Privacy Policy

Last updated: January 16, 2026

1. Introduction

Welcome to Helm, a mental wellness app (“we”, “us”, or “Helm”). We care deeply about protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you use our app or browse our site. By accessing our services, you agree to the terms set out below.

This policy applies to all visitors, users, and registered accounts. If you have any questions or concerns, please contact us using the details provided in the “Your rights and contact” section.

2. Data we collect

We follow the principle of data minimization, meaning we only collect the data needed to provide and improve the service. The information we may collect includes:

  • Account information: If you create an account via Sign in with Apple (e.g., email address, name).
  • Profile data: Information you provide during onboarding (age, goals, selected habits, lifestyle preferences).
  • Usage data: Task completion data, daily progress, habit tracking, streak information.
  • Technical data: IP address, device type, operating system version, possible device identifiers.

In accordance with applicable laws, we will not collect sensitive data (e.g., health conditions, medical history) without your explicit consent, unless you voluntarily choose to share it during use of the app.

3. How we use data

We use collected data primarily to provide and improve the service. We may use it to:

  • Personalize your experience: Adapt your program based on your selected habits and goals.
  • Track progress: Store your daily task completions and show your transformation journey.
  • Improve the app: Analyze usage patterns to refine features and fix potential errors.
  • Meet legal obligations: Comply with lawful requests or orders from competent authorities where required by law.
  • Ensure security: Detect and prevent malicious activity.

We emphasize that we never sell your data. The personal information you entrust to us is not commercially transferred to third parties. Any service providers we engage (e.g., Supabase for database hosting) are bound by strict confidentiality agreements and process your data only as necessary to deliver their services.

4. Retention and deletion of data

We retain your data for as long as your account is active. If you choose to delete your account via the app settings, all your personal data and progress history will be permanently removed from our servers within 30 days.

In general, personal data is not kept longer than necessary for the purposes for which it is processed. Once that period ends (or upon a valid deletion request), we erase or anonymize the relevant information.

5. Security and encryption

We implement physical, logical, and organizational security measures to protect your data from unauthorized access or disclosure. Measures include:

  • Encryption: Information is encrypted in transit (HTTPS/TLS) and at rest in our databases.
  • Access controls: Only authorized personnel (bound by confidentiality) can access administrative or technical areas.
  • Secure hosting: Data is stored using Supabase, a trusted cloud database provider with enterprise-grade security.
  • Monitoring: Intrusion detection tools and security procedures to anticipate or react quickly to anomalies.

Despite these precautions, no system is infallible. If a security breach or confirmed intrusion occurs, we will notify you as soon as reasonably possible and cooperate with the competent authorities where applicable.

6. Third-party services

Helm uses the following third-party services:

  • Supabase: For secure database storage and user authentication.
  • RevenueCat: For subscription management and in-app purchases.
  • Apple Sign In: For secure account authentication.

These services have their own privacy policies and are bound by strict data protection agreements.

7. Your rights and contact

Under the GDPR and applicable privacy laws, you have several rights regarding your personal data:

  • Right of access: Request confirmation that your data is processed and obtain a copy.
  • Right to rectification: Have inaccuracies corrected or incomplete information completed.
  • Right to erasure: Request deletion of your data when its retention is no longer justified.
  • Right to object: Object at any time to processing based on legitimate interests.
  • Right to restriction: Request temporary restriction of processing in specific cases.
  • Right to data portability: Obtain and reuse your data in a structured, machine-readable format.
  • Right to withdraw consent: For processing based on consent, you can revoke it at any time.

To exercise these rights or ask questions, please contact us at:

withubecontact@gmail.com

We may ask for proof of identity to verify the legitimacy of your request. You may also lodge a complaint with your competent supervisory authority (CNIL in France, or equivalent in your country).

8. Children and minors

Helm is intended for users aged 13 and older. If we discover that a child under 13 is using the service without parental authorization, we will take appropriate steps to delete their data. Users aged 13–18 are encouraged to inform their parents or legal guardians of their use of the app.

9. Changes to this privacy policy

We may update this policy to reflect changes in our practices or to meet evolving legal requirements. The “Last updated” date indicates the most recent version. Please review it regularly. Your continued use of the app after publication of an updated version constitutes acceptance of the changes.

10. Disclaimer

Helm provides habit tracking and wellness guidance. It does not replace professional medical, psychological, or fitness advice. In case of health concerns, please contact a qualified healthcare professional. We are not responsible for how you use information obtained via the app or for results achieved.

11. Contact

If you have questions, specific requests, or feedback regarding this privacy policy, please email us at:

withubecontact@gmail.com

We will do our best to respond promptly and handle your requests in accordance with applicable regulations.

© 2026 Helm. All rights reserved.

Terms · Privacy · Support