Privacy Policy

Effective date: May 16, 2026 · Helium (usehelium.io)

Helium is built to be your private knowledge companion. We collect only what's necessary to provide the service, we never sell your data, and we never serve ads. This policy explains exactly what we collect, why, and how you can control it.

1. Data We Collect

Account Information

When you create an account, we collect your email address and optional display name. If you sign in via Apple, Google, or GitHub, we receive the email and name associated with that account. We do not access your contacts, calendar, or other account data.

User Content

Helium stores the content you create and save:

  • Cards (knowledge snippets captured from AI conversations)
  • Prompts (reusable prompt templates with variables)
  • Conversations (imported AI chat threads)
  • My Context profiles (personal context sections)
  • Context Packs (curated bundles of cards and conversations)
  • Projects, Tags, and Saved Links
  • Screenshots (captured images of AI responses)

All user content is stored for your own use. We do not read, analyze, mine, or monetize your content.

Usage Analytics

We use PostHog for basic product analytics on marketing pages: page views, feature clicks, and conversion events. Inside the app, we don't load PostHog's browser SDK or record sessions. Instead, we send a small, well-defined set of product events via authenticated REST calls (see the next section). Analytics events do not include personally identifiable information beyond your account identifier and email address, which are used only to associate activity with your account; they do not include fingerprinting or cross-site tracking.

No session recording or replay. Helium does not use session recording or replay on any surface, including marketing pages, the web app, and mobile. We do not capture screen interactions, scrolling, mouse movements, or text inputs.

Product Analytics (app + mobile)

When you're signed in and using the Helium app (mobile or server-side actions), we log a small set of product events, for example: “a paywall was shown,” “a subscription was activated,” “a rate limit was hit.” These help us understand how Helium is used and make better product decisions. The events are tied to your Supabase account ID (not a tracking cookie, not a device fingerprint), contain no card content, no conversation messages, no prompt text, and no personal information beyond your email (for account linkage only).

The web /app routes themselves never load PostHog's browser SDK. Mobile events are sent from the app via authenticated REST calls; server-side events are sent from our Supabase edge functions. Analytics events are retained in PostHog's systems per their standard retention policies (approximately 12 months); request deletion via [email protected].

Payment Data

Subscriptions are processed by Apple App Store (StoreKit) on iOS, with RevenueCat managing entitlements between the store and our backend. We never see, receive, or store your credit card number, billing address, or bank details. We only receive your subscription status (active, cancelled, expired) and expiration date.

Waitlist

We use Loops.so to manage waitlist signups submitted on the marketing site. If you join the waitlist, we share the email address you provide with Loops for that purpose only. Loops is not used to send signup confirmations, billing notifications, or product updates; authentication-related emails are sent by Supabase Auth.

Sync Metadata

On the iOS app, when you sign in to enable cloud sync, we store timestamps and device identifiers to coordinate multi-device synchronization across your iPhone and iPad. This metadata does not include device names, IP addresses, or location data. The web app and desktop app do not sync at this time; data on those surfaces remains local to the device.

2. Data We Do Not Collect

  • We do not track you across websites or apps
  • We do not use fingerprinting or device profiling
  • We do not sell, rent, or share your data with third parties for advertising
  • We do not serve ads of any kind
  • We do not share data across users; your library is queried only by you
  • We do not read clipboard content on your device without your explicit opt-in (desktop clipboard monitoring is off by default and runs entirely locally)
  • We do not use your content to train AI models

3. AI Features and Data Processing

When you use AI-powered features (screenshot parsing, conversation summaries, context management, auto-crop, link distillation, context suggestions), your content is sent to Anthropic's Claude API via our server-side edge functions. Key facts:

  • Content is sent for processing only and is not stored by Anthropic per their API data usage policy
  • Your data is never used to train AI models
  • The API key is stored server-side and never exposed to clients
  • Most AI features require a Pro subscription. Free users have limited access to screenshot capture with AI parsing (5 captures per day); Pro raises this to 100 per day. All other AI features (conversation summarization, link distillation, context management, and auto-suggestions) are Pro-only. Importing a conversation itself (via ZIP, JSON, or share-link URL) is free; only the AI summary generated afterward is Pro.
  • We log token usage counts (not content) for billing and rate limiting

4. Prompt Sharing

When you share a prompt publicly:

  • Only the prompt title, description, tags, variable names, and a truncated text preview (200 characters) are visible publicly
  • Your identity, email, and account information are never shown on the public page
  • Full prompt text is only transferred to authenticated users who choose to import it
  • You can revoke sharing at any time, which removes the public page
  • Imported copies are independent: revoking sharing does not delete copies others have already imported

5. Third-Party Services

Helium relies on the following third-party services. Each has its own privacy policy; we select services that align with our privacy-first approach.

