1. Scope of this policy
This Privacy Policy describes how HELM handles personal information of users of the HELM trading platform and associated services (together, the “Service”), including:
- the HELM Hub at
https://app.helmstack.appand its APIs; - the HELM Desktop application and HELM background service that run on your machine;
- the HELM Agent (the local MCP server);
- the HELM marketplace and the cassette pipeline;
- marketing pages on
https://helmstack.app; - customer support email channels.
This Policy applies to individuals who create or use a HELM account, visit our websites, contact our support channels, or interact with the Service as a partner or contributor.
We are committed to handling personal information consistently with:
- the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth);
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) for users in the EU/EEA;
- the UK GDPR and Data Protection Act 2018 for users in the UK;
- equivalent privacy laws in other jurisdictions where they apply to us.
For the purposes of GDPR, HELM is the “controller” of personal information described in this Policy. For B2B customer accounts where HELM processes data on a customer's behalf, a separate Data Processing Agreement (DPA) governs the controller / processor relationship.
2. Information we collect
2.1 Account and identity information
- email address
- optional display name
- hashed password (we never store plaintext passwords — they are hashed with bcrypt before storage)
- MFA (multi-factor authentication) secrets where you enable TOTP or WebAuthn (encrypted at rest)
- account creation date, last sign-in timestamp, IP address of last sign-in
- subscription tier and entitlements held under your account
2.2 Billing and subscription information
- subscription tier, status, and billing cycle
- country and state / region (for tax calculation)
- VAT / GST / Tax ID where supplied
- invoice history (line items, amounts, currency, payment status)
- payment card and bank details: we do not store these. They are held by Stripe (our payment processor) under PCI-DSS Level 1 controls. HELM only receives a non-reversible token identifying your payment method.
2.3 Product and usage information
- devices associated with your account (machine fingerprint, hostname, operating system)
- cassettes installed and active per device
- substantive actions (sign-in, sign-out, module enable / disable, refund requested, etc.) recorded in a cryptographically chained audit log — retained for compliance per section 6
- error and performance traces sent to Sentry when the application encounters an error or slow operation. PII headers (Authorization, Cookies, password fields) are stripped before transmission.
- anonymised product-analytics events (e.g. “customer opened Billing tab”) sent to PostHog. Identifiers are hashed before transmission.
- uptime / synthetic monitoring data sent to Better Stack for status-page and alerting purposes (does not include account-level PII; it is health-of-endpoint telemetry).
2.4 Communications
- inbound email you send to
support@helmstack.app,tickets@helmstack.app,privacy@helmstack.app,legal@helmstack.app,security@helmstack.app, or any other HELM mailbox; - records of outbound emails we send you (transactional notices, billing receipts, security alerts);
- bounce / complaint / delivery events for outbound emails so we can stop sending to addresses where delivery is failing.
2.5 Partner information (only if you are a marketplace partner)
If you operate as a HELM marketplace partner, we additionally collect information required to onboard you as a Stripe Connect Express account: legal name, address, tax identifiers, and bank account details. Bank details are routed directly to Stripe and are not retained by HELM.
2.6 Information we do not collect
- We do not collect your trading account credentials. The HELM Agent brokers calls to broker / charting / data software on your machine and that software's credentials never leave your machine.
- We do not collect your trading journal entries, your local strategies, or any other content you create with the Service except to the limited extent necessary to deliver entitlements, sync preferences you have opted into syncing, and reconstruct usage patterns from anonymised events.
- We do not see the contents of your conversations with AI hosts (Claude, ChatGPT, others). Those happen between you and the host; HELM only sees the MCP tool-call surface exposed by the Agent on your machine, which is audit-logged locally on your machine, not on our servers.
3. Lawful basis for processing
We process personal information on one or more of the following lawful bases (GDPR Article 6) and, in Australia, consistent with the APPs:
| Category | Purpose | Lawful basis |
|---|---|---|
| Account & identity | Provide and maintain the Service | Performance of contract (Art. 6(1)(b)) |
| Billing & subscription | Charge fees, comply with tax law | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Audit log | Demonstrate accountability under privacy and financial regulations | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
| Product analytics (PostHog) | Understand which features customers use to improve the product | Legitimate interest (Art. 6(1)(f)) — anonymised identifiers, minimised payloads |
| Error tracking (Sentry) | Diagnose and fix application defects | Legitimate interest (Art. 6(1)(f)) — PII stripped before transmission |
| Uptime monitoring (Better Stack) | Service-availability monitoring | Legitimate interest (Art. 6(1)(f)) — endpoint health only |
| Communications | Reply to support requests, send service-critical notices | Contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Security / fraud prevention | Detect and prevent abuse | Legitimate interest (Art. 6(1)(f)) and legal obligation |
Where we rely on legitimate interest, we have assessed the balance between that interest and your rights and freedoms. You may object to processing on legitimate-interest grounds (see section 7).
