:

12.1 Breach Investigation and Containment

Upon discovery of a breach, we will immediately investigate the scope and nature of the breach, contain it to prevent further unauthorized access, preserve evidence for forensic analysis, and engage cybersecurity experts if necessary.

12.2 User Notification

We will notify affected users within 72 hours of discovering a breach that materially compromises personal data. Notification will include a description of what data was compromised, the date of the breach, likely impact, recommended protective actions, and incident response contact information.

12.3 Regulatory Notification

HelixAI will notify relevant data protection authorities as required by law, including the ICO (UK), DPA (EU member states), and state attorneys general (US) within applicable timeframes.

12.4 Credit Monitoring

In breaches involving financial information, HelixAI may offer credit monitoring and fraud protection services to affected individuals.

13. Content Moderation and Privacy

HelixAI employs automated and manual content moderation to enforce our terms of service and prevent illegal activities, particularly child exploitation.

13.1 What is Monitored

HelixAI monitors user-generated prompts, content generation requests, and chat interactions for:

  • Child Sexual Abuse Material (CSAM) or attempts to generate such content
  • Non-consensual intimate imagery
  • Human trafficking or exploitation content
  • Harassment, threats, or violence
  • Illegal drugs or weapons trafficking
  • Fraud or deception

13.2 Violations Log and Privacy Implications

When a violation is detected, HelixAI records the following information in our violations log: user email address, IP address, User-Agent string, content flagged, matched policy terms, timestamp, tenant name and ID, and severity classification. This information is retained for law enforcement purposes and may be disclosed to authorities. Violations involving child exploitation receive a CRITICAL severity classification and are immediately reported to the National Center for Missing and Exploited Children (NCMEC) and law enforcement.

13.3 User Account Actions

  • First-time minor violations (Low/Medium): Warning and account suspension for 24–48 hours
  • Repeated violations: Temporary account suspension (7–30 days)
  • Severe violations (High/Critical): Immediate permanent account termination
  • Child exploitation (CRITICAL): Immediate permanent termination, law enforcement notification, evidence preservation

13.4 Retention and Law Enforcement

Violations logs and associated moderation data are retained indefinitely to support law enforcement investigations, legal proceedings, and regulatory compliance. These logs may be shared with law enforcement upon request with or without a warrant, depending on the circumstances and applicable law.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or HelixAI's data practices, please contact us:

HelixAI, Inc.

Privacy Team: david@helixai.media

Data Protection Officer: david@helixai.media

Support: david@helixai.media

HelixAI reserves the right to modify this Privacy Policy at any time. Material changes will be communicated to users via email or prominent notice on the platform at least 30 days before taking effect. Your continued use of HelixAI after changes become effective constitutes your acceptance of the updated Privacy Policy.

Privacy Policy Version 1.0. This Privacy Policy is part of the HelixAI legal framework and should be read in conjunction with our Terms of Service, Acceptable Use Policy, and Cookie Policy.

↑ Back to top

Related Legal Documents

Privacy Policy Terms of Service Terms of Use Cookie Policy Acceptable Use Policy
HelixAI
© 2026 HelixAI, Inc. All rights reserved.
Home Blog Privacy Terms Cookies AUP Contact