Skip to content

DRAFT. This text has not been reviewed by a lawyer and is not yet in force. It describes how Helder is designed to work.

Privacy policy

Last updated: 30 September 2026 · Nederlandse versie

Helder helps you stop paying for subscriptions and contracts you don't need. To do that we read part of your email. This policy says exactly what we read, what we keep, who we share it with and what your rights are.

Who we are

Helder (TODO: legal entity, Chamber of Commerce number and address) is the controller for the data described here. Privacy questions go to privacy@hldr.ai (TODO: placeholder address).

What we read

When you connect Google, you grant read-only access to Gmail (the gmail.readonly scope). We cannot send, delete or change email.

For messages from the last twelve months we read only:

  • the sender (From), subject and date;
  • the short preview snippet Gmail generates (roughly the first 200 characters).

We do not read full message bodies or attachments.

What we store

We store only the facts we extract: which provider you subscribe to, the price, how often you pay, when you last paid, and the ID of the message it came from (so you can see what a finding is based on). We also store what Helder did or proposed for you, and your choices.

We never store the content of your emails, including subjects and snippets, and we do not log them.

Your Google access token is used only during a scan.

What we use it for

Only to provide the service you see: finding your subscriptions, showing what you spend and could save, and cancelling or reminding you under your mandate. We do not use your data for advertising, do not sell it and do not use it to train AI models.

Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). Optional features ask for separate consent.

Google API Services: Limited Use

Helder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice:

  • we use Gmail data only to provide or improve user-facing features of Helder;
  • we do not transfer Gmail data to others except as needed to provide those features (the processors below), to comply with law, or as part of a merger or acquisition with prior notice to you;
  • we do not use Gmail data for advertising, including personalised or interest-based advertising;
  • no human reads your Gmail data unless you explicitly consent for specific messages, it is necessary for security (such as investigating abuse), it is required by law, or the data is anonymised and aggregated for internal operations;
  • we do not use Gmail data to develop, improve or train generalised AI or machine-learning models.

Processors

We work with these parties, each under a data processing agreement:

  • Supabase: database and sign-in, hosted in the EU (TODO: confirm region).
  • Vercel: hosting for the website and server. Requests may be processed outside the EU; we pin functions to EU regions where possible (TODO: confirm).
  • Anthropic: when our own rules can't read a receipt from an unknown sender, we send that one message's sender, subject and snippet to Anthropic's Claude to determine the amount and merchant. Anthropic does not use this data to train models. Anthropic processes in the US; transfers rely on the EU Standard Contractual Clauses / EU-US Data Privacy Framework (TODO: confirm).

When cancelling on your behalf, we give the provider only what it needs to find and cancel your subscription.

Retention

  • Email content: not retained; held in memory during a scan only.
  • Extracted facts and actions: for as long as you have an account.
  • After account deletion: erased within 30 days, backups within 90 days (TODO: confirm).

Revoking access and deletion

You can revoke Helder's Gmail access at any time at myaccount.google.com/permissions. You can delete your account and all data in the app or by emailing privacy@hldr.ai.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port and object. Send requests to privacy@hldr.ai; we respond within one month. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Security

Connections are encrypted (TLS), data is encrypted at rest and access within Helder is limited to those who need it.

Changes

If we change this policy materially, we'll tell you in the app before it takes effect.