Last updated: August 22, 2026 · Applies to MissionHelm AI (missionhelm.ai)
Welcome to MissionHelm AI ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application and website (together, the "Service").
Please read this policy carefully. If you do not agree with it, please do not access or use the Service. By using MissionHelm AI you accept the practices described here.
Google API Scopes Disclosure: MissionHelm AI requests access to specific Google Workspace API scopes to power its autonomous productivity and file management tools. We adhere strictly to the Google API Services User Data Policy, including its Limited Use requirements.
We request and use the following Google scopes exclusively for the features listed:
.../auth/calendar):To fetch your schedule, identify conflicts, suggest optimal task slots, and write new productivity events to your calendar..../auth/drive.file):To create and restore your signed data backups on your own Drive — files our app created, nothing else..../auth/documents):To export your timetables as Google Docs on your request..../auth/tasks):To two-way sync your MissionHelm tasks with your Google Tasks lists.userinfo.email, userinfo.profile):To identify your account when you sign in with Google.Google Workspace data is processed only to fulfil the action you trigger (e.g. "sync my calendar"). It is not shared with third parties, not used for advertising, and not used to train machine-learning or AI models. Access tokens are kept in memory for the duration of a request; refresh tokens are stored encrypted (AES-256-GCM) solely to maintain your connection, and are deleted immediately when you disconnect your Google account.
Account information: name, email address, optional profile picture, gender, date of birth and workstation address that you provide at registration or in Settings.
Productivity content: the tasks, subtasks, quests, habits, daily plans, chat conversations, focus sessions and AI decisions you create inside the app.
Usage & security metadata: IP addresses and device/user-agent strings (kept to warn you about unfamiliar logins), and AI usage counters used to enforce free-tier limits (auto-deleted after 48 hours).
Authentication data: a bcrypt hash of your password (never the password itself), and for 2FA users a TOTP secret encrypted with AES-256-GCM.
Payment data: handled entirely by our payment processor (Razorpay). We store only plan names, order/payment identifiers and expiry dates — never card numbers or UPI credentials.
We do not sell, rent, or trade your personal information. We do not use your data for behavioural advertising or model training.
When you use AI features (task analysis, timetable generation, Mission Control chat), the relevant content is sent to our configured AI provider(s) solely to generate your result. These providers act as processors under their own terms; prompts are not used by us to train models. You can review and change the active AI provider configuration as an administrator, and you can avoid sending content to AI simply by not using the AI features.
__Host--prefixed in production) with SameSite protections; passwords are hashed with bcrypt.No method of transmission or storage is 100% secure, but we design every layer to minimise risk and respond quickly to incidents.
Your productivity content is retained while your account is active. AI usage counters are auto-deleted after 48 hours. When you delete your account (or request deletion), we remove your profile, tasks, goals, plans, chats, focus sessions and stored Google tokens. Backups containing your data age out of rotation within 30 days. Disconnecting Google Workspace deletes the stored refresh token immediately.
Depending on your jurisdiction (including under India's DPDP Act, 2023 and the EU GDPR), you have the right to:
We respond to verified requests within 30 days.
We use a single essential, HttpOnly session cookie to keep you signed in ("Remember me" keeps it up to 7 days; otherwise it expires with your browser). We do not use advertising or cross-site tracking cookies. Optional analytics (Cloudflare Web Analytics / Vercel Analytics) collect aggregate, non-identifying usage metrics only.
The Service is available to users aged 10 and up; minors under 18 may use it only with parental or guardian consent, and we process their data minimally and securely as required under applicable law. We do not knowingly collect data from children under 10; if we learn that we have, we delete it promptly.
We may update this policy to reflect product or legal changes. Material changes will be announced in-app or by email before they take effect. The "Last updated" date above shows the current version.
Questions, requests, or grievances about this policy or your data:
[email protected]Grievance Officer, MissionHelm AI (India). We aim to acknowledge queries within 72 hours.