Privacy Policy
Last updated June 22, 2026
Helmsly is an AI chief of staff that reads your email and calendar to give you a daily briefing, triage your inbox, and draft replies you ask for. This policy explains what we access, how we use it, and how we protect it.
What we access (with your permission)
When you connect Google, you grant Helmsly access via Google OAuth to:
- • Your Gmail messages, read-only (to summarize, triage, and read a thread when you ask for a draft).
- • The ability to create Gmail drafts (only when you click to draft a reply — Helmsly never sends email).
- • Your Google Calendar, read-only (for your briefing and meeting context).
- • Your Google Contacts, read-only (to build accurate people profiles).
- • Your basic Google profile (name, email) to identify your account.
How we use it
We use your data solely to provide Helmsly's features — your morning briefing, inbox triage, the reply drafts you request, and people profiles. We do not use your data for advertising, and we do not sell it.
AI processing
To generate briefings, triage, and drafts, relevant content is sent to our AI provider (Anthropic) to produce your result. This data is not used to train generalized AI models and is not retained by the provider beyond producing the response.
What we store
We store email metadata and snippets (not full message bodies) for recent inbound and sent mail — including From/To/Cc addresses — calendar event details, contact details from Google Contacts (name, email, title, organization, photo; no notes, physical addresses, or phone numbers), your generated briefings, triage results, and person profiles, meeting prep dossiers, your voice preferences, your explicit preferences and permission-policy settings, memories you explicitly save (kept until you delete them or your account), and encrypted Google tokens. If you queue a drafted reply for review, we store that queued reply (recipients, subject, body) and an append-only audit log of your review decisions — this is an internal review queue; Helmsly does not send email. Full email and thread bodies are fetched only when needed (for example, to draft a reply) and are not stored.
Security
OAuth tokens are encrypted at rest with AES-256-GCM. Access is restricted per-user with database row-level security. All traffic is served over HTTPS.
Your control
You can disconnect Google at any time from Settings, which revokes our access and deletes your stored Google data, and you can delete your account. To request deletion or ask a question, contact us below.
Limited Use
Helmsly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions or data requests: brandon@uniquemarketingservices.co.