Privacy Policy

Last updated: March 17, 2026

1. Introduction

Welcome to Helm, a mental wellness app (“we”, “us”, or “Helm”). We care deeply about protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application (the “App”) or browse our website at helmfocus.com (the “Site”). By accessing our services, you agree to the terms set out below.

This Policy applies to all visitors, users, and registered accounts. If you have any questions or concerns, please contact us using the details provided in the “Your Rights and Contact” section.

2. Data we collect

We follow the principle of data minimization, meaning we only collect the data needed to provide and improve the service. The information we may collect includes:

  • Account information: If you create an account via Sign in with Apple (e.g., email address, name).
  • Profile data: Information you provide during onboarding (age, goals, selected habits, lifestyle preferences).
  • Usage data: Task completion data, daily progress, habit tracking, streak information, breathing exercise sessions, meditation sessions, and other wellness activity logs.
  • Technical data: IP address, device type, operating system version, possible device identifiers, or approximate geolocation data.
  • Cookies: We use cookies and similar technologies on our website to improve navigation and understand how you interact with our Site (see the “Cookies and Tracking Technologies” section).

In accordance with applicable laws, we will not collect sensitive data (e.g., health conditions, medical history, sexual orientation, political opinions, religious beliefs) without your explicit consent, unless you voluntarily choose to share it during use of the App.

3. How we use data

We use collected data primarily to provide and improve the service. We may use it to:

  • Personalize your experience: Adapt your program based on your selected habits, goals, and wellness preferences.
  • Track progress: Store your daily task completions, breathing exercise history, meditation sessions, and show your transformation journey.
  • Improve the App: Analyze usage patterns to refine features, fix potential errors, and offer more relevant interactions.
  • Enhance navigation: Adapt the user interface or remember your preferences (e.g., language, theme).
  • Meet legal obligations: Comply with lawful requests or orders from competent authorities where required by law.
  • Ensure security: Detect and prevent malicious activity (e.g., hacking attempts or spam).

We emphasize that we never sell your data. The personal information you entrust to us is not commercially transferred to third parties. Any service providers we engage (e.g., Supabase for database hosting) are bound by strict confidentiality agreements and process your data only as necessary to deliver their services.

4. Retention and deletion of data

We retain your data for as long as your account is active. If you choose to delete your account via the App settings, all your personal data and progress history will be permanently removed from our servers within 30 days. No residual records are kept, except where a specific legal obligation applies (e.g., a judicial request).

In general, personal data is not kept longer than necessary for the purposes for which it is processed. Once that period ends (or upon a valid deletion request), we erase or anonymize the relevant information.

5. Security and encryption

We implement physical, logical, and organizational security measures to protect your data from unauthorized access or disclosure. Measures include:

  • Encryption: Information is encrypted in transit (HTTPS/TLS) and at rest in our databases.
  • Access controls: Only authorized personnel (bound by confidentiality) can access administrative or technical areas.
  • Secure hosting: Data is stored using Supabase, a trusted cloud database provider with enterprise-grade security.
  • Monitoring: Intrusion detection tools and security procedures to anticipate or react quickly to anomalies.

Despite these precautions, no system is infallible. If a security breach or confirmed intrusion occurs, we will notify you as soon as reasonably possible and cooperate with the competent authorities where applicable. We will take all reasonable steps to limit impact and remedy the situation.

6. Third-party services

Helm uses the following third-party services:

  • Supabase: For secure database storage and user authentication.
  • RevenueCat: For subscription management and in-app purchases.
  • Apple Sign In: For secure account authentication.

These services have their own privacy policies and are bound by strict data protection agreements. We encourage you to review their respective privacy policies.

7. Cookies and tracking technologies

To improve your browsing experience on our website, our Site may store or retrieve information on your browser, primarily in the form of cookies. These files help remember your preferences (language, session, etc.) and help us understand how you use the Site (usage statistics, etc.).

You can set your browser to refuse cookies or to alert you when cookies are sent. However, refusing certain essential cookies may affect the proper functioning of the Site.

8. Your rights and contact

Under the GDPR and applicable privacy laws, you have several rights regarding your personal data:

  • Right of access: Request confirmation that your data is processed and obtain a copy.
  • Right to rectification: Have inaccuracies corrected or incomplete information completed.
  • Right to erasure: Request deletion of your data when its retention is no longer justified or in case of legitimate objection.
  • Right to object: Object at any time to processing based on legitimate interests for reasons related to your particular situation.
  • Right to restriction: Request temporary restriction of processing in specific cases (e.g., verifying accuracy).
  • Right to data portability: Obtain and reuse your data in a structured, commonly used, machine-readable format.
  • Right to withdraw consent: For processing based on consent, you can revoke it at any time.

To exercise these rights or ask questions, please contact us at:

withubecontact@gmail.com

We may ask for proof of identity to verify the legitimacy of your request. We commit to respond within legal timeframes (one month, renewable where applicable). You may also lodge a complaint with your competent supervisory authority (CNIL in France via https://www.cnil.fr, or equivalent in your country).

9. Sensitive data

Wellness and mental-health information may constitute sensitive data under the GDPR. Its processing requires explicit consent from the User. Helm implements enhanced security measures (encryption, restricted access, etc.) to protect such data.

By using the App and providing wellness-related information (mood tracking, breathing exercise data, meditation progress, personal goals), you explicitly consent to the processing of this data for the purposes described in this Policy.

10. Children and minors

Helm is intended for users aged 13 and older. If we discover that a child under 13 is using the service without parental authorization, we will take appropriate steps to delete their data. Users aged 13–18 are encouraged to inform their parents or legal guardians of their use of the App.

In France, the minimum digital age of consent is 15. Users under 15 in France cannot lawfully consent on their own to the processing of personal data; prior explicit consent from their legal guardian(s) is required.

11. Changes to this privacy policy

We may update this Policy to reflect changes in our practices or to meet evolving legal requirements. The “Last updated” date indicates the most recent version. Please review it regularly. Your continued use of the App or the Site after publication of an updated version constitutes acceptance of the changes.

12. Disclaimer

Helm provides habit tracking, breathing exercises, meditation, and wellness guidance. It does not replace professional medical, psychological, psychiatric, or fitness advice. In case of health concerns, distress, or emergency, please contact a qualified healthcare professional or emergency services immediately. We are not responsible for how you use information obtained via the App or for results achieved or not achieved.

The breathing exercises, meditation sessions, and other wellness tools provided by the App are for general informational and wellness purposes only. Users should consult a qualified healthcare professional before beginning any breathing or wellness program, particularly if they have pre-existing medical conditions.

13. Contact

If you have questions, specific requests, or feedback regarding this Privacy Policy, please email us at:

withubecontact@gmail.com

We will do our best to respond promptly and handle your requests in accordance with applicable regulations.

© 2026 Helm. All rights reserved.

Terms · Privacy · Support