This Privacy Policy explains how Helstify ("Helstify", "we", "us", "our") collects, uses, and shares personal data when you use our website and platform (the "Service"). Helstify takes a business idea you describe in plain language and uses AI agents to validate it, name it, register a domain, build and host a website and backend, provision email mailboxes, and operate the resulting business on your behalf.
The legal entity operating Helstify is Helstify, established in [jurisdiction — to be confirmed], which is the data controller for the personal data described here. If you have any question about this policy or wish to exercise your rights, contact us at hello@example.com.
1. A note on where your data lives
We believe in being straight with you about our security posture rather than reciting reassurances. Helstify currently runs on a single server. Your account, your submitted ideas, the businesses we build for you, your provisioned mailboxes, and your operational data all live on that one machine. This has an important consequence you should understand before you rely on the Service: at present there is no off-site backup of your data, so a catastrophic failure or loss of that server could result in permanent loss of the data held on it. We are actively working to change this, and we describe the security measures we do apply in Section 9. We would rather tell you this plainly than imply a resilience we have not yet built.
2. Data we collect
Account information
- Your name, email address, and a password (stored only as a secure one-way hash — we never store or can recover your plaintext password).
- A public username/slug derived from your name, used for shareable links to idea results you choose to make public.
- Your role and any team memberships (businesses you own or have been invited to operate), including invitation email addresses.
- Login timestamps and email-verification status.
Idea and business content you submit
- The business-idea text you describe (up to roughly 2,000 characters per submission), along with any audience or context you provide.
- The analysis produced from it — scores, summary, target customer, risks, pros, flaws, suggested next steps, suggested names, and any follow-up questions and your answers to them.
- Whether you choose to make an idea analysis public via a share link. By default your ideas are private; publishing is your choice.
- The businesses ("projects") we build and operate for you, including site content, configuration, DNS records, code, and the conversation history and instructions you exchange with the AI council.
Provisioned-mailbox contents
- When we provision email for a business, we create real mailboxes on our mail infrastructure. The messages sent to and from those mailboxes, and their contents, pass through and are stored on that infrastructure.
- Because your AI agents can be granted scoped access to read and answer mail on your behalf, mailbox contents may be processed by the agents and, through them, by the third-party AI providers described in Section 6. To make webmail auto-login and agent access work, we generate and hold the mailbox password, encrypted at rest.
- Mail delivery logs (sender, recipient, timestamps, delivery/spam status, quota usage) are retained for operating and troubleshooting the mail service.
Credentials and connected AI accounts
- If you connect your own AI provider via an API key ("bring your own key"), we store that key encrypted at rest and use it to call the provider on your behalf. We display only the last few characters and never log the full key.
- If instead you authenticate an AI CLI inside your own container, that credential stays on your side and is not transmitted to or stored by us.
- Other tool secrets you provide are stored encrypted, scoped, and revocable.
Payment information
- Card payments are processed by our third-party payment processor. We do not receive or store your full card number; we store a processor customer/subscription identifier and your subscription status, plan, and billing period.
- Cryptocurrency payments are settled on public blockchains. For a crypto payment we record the invoice amount, the token and chain, the receiving address, and — once you pay — the transaction hash, amount received, and block number. Please be aware that blockchain transactions, including the wallet address you pay from and the payment amount, are inherently public and permanent on the relevant network; that is a property of the blockchain, not something we control.
Support data
- Support tickets, their messages, and any attachments you send us.
Usage, log, and analytics data
- An audit log of significant actions in the panel (including AI-agent actions), which may record the action, a description, the affected object, and the originating IP address.
- First-party analytics events: pages visited, a visitor identifier, referrer host, and UTM campaign parameters, associated with your account where you are logged in.
- If you subscribe to product/marketing updates, your email address plus the source and referrer of the sign-up.
- Standard technical data your browser sends (e.g. IP address, user agent) as part of ordinary web-server and security operation.
3. How we use your data
- To provide the Service: analysing your idea, generating names, checking and registering domains, building and hosting your site and backend, provisioning mailboxes, and running autonomous operations you direct.
- To operate AI agents on your behalf within the scopes and limits you set.
- To create and manage your account, teams, and permissions.
- To take payment, manage subscriptions, and prevent payment fraud.
- To provide support and respond to your requests.
- To secure the Service, maintain the audit log, detect abuse, and debug problems.
- To understand product usage through analytics and, where you have opted in, to send you product updates.
