Helm/SitesSign in

Privacy policy

Last updated: August 14, 2026

Helm Sites is a private business system. It is used by the staff of one company to run their own job sites, and it is not open to the public. This page explains, plainly, what it stores and who can see it.

What we store

  • Your account: your name, email address, role, and the colour shown on your avatar.
  • Your work: everything entered into the system: job sites, orders, materials and equipment, expenses and receipts, utility bills, claims, and estimates.
  • Activity: a log of who changed what and when, so a mistake can be traced back. Sign-in times and failed sign-in attempts are recorded to catch someone trying to break in.
  • Errors: when something breaks in your browser, the error and the page you were on are recorded so it can be fixed.

What we don't do

  • We do not sell your data, to anyone, ever.
  • We do not use it for advertising, and there are no adverts in the system.
  • There are no third-party analytics or tracking scripts. No Google Analytics, no advertising pixels, no session recorders.

Ask Helm and other assistance features

Ask Helm answers questions, runs searches, and turns typed instructions into actions. It reads what you type and the business data you already have access to. The same is true of the form assistance, suggested vendors, duplicate warnings, unusual-amount warnings.

None of this is sent to an outside AI service. There is no OpenAI, Anthropic, or other third-party model involved. The language handling runs inside this application on our own server, and what you type is stored only in your own account's history, which you can clear yourself from Account → Intelligence history.

Who processes your data on our behalf

  • Supabase: hosts the database, the accounts and passwords, and the uploaded receipt files.
  • Vercel: hosts and runs the application itself, and sees the web requests that reach it.

That is the complete list. Both are infrastructure providers holding the data so the system can run; neither is given it for their own purposes.

How it is protected

  • Traffic is encrypted in transit with HTTPS.
  • Every table enforces permissions in the database itself, not just in the screens, so what you can see and change is decided at the data layer, by role.
  • Uploaded receipts sit in a private storage area. They are never given a public link; opening one mints a temporary link that expires after five minutes.
  • Repeated failed sign-ins are throttled.

We have not commissioned an external security audit, and this page will not claim otherwise.

Backups

The database is backed up by Supabase, our hosting provider, on their own schedule. You can also export everything yourself at any time from Import / export, and we'd encourage keeping your own copy. A backup held by the same provider that holds the live data is not a substitute for one you control.

Your data is yours

  • The business owns everything entered into the system.
  • You can export all of it, in full, from Import / export.
  • Deactivating someone's account removes their access but deliberately keeps their history, so records stay attributable.
  • To have data deleted, ask. See below. We'll tell you what can be removed and what has to stay for the records to make sense.

Cookies and local storage

  • A cookie keeps you signed in. Without it, the system cannot tell who you are.
  • Your browser stores your own display preferences: theme, text size, density, accent colour, number format.
  • Nothing here tracks you across other websites.

Contact

Questions about this policy, or a request to delete data: mcfarlanematthias@gmail.com