Privacy Policy
This policy explains what [COMPANY LEGAL NAME] ("Helve", "we", "us") collects when you use the Helve API, dashboard, and MCP server (the "Service"), why, and what choices you have. We are the data controller for the account and billing data described below. For the content you send through the API you are the controller and we process it on your instructions.
1. What we collect
Account data
- Your email address and, if you sign in with Google or GitHub, the identifier and profile name that provider shares with us. We do not receive your password from those providers.
- If you sign in with email and password, a salted hash of the password held by our authentication provider. We never see the password itself.
- API key names and a one-way hash of each key. The full key is shown to you once and is not stored.
Usage and billing data
- For each API request: which tool and Provider served it, the HTTP status, latency, cost, and the API key used. Usage records do not contain your query text, URLs, or results.
- Your credit balance and a ledger of top-ups, grants, and charges.
- Stripe customer and checkout identifiers. Card details are collected and stored by Stripe, not by us.
Content you send through the API ("Inputs")
- Search queries, URLs to extract, and audio URLs to transcribe are forwarded to the Provider that serves the request and returned to you. Synchronous requests are not stored after the response is sent, other than in short-lived operational logs.
- Asynchronous jobs (such as transcription) store the job input and result so you can retrieve them. Jobs are deleted seven (7) days after creation.
Technical data
- Server logs containing IP address, request path, status, timing, and error details, kept for a limited period for security and debugging.
- Browser storage on the dashboard: your session token, chosen theme, and last-opened tab. We do not use advertising or analytics cookies.
2. How we use it
- To provide the Service: authenticate you, route requests, return results, meter usage, and bill credits.
- To secure the Service: detect abuse, compromised keys, and fraud.
- To support you and send transactional email (sign-in links, confirmations, receipts, service notices).
- To improve the Service using aggregated usage statistics that do not identify you.
- To comply with law and enforce our Terms of Service.
We do not sell personal data and do not use your Inputs or results to train models.
3. Who we share it with
We share data only with the service providers needed to run Helve, each bound by its own terms and data agreements:
- Tool Providers, which receive the Inputs for the requests they serve: Exa, Parallel, Tavily, Brave, Serper, Firecrawl, Linkup, Valyu, Jina, Octen, Perplexity, AssemblyAI, Deepgram, and ElevenLabs. Each response tells you which Provider served it. Providers may retain request data under their own policies.
- Supabase for authentication and database hosting (EU, Frankfurt).
- Railway for application hosting (EU West).
- Stripe for payments.
- Google and GitHub when you choose to sign in with them.
- [EMAIL PROVIDER] for transactional email delivery.
We may also disclose data if required by law, to protect our rights or users' safety, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply.
4. International transfers
Our infrastructure is hosted in the European Union. Helve is a United States company, and some Providers and service providers are located in the United States or elsewhere. Where personal data leaves the EU or UK we rely on Standard Contractual Clauses or another lawful transfer mechanism.
5. Retention
- Account, key, usage, and ledger data: for the life of your account, then deleted or anonymized within ninety (90) days of closure, except records we must keep for tax or accounting purposes.
- Asynchronous job inputs and results: seven (7) days.
- Operational logs: [30] days.
6. Security
API keys are stored as one-way hashes, traffic is encrypted in transit, and access to production systems is restricted. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
7. Your rights
Depending on where you live you may have the right to access, correct, delete, or export your personal data, to restrict or object to its processing, and to withdraw consent. Residents of the EU, UK, and California have these rights under the GDPR, UK GDPR, and CCPA respectively; California residents may also ask what we collect and confirm that we do not sell it. You can update your email, revoke keys, and close your account from the dashboard, or contact us at the address below. You may also complain to your local data protection authority.
8. Children
The Service is not directed to anyone under 16 and we do not knowingly collect their data.
9. Changes
We will post any changes here and update the date above. Material changes will be announced by email or in the dashboard before they take effect.
10. Contact
[COMPANY LEGAL NAME], [ADDRESS]. Email: [CONTACT EMAIL].