Privacy Policy

Last updated July 13, 2026

1. Introduction

HelpNest (“we,” “us,” or “our”) operates the HelpNest platform, an open-source customer help center that helps businesses create, manage, and publish knowledge bases and support articles.

This Privacy Policy describes how we collect, use, share, and protect your information when you use our website and services. It applies to all users of the HelpNest Cloud platform, including workspace owners, team members, and visitors who access published help centers.

2. Information We Collect

We collect the following categories of information:

Account Information

Name, email address, and password (securely hashed — we never store your password in plain text). If you sign in with Google, we receive your name and email from Google.

Workspace Information

Workspace name, slug, team member roles, and billing information associated with your subscription plan.

Content Data

Articles, collections, article versions, and search indices that you create within your help center.

Conversation Data

If you enable the AI support agent or the chat widget, we store the conversations your visitors have with it: the messages they send, the AI’s replies, the articles the AI drew on, and a confidence score recording how well those articles supported each answer. Visitors type freely, so these messages may contain any information they choose to share.

We also store a browser-generated visitor identifier, and — where your visitor provides them, or your widget passes them — a name and email address.

Contact Data

Visitors who contact you through the widget may be stored as contacts in your workspace inbox, including name, email address, phone number, and avatar where supplied.

Knowledge Gaps

When the AI cannot answer a question from your articles, we record the question so your team can see what content is missing. We also store a numerical representation (an “embedding”) of that question so that different phrasings of the same question can be grouped together.

Usage Data

Article view counts, search queries, helpful/not-helpful feedback votes, and widget interaction events used to provide analytics dashboards.

Custom Domain Data

If you configure a custom domain, we store the domain name, DNS verification status, and SSL certificate status.

Technical Data

IP address, browser type, and device information collected automatically when you use our website.

3. How We Use Your Information

We use your information to:

  • Operate and deliver the HelpNest service
  • Publish and serve your help center content to your visitors
  • Power AI search features including semantic search and AI-generated answers
  • Operate the AI support agent, including answering your visitors’ questions from your published articles and handing a conversation to your team when it cannot
  • Record questions your knowledge base could not answer, so your team can see what content is missing
  • Generate article embeddings for vector search
  • Provide usage analytics and search insights
  • Send transactional emails such as account verification and password resets
  • Process billing and enforce plan limits
  • Improve and maintain the security of our service
  • Comply with legal obligations

4. AI and Automated Processing

HelpNest uses artificial intelligence to power semantic search, AI-generated answers, and the AI support agent. To deliver these features, content is processed by third-party AI providers. Which providers receive data depends on the settings you choose in your workspace — see Third-Party Service Providers below.

We do not use your data to train AI models. Your information is used solely to provide the service to you.

What is sent to AI providers

  • Your article content, to generate the embeddings that make semantic search work.
  • Questions your visitors ask, both to find matching articles and to generate an answer. The question is sent together with excerpts of the articles that matched it.
  • Previously recorded questions that the AI could not answer, when we check whether a new question is a rephrasing of one already recorded.

Grounding and escalation

The AI support agent answers only from your published articles. Before an answer is delivered we measure how well your knowledge base actually matched the question. When that match is poor, the agent hands the conversation to a human on your team rather than guessing, and records the question as a knowledge gap. Escalated conversations are readable by members of your workspace.

This measurement is a decision made by software about how a support request is handled. It affects whether a visitor is answered by a machine or a person; it does not produce legal or similarly significant effects about them.

Questions may become draft articles

If you enable auto-drafting, a question the AI could not answer may be sent to an AI provider and used to generate a suggested help article. These are created as unpublished drafts. Nothing is published to your help center until a member of your team reviews and publishes it. You should review drafts before publishing, as the originating question may contain information a visitor typed.

Accuracy

AI-generated answers may still be incorrect, incomplete, or based on an article that is out of date. Visitors are told that answers are AI-generated, and each answer records the articles it was based on so your team can trace and correct it.

5. Website Import (Crawling)

HelpNest can import existing documentation by fetching pages from a website and turning them into help articles. When you use this feature, our crawler retrieves those pages from our servers.

You may only import from a domain you have verified that you own. We check this before fetching anything. We do this so that HelpNest is not used to copy content from websites that belong to someone else.

