Privacy
What we collect, why, who else touches it, and how to get it back or get it gone.
Updated
This policy covers the helmsman.sh website, the release-notes email list, your Helmsman account,
and the Helmsman app. It is written in plain language. Helmsman is an
independent project, and its operator is the data controller for the personal
data described here. Questions go to
hello@helmsman.sh.
The short version
- We collect only what we need to run the email list, your account, and billing.
- Helmsman is local-first: your code, prompts, and terminal output run on your computer and do not pass through a Helmsman server.
- When you use the app's AI features with your own key, each request goes straight to Anthropic or OpenAI under that key. See Your own key below.
- We do not sell or share your personal data, and we run no ad tracking.
- This site uses strictly-necessary cookies only, so there is no cookie banner.
What we collect
The data we hold depends on how you use Helmsman.
- Release-notes list. The email address you submit, plus a timestamp. Stored lowercased in a deduplicated set.
- Account. Your email address and display name, and a short bio if you add one. There is no password: you sign in with Google or with a code we email you. We keep each sign-in session with its IP address and browser. If you sign in with Google or GitHub, we keep the link to that account, with the tokens it issued at sign-in. The desktop app requires an account, so your account also holds the install id of each copy you sign in on (see launch analytics) and two app preferences you sync: the caffeinate default and the usage direction.
- Your own key. We store no AI key. The desktop app keeps your Anthropic or OpenAI key on your computer, encrypted with your system's key store, and sends each request straight to that provider. Remove the key in Settings at any time.
- Billing. If you subscribe to Pro, our payment provider collects and processes your payment details. We do not see or store full card numbers. We keep a record that you are a paying customer and your subscription status.
- Technical and security data. Minimal server logs and short-lived per-IP rate-limit counters used to keep the site and forms working and to block abuse. The site uses cookieless, aggregate web analytics (Vercel Web Analytics): page views and referrers with a visitor hash that resets every day. It also collects anonymous page-speed measurements (Vercel Speed Insights) so we can see where the site loads slowly. No advertising trackers, no cross-site tracking, no analytics cookies.
- App updates. The desktop app checks for a new build at launch, every hour, and on wake or focus. Each check sends a build key that every copy shares and a random update id that the updater keeps on your computer. Our server reads only the build key.
- Launch analytics. On by default in the desktop app - two small pings so we can tell whether the launch works. See launch analytics below.
- Crash reports. Off until you agree. After a crash, the app can send one short report. See crash reports below.
Launch analytics (on by default)
The desktop app sends us two small pings so we can tell whether the launch works: one when the app starts, and one the first time you spawn a session. Each ping carries exactly four fields:
event, which of the two pings this is;-
install_id, a random token generated on your computer at first launch. The ping itself carries no account, and the token is never derived from your hardware; app_version, for example0.9.0;-
os_major, your operating system's major version only, for examplemacOS 15. During the beta every value carries themacOSprefix, on Windows and Linux too. The patch number never leaves your computer.
That is the whole payload. It never carries prompts, agent output, file paths, project names, or any content, and our server rejects any submission with more than these four fields. We never store your IP address with these pings. Rows older than 400 days are deleted.
The app requires sign-in. At sign-in and once each launch, it also makes a separate, authenticated call that links your install id to your account, so we can count how many installs belong to each account. This call runs with the analytics switch off too. The pings themselves carry no account, but your account holds the same install id, so we can connect the pings to you. The link is deleted with your account.
Turn the pings off with the launch analytics switch in Settings; with it off the app
sends no pings. To erase what has been sent, use "Delete my analytics" next to it, or
email the id shown there to
hello@helmsman.sh.
Check us: start Helmsman from a terminal with
HELMSMAN_TELEMETRY_DEBUG=1 and the app prints every ping it would
send, and sends none of them.
The app shows this notice once, on first launch.
Crash reports (off until you agree)
After a crash, the desktop app asks before it sends anything. You see the exact report and its id, and you choose Send, Don't send, or Always send. With Always, later reports go out without a question. Change the choice in Settings › General at any time.
A report holds seventeen fields: a random report id, what kind of crash it was, which process stopped and why, its exit code, the app and Electron versions, your operating system, its major version and your processor type, the error name and code, up to 30 places in the app's own files where the error passed (each place is a file name inside the app, a function name, a line, and a column, never the code itself), and three rough ranges: how long the app ran, how much memory it used, and how many sessions were open.
If the app quit without warning, the report can also hold a short summary of the crash report that macOS wrote on your computer: the error type, the signal, the name of the thread that stopped, the names of the Helmsman, Electron, and macOS libraries it passed through, and code positions inside Helmsman and Electron. It never holds the rest of that macOS report: no machine id, no user id, no Mac model, no paths, and no names of other software. The app reads that macOS report on your computer to show it to you, and sends nothing before you choose.
That is the whole report. It never holds the error message, prompts, agent output, terminal output, paths on your computer, project names, environment values, command arguments, your account, or the launch analytics id. Our server rejects any report with other fields. We never store your IP address with a report, and we store only the day it arrived. Reports older than 90 days are deleted.
To delete reports that you sent, use "Delete sent reports" in Settings, or email a report id
to hello@helmsman.sh.
Check us: start Helmsman from a terminal with HELMSMAN_CRASH_DEBUG=1. The app
prints every report that it would send, and sends none of them.
Why we collect it, and our legal basis
Under the GDPR we need a lawful basis for each use. Ours are straightforward:
- To run your account and provide the app - basis: performance of our contract with you.
