Privacy Policy

Last updated March 21, 2026

1. Introduction

HelpNest (“we,” “us,” or “our”) operates the HelpNest platform, an open-source customer help center that helps businesses create, manage, and publish knowledge bases and support articles.

This Privacy Policy describes how we collect, use, share, and protect your information when you use our website and services. It applies to all users of the HelpNest Cloud platform, including workspace owners, team members, and visitors who access published help centers.

2. Information We Collect

We collect the following categories of information:

Account Information

Name, email address, and password (securely hashed — we never store your password in plain text). If you sign in with Google, we receive your name and email from Google.

Workspace Information

Workspace name, slug, team member roles, and billing information associated with your subscription plan.

Content Data

Articles, collections, article versions, and search indices that you create within your help center.

Usage Data

Article view counts, search queries, helpful/not-helpful feedback votes, and widget interaction events used to provide analytics dashboards.

Custom Domain Data

If you configure a custom domain, we store the domain name, DNS verification status, and SSL certificate status.

Technical Data

IP address, browser type, and device information collected automatically when you use our website.

3. How We Use Your Information

We use your information to:

  • Operate and deliver the HelpNest service
  • Publish and serve your help center content to your visitors
  • Power AI search features including semantic search and AI-generated answers
  • Generate article embeddings for vector search
  • Provide usage analytics and search insights
  • Send transactional emails such as account verification and password resets
  • Process billing and enforce plan limits
  • Improve and maintain the security of our service
  • Comply with legal obligations

4. AI and Automated Processing

HelpNest uses artificial intelligence to power semantic search and AI-generated answers. Your article content is processed by third-party AI providers (OpenAI for embeddings, Anthropic for answer generation) to deliver these features.

We do not use your data to train AI models. Your information is used solely to provide the service to you.

AI-generated answers may not always be accurate. Visitors are informed that answers are AI-generated and should verify information against your published articles.

5. Third-Party Service Providers

We share data with the following providers to operate the service:

ProviderWhat They ReceivePurpose
GoogleName, email (during OAuth sign-in)Authentication
OpenAIArticle content chunksText embeddings for vector search
AnthropicSearch queries, relevant article excerptsAI-generated answers
QdrantArticle embeddingsVector search database
StripeEmail, payment methodSubscription billing
ResendEmail addressesTransactional emails
AWSAll service dataCloud hosting infrastructure (US regions)

Each provider processes data under their own privacy policies and terms of service.

6. Cookies

We use only essential cookies required for the service to function:

  • Session cookie: Keeps you signed in to your account. This cookie is httpOnly and secure.
  • OAuth state cookie: A temporary cookie used during Google sign-in that expires after 10 minutes.

We do not use analytics cookies, tracking pixels, or advertising cookies.

7. Data Retention

Account data is retained for as long as your account is active.

Articles, collections, and usage analytics are retained to provide you with ongoing service.

You may request deletion of your data at any time (see Your Rights).

Password reset tokens expire automatically and are deleted after use.

8. Data Security

We take reasonable measures to protect your information:

  • All data is encrypted in transit between your browser and our servers
  • Passwords are securely hashed and never stored in plain text
  • Internal service communication is authenticated and encrypted
  • We implement access controls and role-based permissions to protect your data

No system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

9. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know: You may request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request deletion of your personal information.
  • Right to opt-out: We do not sell or share your personal information for cross-context behavioral advertising.
  • Non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at the email listed in the Contact Us section below.

10. European Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides you with additional rights regarding your personal data.

Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance: Processing necessary to provide the HelpNest service you signed up for, including account management, content hosting, and billing.
  • Legitimate interest: Processing necessary for our legitimate business interests, such as improving the service, preventing fraud, and ensuring security, where those interests are not overridden by your rights.
  • Consent: Where you have given explicit consent, such as opting into AI-powered search features. You may withdraw consent at any time.

Your GDPR Rights

In addition to the rights listed in Your Rights, you have the right to:

  • Restriction: Request that we restrict processing of your personal data in certain circumstances
  • Objection: Object to processing based on legitimate interest
  • Complaint: Lodge a complaint with your local data protection authority

International Transfers

Your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for these transfers.

To exercise your GDPR rights, contact us at [email protected]. We will respond within 30 days.

11. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data and account
  • Export: Request a portable copy of your data

Contact us at the email below to exercise these rights. We will respond within 30 days.

12. Children's Privacy

HelpNest is a business tool and is not directed at individuals under 18. We do not knowingly collect personal information from children.

13. International Users

HelpNest is operated from the United States. Your data is processed and stored in the United States.

By using the service, you consent to the transfer and processing of your data in the United States.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to your registered address.

The “Last updated” date at the top of this page will reflect the most recent revision. Continued use of the service after changes constitutes acceptance.

15. Contact Us

For privacy questions or to exercise your rights, contact us at:

[email protected]