Our crawler:

  • Identifies itself honestly as HelpNestBot and does not disguise itself as a human visitor.
  • Reads and obeys robots.txt before requesting a page, and will not fetch a page a site has asked crawlers not to fetch.
  • Refuses to fetch private, internal, or loopback network addresses.

Page content retrieved this way is used only to generate draft articles for your workspace. Those drafts are unpublished until a member of your team reviews and publishes them.

If you operate a website and want to block HelpNest, disallow HelpNestBot in your robots.txt, or contact us at [email protected].

6. Third-Party Service Providers

We share data with the following providers to operate the service:

ProviderWhat They ReceivePurpose
GoogleName, email (during OAuth sign-in)Authentication
OpenAIArticle content chunks; visitor questions and support messagesText embeddings for vector search; AI answers where OpenAI is the selected answer provider
Anthropic, Google, or MistralVisitor questions and support messages, relevant article excerpts, and recorded knowledge-gap questionsAI-generated answers, the AI support agent, grouping of repeated questions, and drafting suggested articles. Only the provider selected in your workspace receives this data.
QdrantArticle embeddingsVector search database
StripeEmail, payment methodSubscription billing
ResendEmail addressesTransactional emails
AWSAll service dataCloud hosting infrastructure (US regions)

Each provider processes data under their own privacy policies and terms of service.

If you supply your own AI provider API key (“bring your own key”), data is sent directly to that provider under your account and your agreement with them, and their terms — including any data-retention or training terms attached to your account — govern that processing.

7. Cookies

We use only essential cookies required for the service to function:

  • Session cookie: Keeps you signed in to your account. This cookie is httpOnly and secure.
  • OAuth state cookie: A temporary cookie used during Google sign-in that expires after 10 minutes.

We do not use analytics cookies, tracking pixels, or advertising cookies.

8. Data Retention

Account data is retained for as long as your account is active.

Articles, collections, and usage analytics are retained to provide you with ongoing service.

Conversations, contacts, and knowledge gaps — including the embeddings derived from recorded questions — are retained for as long as your workspace is active, so that your team can review support history and see which articles are missing. Deleting a workspace deletes its conversations, contacts, and knowledge gaps.

You may request deletion of your data at any time (see Your Rights).

Password reset tokens expire automatically and are deleted after use.

9. Data Security

We take reasonable measures to protect your information:

  • All data is encrypted in transit between your browser and our servers
  • Passwords are securely hashed and never stored in plain text
  • Internal service communication is authenticated and encrypted
  • We implement access controls and role-based permissions to protect your data

No system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Reporting a vulnerability

If you believe you have found a security vulnerability in HelpNest, please report it privately to [email protected] rather than disclosing it publicly, so we can fix it before it can be exploited. Our full policy, including what is in scope, is published in the SECURITY.md file of our open-source repository.

10. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know: You may request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request deletion of your personal information.
  • Right to opt-out: We do not sell or share your personal information for cross-context behavioral advertising.
  • Non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at the email listed in the Contact Us section below.

11. European Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides you with additional rights regarding your personal data.

Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance: Processing necessary to provide the HelpNest service you signed up for, including account management, content hosting, and billing.
  • Legitimate interest: Processing necessary for our legitimate business interests, such as improving the service, preventing fraud, and ensuring security, where those interests are not overridden by your rights.
  • Consent: Where you have given explicit consent, such as opting into AI-powered search features. You may withdraw consent at any time.

Your GDPR Rights

In addition to the rights listed in Your Rights, you have the right to:

  • Restriction: Request that we restrict processing of your personal data in certain circumstances
  • Objection: Object to processing based on legitimate interest
  • Complaint: Lodge a complaint with your local data protection authority

International Transfers

Your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for these transfers.

To exercise your GDPR rights, contact us at [email protected]. We will respond within 30 days.

12. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data and account
  • Export: Request a portable copy of your data

Contact us at the email below to exercise these rights. We will respond within 30 days.

13. Children's Privacy

HelpNest is a business tool and is not directed at individuals under 18. We do not knowingly collect personal information from children.

14. International Users

HelpNest is operated from the United States. Your data is processed and stored in the United States.

By using the service, you consent to the transfer and processing of your data in the United States.

15. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to your registered address.

The “Last updated” date at the top of this page will reflect the most recent revision. Continued use of the service after changes constitutes acceptance.

16. Contact Us

For privacy questions or to exercise your rights, contact us at:

[email protected]