Privacy Policy
Last updated: 2026-08-28
Helm AI is a workforce, finance and compliance platform used by companies ("workspaces"). This policy explains what we collect and why, for the web app and the Helm mobile apps.
What we hold
- Account data — your name, work email, role, and a hashed password. Passwords are never stored in readable form.
- Workspace data your employer enters — employee records, payroll, leave, documents, ledger entries. Your employer is the controller of this data; Helm processes it on their behalf.
- Location, only for attendance — if your employer enables geofenced attendance and you grant permission, the mobile app registers an office geofence with your phone's operating system. Enter/exit events (a coordinate and a timestamp) are sent to record attendance, including when the app is closed. We do not track your route or continuously record your position, and you can revoke the permission at any time in system settings.
- Device push tokens — so we can deliver notifications you enable.
- Sign-in metadata — IP-derived region and time, kept for security auditing.
- What you ask the assistant, and what it answers — the question, the reply, which assistant answered, whether it succeeded and how long it took. See "Assistant conversations" below, because a person at Helm can read these.
- Standalone WhatsApp assistant data — if you use the personal assistant on WhatsApp, Helm stores the conversation and short-term preferences against a hashed phone number. This is separate from company workspaces. You can ask Helm to delete it.
- Connected personal email — if you connect Gmail or Outlook, Helm stores an encrypted access grant and the mailbox address. Helm reads email only when you ask. The requested message content is sent to Helm's configured AI provider to answer you; it is not added to long-term personal facts or application logs. An unsent draft is encrypted and deleted after ten minutes unless you approve it. A sent receipt keeps only hashed recipient and subject values. Disconnecting or deleting your WhatsApp data removes the local grant and mail records.
What we do not do
- We do not sell personal data, to anyone, for any purpose.
- We do not use workspace data to train AI models.
- We do not read your location outside the attendance geofence feature.
- We do not use connected personal email to train an AI model.
Use of information received from Google Workspace scopes adheres to the Google API Services User Data Policy, including its Limited Use requirements.
AI features
Assistant responses are generated by a large-language-model provider processing the minimum context needed for your request. AI drafts are proposals — a human approves before anything takes effect.
Assistant conversations
Helm keeps what you ask the assistant and what it answers, and staff at Helm can read it. We do this to see how the assistant is answering and to find a fault when one is reported. We are telling you plainly rather than burying it.
- How long — thirty days, and at most the four hundred most recent exchanges for a workspace. Older ones are deleted automatically.
- What is removed before it is stored — a bank account number (IBAN) and a national identity or iqama number are masked in the record itself, so they are not in the stored text at all. Your name is not stored beside the exchange either: the person is a one-way code.
- Who can read it — an administrator of Helm's own workspace. Nobody at another customer can ever see it, and it never leaves your workspace's storage until such a read happens.
- Every read is recorded in your own audit trail, with the name of the person who read it. Your workspace administrator can open that trail under Settings, so you can see when we looked. If the record of the read cannot be written, the read does not happen.
- It is not used to train AI models, and it is never sold or shared.
The Helm helper (browser extension)
It is optional and separate. Helm works without it. You install it yourself, and you can remove it at any time from your browser's extensions page.
Saudi government portals refuse a request that comes from a datacentre address, so no Helm server can reach a portal's sign-in page. Your own browser is not refused. The helper is what lets Helm fill that form in your browser.
- What it does — opens the portal's own sign-in page in a visible tab, fills in the national ID or iqama number you typed into Helm, presses sign in, and reads the two-digit number the portal displays so you can match it in the Nafath app. You approve every sign-in on your own phone. Helm is not the portal, not Nafath, and not a government authority.
- What it may touch — the portal and your own Helm workspace, and nothing else. It asks for no permission over your browsing, your history or your cookies.
- It does nothing unless you press the button. On a portal page you opened yourself, it asks Helm first and is told to do nothing.
- The national ID is not stored and never reaches Helm. It goes from the Helm page into the portal's field and is then dropped. The extension does not keep it, and it is not sent to any Helm address.
- What does reach your workspace — which step the helper reached; the two-digit number the portal displayed; and, when a step cannot find what it expected or when you ask it to map a page, a description of that page's structure: its headings, its column names, its field names and its counts. Never a cell's contents, never a field's value, and every run of five or more digits is removed before it leaves your browser.
- One honest limit — a page heading is kept exactly as the portal wrote it, so a heading that names a person would carry that name. You can download the whole file and read it before you send it anywhere.
- No remote code. Everything the extension runs is in the package you installed. It receives data — a web address, the names of fields, the words on a button — and never code.
Storage and retention
Data is stored in Google Cloud, isolated per workspace. It is retained while your workspace is active; when a workspace closes, its data is deleted on the schedule agreed with the customer.
Your rights
For access, correction or deletion requests, contact your employer's administrator (the data controller) or us at support@helm-ai.sa. We comply with the Saudi Personal Data Protection Law (PDPL).