Privacy Policy
Last updated: July 2026
1. What we collect
When you create a Helmbase workspace, we collect your name, email address, and password (stored as a salted hash, never in plain text). As you use the product, you may enter data about your own clients — names, emails, project details, documents, and invoices — which is stored on your behalf so you can manage your business.
2. How we use it
Your account data is used to operate the service: authenticating you, sending transactional email (welcome messages, invoice reminders, portal links you choose to send), and displaying your workspace’s data back to you. We do not sell your data or your clients’ data to third parties.
3. Client portal data
If you share a client portal link, the named client can view the project status, documents, and invoices you’ve associated with them via a unique link. We don’t require your clients to create an account or share data with anyone else.
4. Third-party services
We use Supabase for data storage, Resend for transactional email, and Vercel for hosting. If you connect optional integrations (Hunter.io, Google Places, or an AI proposal writer) from Settings, those API keys are encrypted at rest and used only to fulfill the specific feature you enabled.
5. Data retention & deletion
We retain your workspace data for as long as your account is active. You can request deletion of your account and all associated data at any time by contacting us.
6. Contact
Questions about this policy? Reach out to the team through the contact details on our website.