Back to Homepage

Privacy Policy

Last updated: August 22, 2026 · Applies to MissionHelm AI (missionhelm.ai)

Secure Platform

The short version

  • We collect only what the app needs to function: your account details and the tasks, quests, habits, plans, chats and focus sessions you create.
  • Your Google Workspace data is used in-memory to perform actions you request — we never sell it, never use it for ads, and never train AI models on it.
  • All data is stored encrypted-in-transit and at rest; Google OAuth refresh tokens are AES-256-GCM encrypted.
  • You can export or permanently delete everything at any time from the app or by emailing us.

1. Introduction

Welcome to MissionHelm AI ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application and website (together, the "Service").

Please read this policy carefully. If you do not agree with it, please do not access or use the Service. By using MissionHelm AI you accept the practices described here.

2. How We Use Google User Data

Google API Scopes Disclosure: MissionHelm AI requests access to specific Google Workspace API scopes to power its autonomous productivity and file management tools. We adhere strictly to the Google API Services User Data Policy, including its Limited Use requirements.

We request and use the following Google scopes exclusively for the features listed:

  • Google Calendar (.../auth/calendar):To fetch your schedule, identify conflicts, suggest optimal task slots, and write new productivity events to your calendar.
  • Google Drive (.../auth/drive.file):To create and restore your signed data backups on your own Drive — files our app created, nothing else.
  • Google Documents (.../auth/documents):To export your timetables as Google Docs on your request.
  • Google Tasks (.../auth/tasks):To two-way sync your MissionHelm tasks with your Google Tasks lists.
  • Basic profile (userinfo.email, userinfo.profile):To identify your account when you sign in with Google.

Google Workspace data is processed only to fulfil the action you trigger (e.g. "sync my calendar"). It is not shared with third parties, not used for advertising, and not used to train machine-learning or AI models. Access tokens are kept in memory for the duration of a request; refresh tokens are stored encrypted (AES-256-GCM) solely to maintain your connection, and are deleted immediately when you disconnect your Google account.

3. Information We Collect

Account information: name, email address, optional profile picture, gender, date of birth and workstation address that you provide at registration or in Settings.

Productivity content: the tasks, subtasks, quests, habits, daily plans, chat conversations, focus sessions and AI decisions you create inside the app.

Usage & security metadata: IP addresses and device/user-agent strings (kept to warn you about unfamiliar logins), and AI usage counters used to enforce free-tier limits (auto-deleted after 48 hours).

Authentication data: a bcrypt hash of your password (never the password itself), and for 2FA users a TOTP secret encrypted with AES-256-GCM.

Payment data: handled entirely by our payment processor (Razorpay). We store only plan names, order/payment identifiers and expiry dates — never card numbers or UPI credentials.

4. How We Use Your Information

  • To operate the Service: authenticate you, store your productivity content, generate schedules and power the AI assistant.
  • To sync with the Google services you explicitly connected.
  • To send transactional email: verification, password reset, and new-login security alerts.
  • To enforce free-tier limits, prevent abuse, and detect compromised accounts.
  • To process subscriptions and manage premium entitlements.

We do not sell, rent, or trade your personal information. We do not use your data for behavioural advertising or model training.

5. AI Processing

When you use AI features (task analysis, timetable generation, Mission Control chat), the relevant content is sent to our configured AI provider(s) solely to generate your result. These providers act as processors under their own terms; prompts are not used by us to train models. You can review and change the active AI provider configuration as an administrator, and you can avoid sending content to AI simply by not using the AI features.

6. Data Storage & Security

  • Data is transmitted over TLS and stored on managed cloud infrastructure (MongoDB Atlas / Google Cloud).
  • Sessions use signed HttpOnly cookies (__Host--prefixed in production) with SameSite protections; passwords are hashed with bcrypt.
  • Google refresh tokens, TOTP secrets and SMTP credentials are encrypted at rest with AES-256-GCM; backups are HMAC-signed so tampered archives are rejected on restore.
  • Requests are protected by rate limiting, strict Content-Security-Policy headers, and same-origin enforcement.

No method of transmission or storage is 100% secure, but we design every layer to minimise risk and respond quickly to incidents.

7. Data Retention & Deletion

Your productivity content is retained while your account is active. AI usage counters are auto-deleted after 48 hours. When you delete your account (or request deletion), we remove your profile, tasks, goals, plans, chats, focus sessions and stored Google tokens. Backups containing your data age out of rotation within 30 days. Disconnecting Google Workspace deletes the stored refresh token immediately.

8. Your Rights

Depending on your jurisdiction (including under India's DPDP Act, 2023 and the EU GDPR), you have the right to:

  • Access and obtain a copy of your data (in-app exports and Drive backups).
  • Correct inaccurate information (Profile → Settings).
  • Withdraw consent and disconnect integrations at any time.
  • Erase your account and associated data.
  • Grievance redressal as required under Indian law (contact below).

We respond to verified requests within 30 days.

9. Cookies

We use a single essential, HttpOnly session cookie to keep you signed in ("Remember me" keeps it up to 7 days; otherwise it expires with your browser). We do not use advertising or cross-site tracking cookies. Optional analytics (Cloudflare Web Analytics / Vercel Analytics) collect aggregate, non-identifying usage metrics only.

10. Children's Privacy

The Service is available to users aged 10 and up; minors under 18 may use it only with parental or guardian consent, and we process their data minimally and securely as required under applicable law. We do not knowingly collect data from children under 10; if we learn that we have, we delete it promptly.

11. Changes to This Policy

We may update this policy to reflect product or legal changes. Material changes will be announced in-app or by email before they take effect. The "Last updated" date above shows the current version.

12. Contact Us

Questions, requests, or grievances about this policy or your data:

[email protected]

Grievance Officer, MissionHelm AI (India). We aim to acknowledge queries within 72 hours.