Privacy Policy
Helvety by Rubin ("we," "us," or "the Company") explains how we handle information when you use helvety.com, helvety.cloud, and related Helvety products ("the Services"). This notice is based primarily on the Swiss Federal Act on Data Protection (nDSG / FADP). The Services are intended for customers in Switzerland. We do not offer the Services in the EU/EEA. Where mandatory law elsewhere applies in a specific case, we follow those obligations.
helvety.com public browser tools and the Store do not require a Helvety account. Helvety Cloud (helvety.cloud) does: email one-time codes for sign-in, and separate device unlock for end-to-end encryption. Encrypted workspace content is opaque to Helvety.
1. Data Controller
Helvety by Rubin (Caspar Camille Rubin), Holeestrasse 116, 4054 Basel, Switzerland. UID CHE-356.266.592. Email: contact@helvety.com.
2. Services and Processing
This notice covers helvety.com marketing and legal pages, Helvety Store, the public browser tools below, Helvety Cloud at helvety.cloud, and separately distributed desktop or Microsoft 365 products that link here.
- Helvety PDF (helvety.com/pdf): Merge, reorder, rotate, extract, and related supported actions keep file contents inside your browser under the current architecture. Nothing is uploaded to our servers for conversion.
- Helvety Image Editor (helvety.com/image-editor): Annotation and export workflows run locally in your browser under the current architecture. Image files are not uploaded to our servers for processing.
- Helvety OCR (helvety.com/ocr): Text extraction runs locally in your browser under the current architecture with on-device optical character recognition. Files are not uploaded to our servers for processing.
- Helvety Store (helvety.com/store): Catalog browsing and public package downloads work without registration. We may process IP address and related technical metadata for security, rate limiting, and abuse prevention.
- Power Platform Configurator: Choose classic or new designer for Power Automate flow/run URLs. Control survey flags. Reveal or enable Power Apps form elements. Power Automate: choose Classic Designer, New Designer, or Paused; Hide sets v3survey=false on rewrites, while Show only normalizes an existing parameter. Power Apps: reveal hidden tabs, sections, and controls or enable disabled controls on supported model-driven record forms. The extension reads supported flow/run URLs and accesses model-driven form UI objects locally only to apply the selected behavior. Preferences stay in browser storage. The extension does not send tab URLs, form content, or preferences to Helvety servers. Your browser and sync provider may process stored preferences under their own terms.
- Helvety SPO Explorer: SharePoint Framework package distributed via the Store. Runs in your Microsoft 365 tenant under Microsoft's hosting and your organization's policies.
- Helvety Screen Tools: Windows desktop app distributed outside this monorepo. Screenshot and annotation content stays on your device in normal operation.
- Helvety Cloud (helvety.cloud): Passwordless, end-to-end encrypted workspace service. Sign-in uses email one-time codes. Encryption unlock and decryption happen only on your device (WebAuthn PRF / passkey and related client-held material). Helvety stores account metadata and opaque ciphertext. It cannot decrypt workspace content and does not hold a master key.
AI model training and retention statement: We do not use files you open in Helvety PDF, Helvety Image Editor, or Helvety OCR to train AI models. Under the current architecture those tools keep content on your device and only use minimal server-side endpoints for platform and security functions (for example CSP reporting). We also do not use Helvety Cloud ciphertext or decrypted workspace content to train AI models.
3. What We Collect
3.1 helvety.com and public tools
Because there is no helvety.com account, we do not maintain user profiles or passwords for public tools on our servers.
- Technical metadata: IP address and request timestamps from standard web server and hosting logs, plus security signals needed for rate limiting and abuse prevention (including Store downloads). We do not use third-party analytics on our web Services and do not build navigation or usage profiles of visitors.
- Support messages: Whatever you choose to send when you email us.
- On-device preferences: Theme and tool UI settings stored in your browser (see Cookies and Local Storage).
3.2 Helvety Cloud account and metadata
When you use Helvety Cloud, Helvety processes:
- Email address and authentication metadata (for example OTP delivery via Supabase Auth).
- Workspace invitation email addresses (including invitees who have not yet created an account), plus invitation claim and accept timestamps.
- Profile and membership records (user id, workspace membership, timestamps).
- Public cryptographic material needed for the product (for example user public keys) and wrapped or encrypted blobs that Helvety cannot decrypt.
- Policy acceptance records (which policy versions you accepted and when), including geographic eligibility acknowledgment.
- Technical logs reasonably needed to operate and secure the Service (for example IP addresses in hosting/auth logs, request metadata).
- Billing metadata when you use paid plans (for example subscription status and meter counts). Billing never includes encrypted plaintext or raw encryption keys.
- Intentional plaintext product metadata that is not ciphertext: for example workspace membership, entity-link UUID pairs (which ids are linked, never titles or colors), categorization soft-reference ids on tasks, attachment operational fields (byte size, storage path, status, and which entities link to an attachment id), and similar operational fields needed to run the Service. Filenames and file bytes remain ciphertext.
3.3 Data Helvety cannot access
Encrypted Helvety Cloud content (ciphertext) is opaque to Helvety. Staff, database administrators, and privileged database roles cannot decrypt titles, bodies, board graphs, comments, contact fields, filenames, file bytes, or other plaintext from your encrypted data. Helvety does not receive PRF output, unlock keys, recovery key plaintext, or raw private keys. Helvety cannot restore your data if you lose unlock or recovery material. Helvety is not a controller of plaintext it cannot access.