- To comply with legal obligations.
4. Legal bases (GDPR)
Where the EU/UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you sign up for: account management, idea analysis, building and operating your businesses, mailbox provisioning, and billing.
- Legitimate interests — to secure the Service, maintain audit logs, prevent fraud and abuse, understand aggregate usage, and improve the product, balanced against your rights.
- Consent — for marketing emails and any non-essential analytics/cookies where consent is required. You may withdraw consent at any time.
- Legal obligation — where we must retain or disclose data to comply with law (for example, tax and accounting records).
5. When you bring your own AI key or content
When you submit an idea, mailbox content, or business content to be processed by AI agents, you are instructing us to send that content to the AI provider you have connected (or that the Service uses) for processing. You are responsible for ensuring you have the right to submit any personal data contained in that content, and for not submitting sensitive personal data you do not want processed by a third-party AI provider. Where you use your own API key or your own container credential, your own agreement with that provider also governs how they process the content.
6. Third-party processors and sub-processors
We share personal data with the following categories of service providers, only as needed to run the Service:
- AI providers — such as Anthropic (Claude), OpenAI (Codex), and Google (Antigravity). Idea text, business/build instructions, and — where you grant it — mailbox contents may be sent to the provider you connect so that agents can analyse, build, and operate on your behalf.
- Domain registrar and DNS provider(s) — our domain registrar partner, used to check availability and register/manage domains on your behalf; registration requires registrant contact details, which may be subject to WHOIS/registry requirements.
- Payment processors — our card payment processor, and the blockchain networks and node providers we use to observe on-chain crypto payments.
- Mail infrastructure — the mail server software that hosts your mailboxes and handles delivery.
- Hosting/infrastructure — our dedicated server infrastructure, on which Helstify and your businesses run.
- Transactional email — our own mail infrastructure, used to send account emails such as verification and password reset.
We will maintain an up-to-date list of sub-processors and, where required, put appropriate data-processing agreements in place with each.
7. International transfers
Some of the providers above (notably AI providers and payment processors) may process data outside your country, including in the United States. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision, as applicable. Blockchain networks are global and decentralised by design; data written to a public chain is not confined to any one jurisdiction.
8. Data retention
- We keep account and business data for as long as your account is active and as needed to provide the Service.
- Idea analyses, projects, and mailbox contents are retained until you delete them or close your account, subject to short operational delays.
- Billing and transaction records are retained as long as required for accounting, tax, and legal purposes.
- Audit logs and mail/delivery logs are retained for a limited period for security and troubleshooting.
- When you close your account we delete or anonymise personal data we no longer need, except where we must keep it to meet a legal obligation. Note that content already sent to a third-party AI provider, and any data already written to a public blockchain, is outside our ability to delete.
9. Security
We take reasonable measures to protect your data, and we describe them honestly rather than over-promising:
- Passwords are stored only as secure hashes; API keys, mailbox passwords, and tool secrets are encrypted at rest.
- Each business runs in its own isolated container with its own credentials, so one business cannot reach another's data.
- Agent actions are scoped, rate-limited, revocable, and recorded in an audit log.
- Traffic is served over TLS.
At the same time, you should know the limits: as described in Section 1, the Service currently runs on a single server without an off-site backup, so a catastrophic loss of that server could mean permanent loss of data. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security. We encourage you to keep your own copies of anything important to you (your domain, code, and data are yours and can be exported at any time).
10. Your rights
Depending on where you live (including under the GDPR and the California Consumer Privacy Act, as amended), you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data ("right to be forgotten"), subject to the practical limits noted above for third-party AI providers and public blockchains.
- Request a portable copy of data you provided (data portability).
- Object to, or request restriction of, certain processing, including processing based on legitimate interests.
- Withdraw consent at any time where we rely on consent.
- Opt out of marketing at any time via the unsubscribe link or by contacting us.
For California residents: we do not "sell" your personal information or "share" it for cross-context behavioural advertising as those terms are defined under the CCPA, and we will not discriminate against you for exercising your rights. To exercise any right, contact hello@example.com. We will respond within the timeframes required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
11. Children
The Service is not intended for children, and is not directed to anyone under 16 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact hello@example.com and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.
13. Contact
Data controller: Helstify, [jurisdiction — to be confirmed]. For any privacy question or to exercise your rights, email hello@example.com or write to us at [registered address — to be confirmed].