Privacy Policy
Last updated: October 3, 2026
This policy explains what data Helper Guard AI (the website and the iOS and Android apps) collects, how we use and protect it, and your rights.
1. Data we collect
- Account data: name, email address, password (stored as a one-way hash), your Google or Facebook account ID if you sign in with them, and your two-factor authentication setting.
- Content you create: conversations and messages, files and images you upload, voice recordings, projects and tasks, and the images and videos you generate.
- Connected accounts (optional): when you connect Gmail or social media accounts, we store their access tokens encrypted and use them only to do what you ask.
- Usage and security data: IP address, sign-in and security event logs, and AI usage statistics (request counts and cost) to protect your account and apply plan limits.
- Learning data (optional, off by default): only if you turn on Learning in Settings do we keep a short topic profile and, to personalize answers, encrypted excerpts of your conversations and files together with numeric embeddings (vectors) computed from them. Turning Learning off deletes all of it.
- Accounts that existed before October 2, 2026: if Learning was already on but we have no record of your consent, it is paused: nothing new is collected and nothing already kept is used until you make your choice in Settings. Choosing off deletes what was kept; otherwise it is kept, unused, only within the retention periods below.
- Payments: handled by Stripe. We never store card numbers; we only keep your subscription status.
- Browser storage: we use your browser's local storage for your sign-in session and preferences (language, theme). We use no advertising cookies or ad tracking.
2. How we use your data
- To provide the service: answering your messages, summarizing your files, generating images and videos, and running the tasks you request.
- To personalize answers, only if you have turned on Learning (it is off by default and needs your opt-in).
- To protect accounts, prevent abuse, and send necessary messages (email verification, security alerts).
- We do not sell your data and do not use your content for advertising.
3. Service providers
Only the content needed to provide the service is sent to trusted providers: AI providers (OpenAI, including its embeddings service, which receives text excerpts only when Learning is on; Anthropic; Google Gemini; OpenRouter), fal.ai for image generation, Tavily for web search, Resend for email, Stripe for payments, our cloud storage provider when enabled, and Google, Meta and other platforms you choose to connect.
4. Google user data (Gmail)
When you connect Gmail we request read and draft-compose access only; we never send email as you or delete your messages. Helper Guard AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Security
Uploaded files, connected-account tokens, two-factor secrets and Learning excerpts are encrypted at rest (AES-256-GCM) with keys that we can rotate; other account data, including chat messages, is protected by encrypted database storage and access controls rather than by separate application-level encryption. Connections are encrypted and two-factor authentication is available. No system is 100% secure, but we continuously work to protect your data.
6. Retention and deletion
We keep your data while your account is active, or until you delete it. Technical logs are kept for limited periods: security events (sign-in attempts, IP addresses and the email addresses tried) 90 days; audit log (account actions and IP addresses) 365 days; AI usage records 400 days; Learning events 180 days; read notifications 90 days; Learning excerpts up to 2 years, or until you delete their source or turn Learning off.
When you delete your account, your data is permanently deleted (see the data deletion page), we remove the IP addresses and email addresses from security and audit records that were linked to you, we revoke the access you granted us to your Gmail, Google and social media accounts, and we delete your Stripe customer record when you have no active subscription. We keep only what the law requires, such as payment records held by Stripe.
When you delete your account, the audit log keeps one entry saying that an account was deleted, identified only by a random pseudonymous ID that no longer points to any person, for the same 365 days (security and accountability).
Backups: deleted data can remain in encrypted database backups for up to 30 days, until those backups expire. Backups are used only to recover the whole service after a failure, and any deletion is re-applied afterwards.
7. Your rights
You can access and correct your data, download a copy of it (conversations, files, tasks, projects and more, as a ZIP of JSON files; ask us if you cannot find the option in your app), turn Learning off, and delete your account at any time from Settings, or by contacting us.
The download contains your profile and consent record, conversations and messages, files, tasks, projects, notifications, usage records, connected-account details (never passwords or access tokens), voice commands with their results, background jobs and your Learning data. It does not contain the security log (sign-in attempts) or the audit log: we keep those on the basis of our legitimate interest in security (GDPR art. 6(1)(f)) until the periods above end, and you can ask us in writing for the entries about you.
8. Children
The service is not directed to anyone under 16. When you register you confirm that you are at least 16 years old.
9. Contact
Privacy questions: privacy@helperguard.com
We may update this policy; any change will be posted on this page with the update date.