4. How We Use Information
Under Swiss nDSG we process personal data for the purposes below where processing is connected with a contract with you, needed to take pre-contractual steps you request, justified by overriding private interests that are not outweighed by yours (for example security, abuse prevention, and reliable hosting), based on your consent where we ask for it, or required to meet Swiss legal duties.
- Operate and secure helvety.com, Helvety Store, Helvety PDF, Helvety Image Editor, Helvety OCR, and related public pages (local-only browser file tools under the current architecture).
- Provide and secure Helvety Cloud: authenticate you, manage accounts and workspaces, store ciphertext and related metadata, deliver workspace invitations (including to invitee email addresses), and record policy acceptances.
- Deliver public package downloads, apply rate limits, and investigate abuse.
- Bill and account for paid Helvety Cloud plans (contract / legal obligation).
- Respond to support and legal requests you or authorities send, limited to data Helvety actually holds.
- Meet Swiss legal, tax, and accounting duties where records are required.
5. Processors and Subprocessors
We use infrastructure providers to host and protect the Services. Typical categories include:
| Category | Role |
|---|---|
| Hosting / CDN | Serve helvety.com zones, helvety.cloud, and static assets (currently Vercel). Request routing and edge delivery may involve processing in the United States and other Vercel edge regions in addition to Swiss or EU points of presence, depending on visitor location and vendor configuration. |
| Auth / database (Cloud) | Supabase: authentication and Postgres for Helvety Cloud in Zurich (eu-central-2). Processes account email/auth metadata and ciphertext/metadata as described above. |
| Object storage (Cloud files) | Supabase Storage in the same Zurich Helvety Cloud project: opaque encrypted attachment ciphertext objects. Helvety stores size and path metadata for quotas; it cannot decrypt filenames or file contents. |
| Email (Cloud auth) | OTP, invitation, and auth emails via Supabase Auth and its configured email providers. Message delivery may involve processing outside Switzerland (for example EU or US regions depending on vendor email configuration). |
| Payments (Cloud) | Stripe (typically Ireland and/or United States entities, depending on account configuration): billing identity and payment metadata for Pro Workspace and add-ons. Never encrypted plaintext or raw encryption keys. |
| Rate limiting | Distributed limits for Store downloads (currently Upstash Redis) |
| Package delivery | GitHub Releases (or equivalent) for public .sppkg downloads |
| Chrome Web Store | Distribution of Power Platform Configurator by Google |
Primary Helvety Cloud database, auth, and attachment object storage are hosted in Switzerland (Zurich). Hosting, CDN, payments, and email tooling may involve processing in other countries or regions (including the United States and EU member states) depending on vendor configuration and where you connect from. Where Swiss law requires safeguards for transfers abroad, Helvety relies on appropriate mechanisms offered by those vendors (for example standard contractual clauses, adequacy where recognized, and contractual security terms).
Microsoft 365, SharePoint / Power Platform runtimes, browser vendors, and Windows operate under their own terms when you use SPO Explorer, Power Platform Configurator, or Screen Tools. We do not sell personal data. This subprocessors list may change; material changes will be reflected on this page.
6. Retention
Hosting and security logs are kept only as long as needed for operations, abuse handling, and legal holds (typically up to about 6 months for routine security metadata under current policy). Contract or accounting evidence may be kept longer where Swiss law requires it (for example up to 10 years). Browser-local files and preferences remain on your device until you clear them.
For Helvety Cloud: account and membership data are kept while your account is active and for a reasonable period afterward as needed for security, dispute handling, and legal retention. Ciphertext and related encryption metadata are kept while associated with your account or workspaces, or until deleted via the Service or account closure. Account closure deletes workspaces where you are the only member (including your Personal workspace) and their ciphertext. Shared workspaces with other members are not wiped for those members. Policy acceptance records are retained to evidence which terms applied.
7. Your Rights
Under the Swiss nDSG you may request access, correction, deletion, or restriction of personal data we hold, and object to certain processing, subject to legal exceptions. Contact contact@helvety.com. Helvety may need to verify your identity. Helvety cannot produce encrypted plaintext it never held.
For helvety.com public tools there is no self-service export or deletion dashboard; we generally hold only technical metadata and any messages you sent us. For Helvety Cloud, erasure of account data does not recreate lost encryption keys. Deleting ciphertext removes stored blobs; it does not mean Helvety ever held plaintext. You may lodge a complaint with the Swiss FDPIC or another competent supervisory authority where applicable. The Service is not directed to children under 16.
9. Controller, Processor, and DPA
Helvety is the controller of Helvety Cloud account, authentication, invitation, policy-acceptance, and billing metadata described in this notice. Helvety stores end-to-end encrypted workspace ciphertext it cannot read and is not a controller of that plaintext.
If you are an organization that needs a written Swiss nDSG Art. 9 processor agreement for Helvety's processing of Cloud account metadata on your documented instructions, see the Helvety Cloud Data Processing Addendum (metadata). That addendum does not cover encrypted workspace plaintext Helvety cannot access.
10. Changes
We may update this Privacy Policy when the Services change. The "Last reviewed" date at the top shows the latest review. Material changes will be reflected on this page. For Helvety Cloud, material changes that affect signup-gated acceptance use a new version string you must accept before continued encryption setup or use where gated.
11. Contact
Privacy questions: contact@helvety.com. Related: Terms of Service, Cloud DPA (metadata), Impressum.