- To take payment and manage your subscription - basis: performance of our contract, and compliance with tax and accounting law.
- To email you release notes and product news after you sign up - basis: your consent, which you can withdraw at any time.
- To secure the service and prevent abuse - basis: our legitimate interest in keeping Helmsman safe and available.
- To measure whether the public launch works - basis: our legitimate interest in understanding adoption of the app we ship; object by turning the toggle off.
- To find and fix crashes in the app - basis: your consent, which you can withdraw at any time in Settings.
Bring your own key, and Anthropic as your own provider
Helmsman runs your own agent CLIs and your own model access. How your prompts travel depends on what you use:
- Agent CLIs. When Helmsman runs Claude Code, Codex, or another agent CLI, your prompts and code context go straight from your computer to that CLI's provider, exactly as they would if you ran the CLI in your own terminal. They do not pass through a Helmsman server.
- AI features with your own key. When you give the app an Anthropic or OpenAI key, the app sends the content of the feature you use (for example the diff for a commit message), together with that key, straight to that provider. Each provider processes that data as an independent provider under its own terms.
- Plan usage. If Claude Code is signed in to a Claude plan, the app uses that sign-in to read your plan limits from Anthropic every 3 minutes. The request goes straight to Anthropic.
In each case the provider acts as your own model provider for the content you send to its models, under your own key or session - not as a Helmsman sub-processor, and that content does not pass through a Helmsman server. Anthropic states that, by default, it does not use commercial API inputs or outputs to train its models. Your use of Anthropic is governed by Anthropic's own agreements:
- Anthropic Data Processing Addendum - anthropic.com/legal/data-processing-addendum
- Anthropic sub-processor list - trust.anthropic.com/subprocessors
- Anthropic Privacy Policy - anthropic.com/privacy
Your use of OpenAI is governed by OpenAI's own agreements, including its privacy policy.
Who else processes your data
We keep the list of third parties short, and we use each only to run the service. The providers that may handle your data are:
- Vercel - hosts this site and runs the signup and account endpoints.
- Upstash - stores the release-notes list and short-lived abuse-prevention counters (a managed Redis store).
- Neon - the managed Postgres database for your account, launch analytics, and crash reports.
- Resend - sends our transactional email (sign-in codes, account confirmation links, and release notes).
- Cloudflare - serves the app download and app updates (R2 storage) and, where enabled, bot protection (Turnstile); it processes the requesting IP address for these.
- Google, or GitHub where offered - confirms who you are when you sign in with that account.
- A Merchant-of-Record payment provider (for example, Paddle) - takes payment, handles tax, and acts as the seller of record for Pro.
- Anthropic and OpenAI - receive the model content you send under your own key or session; they are your own providers, not Helmsman sub-processors (see above).
We do not sell or share your personal data with anyone for their own marketing, and we do not build advertising profiles. If our list of providers changes, we will update this page.
How long we keep it
- Release-notes email - until you unsubscribe or ask us to remove it.
- Account data - for as long as your account is open. When you delete your account, we delete it, except where law requires us to keep records.
- Launch analytics - rows older than 400 days are deleted.
- Crash reports - rows older than 90 days are deleted.
- Your AI key - we keep none. The app keeps it on your computer until you remove it.
- Billing records - kept as long as tax and accounting law require.
- Security logs and rate-limit counters - short-lived: rate-limit counters within minutes to hours, and minimal server logs within days.
International data transfers
Some of our providers process data outside your country, including in the United
States. Where personal data leaves the European Economic Area or the UK, we rely
on the approved transfer mechanism for your region, such as the European
Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum
for UK data, and, where a provider is certified, the EU-US Data Privacy Framework (and
its UK extension). You can request a copy of the relevant safeguards by
emailing hello@helmsman.sh.
Wherever you live, we remain responsible for the personal data we pass to these
providers. Anthropic's transfer terms are covered by its
DPA.
Your rights
Depending on where you live, you have rights over your personal data, including under the GDPR and the CCPA. These include the right to:
- Access a copy of the data we hold about you.
- Correct data that is wrong or out of date.
- Delete your data (sometimes called the right to be forgotten).
- Export your data in a portable form.
- Object to processing we base on legitimate interest, including security and anti-abuse.
- Restrict how we process your data while a question about it is being resolved.
- Opt out of any sale or sharing of personal data - note that we do neither.
- Withdraw consent at any time, where we rely on consent. For crash reports, choose Never in Settings, and use Delete sent reports to erase what you sent.
To exercise any of these, email
hello@helmsman.sh. We will not
charge you or treat you differently for asking. You also have the right to complain to
the privacy regulator where you live. In the EEA that is your local Data Protection
Authority (in the Netherlands, the
Autoriteit Persoonsgegevens);
in the UK, the Information Commissioner's Office (ICO).
If there is a data breach
If a breach affects your personal data, we will act quickly to contain it. Where the law requires, we will notify the relevant supervisory authority without undue delay, and we will tell affected users without undue delay when the breach is likely to put your rights at risk.
Children
Helmsman is not directed to children. We do not knowingly collect personal data from anyone under 18, and if we learn that we have, we will delete it.
Cookies
This site sets strictly-necessary cookies only - the kind needed to keep you signed in and to keep the forms secure. We set no analytics, advertising, or cross-site tracking cookies, so there is no cookie banner to click through.
Changes
If our practices change, we will update this page and move the "last updated" date above. Significant changes that affect you will be flagged clearly.
Contact
Questions, requests, or concerns about your data? Email
hello@helmsman.sh and a person
will reply.