We do not rely on consent for the processing above. If we ever rely on consent (for example, for an optional newsletter), we will request it expressly and you will be able to withdraw it at any time.
4. How we use your information
We use the information described in section 2 to:
- authenticate you and protect your account against unauthorised access;
- bill you correctly and remit tax to the right jurisdictions;
- deliver Service entitlements and software updates to your Desktop client and the HELM Agent;
- respond to your support requests and security disclosures;
- diagnose and fix product defects;
- improve the product based on aggregate, anonymised usage patterns;
- comply with our legal and regulatory obligations (including financial-records and anti-fraud obligations); and
- defend the Service against fraud, abuse, and security threats.
We do not sell your personal information.
We do not use your personal information or Customer Data to train third-party AI models. The AI host you choose to integrate with HELM is your own contractual relationship with that vendor; you are responsible for understanding that vendor's data handling.
5. Third-party processors and storage location
5.1 Where your data is stored
Production data is stored in:
- Hetzner (Singapore region) for the production Hub backend (Postgres, application servers).
- Vultr (Sydney region) for the staging environment.
- Cloudflare R2 for backups and large object storage (region: global, with EU/APAC data plane affinity).
5.2 Sub-processors
We use the following third-party processors. The list is updated whenever it changes and is also published at https://app.helmstack.app/legal/processing-records.
| Sub-processor | Purpose | Data categories |
|---|---|---|
| Stripe (Stripe Payments Australia Pty Ltd and affiliates) | Subscription billing, invoicing, tax computation, Connect partner payouts | Email, country, tax ID, payment method (held by Stripe), invoice history |
| Resend (Resend Inc.) | Transactional email delivery (receipts, security notices, alerts) | Email address, message metadata, delivery / bounce / complaint events |
| Cloudflare (Cloudflare, Inc.) | Network edge, DNS, DDoS protection, R2 storage for backups and assets | IP address, request metadata, encrypted backups |
| Sentry (Functional Software, Inc. dba Sentry) | Error and performance tracing | Stack traces, scrubbed request metadata; no PII payloads |
| PostHog (PostHog Inc.) | Product analytics — anonymised feature-usage events | Hashed user identifier, event names, page metadata |
| Better Stack (Better Stack, s.r.o.) | Uptime monitoring, on-call paging, status-page hosting | Endpoint health, response codes, latency — no account-level PII |
| Hetzner (Hetzner Online GmbH) | Compute and storage hosting for production Hub | All categories listed in section 2 (at-rest, encrypted) |
| Vultr (The Constant Company, LLC) | Compute and storage hosting for staging | Staging-only data (no production PII) |
| Doppler (Doppler Inc.) | Secrets management (not personal data — application credentials) | Application secrets only |
Privacy-policy references for each sub-processor are available on request at privacy@helmstack.app and at the processing-records URL above.
5.3 International transfers
Where personal information is transferred outside your jurisdiction:
- EU / EEA → outside EU/EEA: we rely on the European Commission's Standard Contractual Clauses (SCCs) where required, together with supplementary technical and organisational measures (encryption in transit and at rest, access controls, audit logging).
- Australia → outside Australia: we take reasonable steps under APP 8 to ensure the overseas recipient does not breach the APPs in relation to the information, including contractual safeguards and reliance on sub-processors that themselves operate to recognised privacy frameworks.
You can request a copy of the relevant transfer-safeguard documents by emailing privacy@helmstack.app.
6. Retention
We retain personal information only as long as necessary for the purpose for which it was collected, or as required by law.
| Category | Retention period |
|---|---|
| Account & identity (active account) | For the life of the account |
| Account & identity (after deletion request) | 14-day cooldown, then PII fields hashed or nulled; the account row is retained with a hashed email so lifetime-rule constraints (e.g. one trial per email) remain enforceable |
| Sessions (signed-in device records) | 90 days after last seen, then purged |
| Logs and ephemeral telemetry | 90 days, then purged |
| Audit log (cryptographically signed and chained) | Up to 7 years (financial-records minimum); payload redaction available on regulator request |
| Invoice / billing records | 7 years (statutory) |
| Bounce / complaint / delivery events | 2 years (sender reputation hygiene) |
| Product analytics events (PostHog) | 13 months default; configurable per event |
| Error traces (Sentry) | 90 days default |
| Inbound support email | 3 years from ticket close, then purged |
After your account is deleted (subject to the 14-day cooldown), the audit-log rows that reference your account are retained but the PII fields they reference (email, display name) are hashed or nulled.