Hosting and Infrastructure

  • Supabase: database, authentication, file storage, edge functions (data stored in US infrastructure)
  • Vercel: web hosting and edge functions
  • Vercel Analytics: anonymous traffic analytics on every web page (page views, route, viewport, device class; no cookies, no PII)
  • Vercel Speed Insights: anonymous Web Vitals telemetry (LCP, FID, CLS, TTFB, INP; no cookies, no PII)
  • jsdelivr CDN (Cloudflare-fronted): serves the OCR worker bytecode (tesseract.js) when you capture a screenshot in the web app

AI Features

  • Anthropic Claude API: processes content for AI features (titles, summaries, auto-crop, distill links, context management). Per Anthropic's API policy, content is not retained beyond 30 days and is not used to train models.

Payments

  • RevenueCat: subscription entitlement management
  • Apple App Store / StoreKit: iOS subscription purchases

Authentication (only the provider you choose)

  • Apple Sign In: when you choose "Continue with Apple"
  • Google OAuth: when you choose "Continue with Google"
  • GitHub OAuth: when you choose "Continue with GitHub"
  • Email and password: handled entirely by Supabase Auth (no third-party involvement)

Waitlist

  • Loops.so: marketing-site waitlist signups

Analytics

  • PostHog: product analytics on marketing pages and inside the app (account-linked via Supabase user ID, plus email address on mobile $identify; no card content, no session recording)

Link Preview (server-side only, when you save a link)

  • api.fxtwitter.com: when you save a Twitter/X link
  • youtube.com/oembed: when you save a YouTube link
  • reddit.com/….json: when you save a Reddit link

These calls are made from our server to fetch link metadata. Your IP address is not sent; only the URL of the link you saved is.

6. Cookies and Local Storage

We use cookies and local storage minimally:

  • Supabase Auth session cookies (HttpOnly, Secure, SameSite=Strict) on the web: required for sign-in to work; cleared when you sign out
  • PostHog distinct-id cookie on marketing pages: anonymous, used to deduplicate sessions. Never set on /app routes.
  • Vercel Analytics and Vercel Speed Insights do not set cookies
  • localStorage in the web app: caches your settings, theme, sidebar state, and sync cursors locally on your device; never read from the server
  • AsyncStorage on mobile: local data store and analytics distinct ID; cleared when you uninstall the app

We do not use third-party cookies for advertising, retargeting, or cross-site tracking.

7. Data Storage and Security

  • All data is encrypted at rest via Supabase (AES-256)
  • All data in transit is encrypted via HTTPS/TLS
  • Web sessions use HttpOnly, Secure, SameSite=Strict cookies
  • Row Level Security (RLS) is enabled on every database table; queries are scoped to the authenticated user
  • Screenshot storage uses per-user path isolation
  • We never log card content, prompt text, conversation messages, passwords, or authentication tokens
  • Mobile auth tokens are stored via Expo SecureStore (iOS Keychain on iOS, encrypted with Android Keystore-backed keys on Android)
  • Desktop auth tokens are stored in the OS keychain

8. Data Deletion

You can delete your account at any time via Settings → Account → Delete Account. Deletion is permanent and removes:

  • All cards, prompts, conversations, and context profiles
  • All screenshots and uploaded files
  • All embeddings and search indexes
  • All projects, tags, and saved links
  • Your authentication account and profile
  • All shared prompt links (public pages are revoked)

You can export all your data as a ZIP file before deleting (Settings → Import/Export). To request deletion by email, contact [email protected].

9. Children's Privacy

Helium is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

10. Changes to This Policy

We may update this privacy policy from time to time. For material changes, we will notify you via email or an in-app notification. The “Effective date” at the top reflects the latest revision. Continued use of Helium after changes constitutes acceptance.

11. Contact

Questions about privacy? Contact us at [email protected].