Helmo Legal
Privacy Policy
Ultimo aggiornamento: July 2026
Helmo AI ("Helmo", "we", "us") is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, who processes it on our behalf, and your rights as a user.
1. Data We Collect
When you create an account or use Helmo, we may collect:
- Account data — your name, email address, and password (stored as a secure hash).
- Financial data — transaction records, budget configurations, savings goals, commitments, and spending patterns that you enter or import.
- AI conversations — the messages you exchange with our AI assistant (LISA) and your AI preferences.
- Usage data — pages visited, features used, and interaction logs.
- Device data — browser type, operating system, and IP address for security and analytics.
- Communication preferences — notification settings and Telegram integration details if you choose to connect.
2. How We Use Your Data
We use your data to:
- Provide and improve the Helmo service, including AI-powered financial insights.
- Send you proactive notifications and alerts you have opted into.
- Ensure the security and integrity of your account.
- Comply with legal obligations.
- Analyse usage patterns to improve the product.
We never sell your personal or financial data. The legal bases for our processing are the performance of our contract with you (to provide the service), your consent (for optional features such as analytics, push and Telegram), and our legitimate interest in securing and improving the product.
Closed beta quality review. During the closed beta, authorised Helmo personnel may review and analyse limited service data, including AI conversations and the financial details contained in them, to diagnose issues and improve the reliability, safety and quality of the product. We do not sell personal data or disclose personal or financial data to third parties for their own advertising, marketing or other independent purposes. Service providers may process data only on our behalf to operate and improve Helmo as described in this policy.
3. AI Processing
To generate financial insights and power the AI assistant, the relevant financial data and your chat messages are sent to large-language-model providers that process them on our behalf as service providers/data processors:
- Google (Gemini) — the models that generate insights and assistant replies.
- LiteLLM — routes requests to the AI models.
- Langfuse — AI observability, hosted in the European Union. During the beta, the content of your AI conversations (including financial details within them) and the assistant's responses may be recorded to debug, monitor quality, and improve the assistant. Access is restricted to authorised personnel and records are kept only for a limited period before automatic deletion.
These providers process your data only to deliver the service and do not use it to train their own models. AI-generated insights and simulator scenarios are advisory and informational only — they are not automated decisions producing legal or similarly significant effects, and a human (you) always remains in control. AI outputs do not constitute professional financial advice.
4. Other Processors
We also rely on the following service providers, each under its own privacy policy:
- Railway — application hosting and database.
- Vercel — frontend hosting and anonymous usage analytics.
- Resend — transactional email delivery.
- OneSignal — push notifications (if you opt in).
- Sentry — error monitoring (personal data is scrubbed from error reports).
- Google Cloud Logging — security and operational logging. We configure this service to receive operational log messages and limited technical metadata, including pseudonymous identifiers when needed to investigate a request, but not financial records, request bodies, query strings, headers, or cookies. These logs are stored in the European Union (
europe-west1) for 90 days. - PostHog — product analytics (financial data is excluded by design).
- Google Analytics — aggregate traffic analysis (production only, after consent).
- Telegram — if you connect the optional Telegram integration.
5. International Transfers
Some of the providers above may process data outside the European Economic Area. Where this happens, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Data Storage and Security
Your data is stored on secure servers with encryption at rest and in transit (TLS 1.2+). Access to production data is strictly limited to authorised personnel. We apply industry-standard security practices including access controls and audit logging.
7. Data Retention
We retain the financial and account data you provide for as long as your account is active. Transient and observability data is kept for shorter, fixed periods and then automatically deleted: API and Google Cloud operational logs are retained for up to 90 days, activity logs for up to 180 days, and raw import files for 30 days. If you delete your account, your personal data is removed promptly, except where retention is required by law.
8. Your Rights
Under the GDPR and applicable data protection law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict certain processing activities.
- Data portability — receive your data in a machine-readable format.
You can exercise access and portability directly in Settings → Export my data, and erasure in Settings → Delete account. For any other request, contact us at team@helmofinance.com.
9. Cookies
We use essential cookies to keep you logged in and remember your preferences. Analytics cookies are only set after you consent. See our Cookie Policy for full details.
10. Changes to This Policy
We may update this policy as the product evolves. We will notify you of material changes via email or an in-app notice.
11. Contact
For any privacy-related questions, contact us at team@helmofinance.com.