7. Your rights
You have the following rights, exercisable by contacting privacy@helmstack.app (or, where indicated, via your customer portal). We respond to verified requests within 30 days.
- Access — you may request a copy of the personal information we hold about you. Self-service is available at
https://app.helmstack.app/account/security/data-exportand produces a downloadable JSON archive. - Rectification — you may correct inaccurate or incomplete data. Most fields are editable in the customer portal; otherwise email privacy@helmstack.app.
- Erasure (“right to be forgotten”) — you may request deletion of your account and the PII we hold. Self-service is available at
https://app.helmstack.app/account/security/delete. A 14-day cooldown applies before destruction so accidental deletions can be recovered. Signed audit-log rows are retained per section 6 but with PII hashed or nulled. - Restriction — you may request that we limit processing in certain cases (for example, while a rectification request is outstanding). Email privacy@helmstack.app.
- Portability — you may request that we provide your data in a structured, commonly used, machine-readable format. The data-export self-service produces a JSON archive suitable for re-import elsewhere.
- Objection — you may object to processing on legitimate-interest grounds, including for analytics or marketing purposes. Email privacy@helmstack.app.
- Withdrawal of consent — where we rely on consent (rare), you may withdraw it at any time. Withdrawal does not affect processing already carried out.
- Automated decision-making — HELM does not make decisions about you that have legal or similarly significant effects based solely on automated processing.
- No retaliation — exercising any of these rights will not result in unfavourable treatment of your account.
You also have the right to lodge a complaint with a supervisory authority (see section 11).
8. Security
We apply industry-standard technical and organisational measures appropriate to the risk:
- Passwords stored as bcrypt hashes.
- All client ↔ server communication uses TLS 1.2 or higher.
- Sessions issue short-lived (1-hour) access tokens and longer-lived (7-30 day) refresh tokens.
- Multi-factor authentication required for paying customer accounts.
- The audit log is hash-chained and RS256-signed; tampering is detectable.
- Production secrets are managed in Doppler with per-environment access scoping.
- Database backups are encrypted at rest and tested via a quarterly restore drill.
- The cassette release pipeline verifies publisher signatures before any cassette is loaded by an end-user device.
- Quarterly tabletop incident-response exercises and an annual third-party security review.
Despite these measures, no internet-based service is completely secure. We notify affected users and the relevant supervisory authority of any personal-data breach without undue delay and, where required by GDPR, within 72 hours of becoming aware of it.
9. Cookies and similar technologies
HELM uses cookies sparingly. The categories used:
- Strictly necessary — session cookie for signed-in customer portal access, idempotency-key cache for safe retry of paid actions, CSRF protection token. These cannot be disabled without breaking sign-in.
- Analytics (anonymous) — PostHog uses a single first-party cookie to deduplicate page views. Cookie name pattern:
ph_*_posthog. You may opt out by signing out (the cookie expires), using the PostHog opt-out, or blocking cookies forhelmstack.appin your browser settings.
HELM does not use advertising cookies, retargeting pixels, or third-party trackers. Marketing pages on https://helmstack.app do not set non-essential cookies without your consent where consent is required by local law.
10. Children
HELM is a business-tier product and is not directed to children. Consistent with GDPR Article 8 and applicable Australian guidance, we require users to be at least 16 years old, and in any case at least the age of majority where required by the Terms of Service.
We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@helmstack.app and we will delete it.
11. Complaints and supervisory authorities
We hope you bring concerns to us first — email privacy@helmstack.app and we will reply within 30 days.
You also have the right to lodge a complaint with the supervisory authority in your jurisdiction:
- Australia — Office of the Australian Information Commissioner (OAIC): oaic.gov.au
- EU / EEA — the data protection authority of your country of residence. The European Data Protection Board lists members at edpb.europa.eu.
- United Kingdom — Information Commissioner's Office: ico.org.uk
12. Changes to this policy
When we update this Policy, the document version field at the top reflects the new version.
Material changes (new sub-processor categories, change in retention, change in jurisdiction of storage, change in lawful basis) are notified to all active customers by email at least 30 days before they take effect. Where possible, we provide a summary of the material change.
Non-material changes (clarifications, typo corrections, addition of an equivalent-tier sub-processor without change in data categories) take effect on publication.
You can always find the current version at https://app.helmstack.app/legal/privacy.
Contact summary
- Privacy / data-subject requests: privacy@helmstack.app
- Security disclosures: security@helmstack.app
- Commercial / legal questions: legal@helmstack.app
- DPO: to be appointed — until then, privacy enquiries are handled by the privacy contact above.
Controller details
Tripod Advisory Group Pty Ltd
ABN 33 676 185 149
Registered in Australia
Trading as HELM Systems / helmstack.app