1. Scope
This policy applies to HelperAI software for Windows, macOS, Linux, and Android, the HelperAI Chrome extension, the HelperAI website, and related account, subscription, trial, and software-licensing services.
HelperAI is designed for local execution. It does not sell personal information for targeted advertising and does not proactively read your documents, screen, or browser content when a task does not require it.
2. Information we process
- Local operation content: window and application metadata, interface structure, screenshots, input text, file paths, and selected files that you explicitly ask an AI assistant to handle.
- Account information: account identifier, display name, email address, avatar, and sign-in status returned by the sign-in service.
- Subscription and order information: plan, payment channel, order identifier, amount, payment status, and renewal status. Payment credentials are processed by payment providers; HelperAI does not store full card numbers or payment passwords.
- Device and licensing information: a device identifier used for trials and licensing, installation and expiration times, client version, operating-system name, version, build, and architecture. License-sync data does not include the computer hostname.
- Website and diagnostic information: IP address, access-verification and session records, error details, necessary runtime logs, and security events.
- Browser-task information: only when you explicitly request a browser task, local HelperAI processes the target tab URL and title, page structure and text, task-required screenshots, input, interaction results, and paths of files you select for upload.
3. Purposes
We use this information to perform computer actions you request, display and synchronize account and subscription status, enforce trials and licenses, provide updates and support, troubleshoot failures, prevent abuse, and protect service security.
4. Local processing and transfers
Application interfaces, screenshots, files, and operation records are generally processed on your device. Information needed for a task is sent to an AI service, target service, or HelperAI service only when you ask an AI assistant to analyze content, submit content to a target site, synchronize a license, or use online account and subscription features.
The Chrome extension reuses the HelperAI website login: after sign-in is started from the extension, the user can finish the normal website login or use an existing website session. The browser sends its existing HttpOnly session cookie only to HelperAI website/Admin; the extension cannot read or copy it. After the website/Admin verifies the account, it issues a single-use ticket valid for 60 seconds and bound to a PKCE challenge, random state, and extension installation ID. After redeeming that ticket, the extension keeps a short-lived access token (up to 15 minutes) only in the current browser session and reads the account trial/subscription entitlement shared with the desktop app. Eligible accounts can receive one seven-day trial; accounts with paid history do not receive a new trial after expiry. Paid extension use registers a random extension installation ID as a device seat and is subject to the account's ten-device limit. The installation ID is stored in Chrome local extension storage. The extension does not receive the cookie, account password, Logto token, or client secret, and does not collect full card numbers or payment passwords. The desktop app uses Native Messaging to synchronize a signed entitlement policy bound to its device ID. Page content is not sent to HelperAI servers for subscription verification.
AI services and target websites process information they receive under their own privacy policies. Review the task content and destination before submitting it.
5. System permissions
Depending on enabled features, HelperAI may request Accessibility or UI Automation, screen recording or window capture, browser extension and Native Messaging, and Android Debug Bridge permissions. The Chrome extension does not request identity or cookies permission; user-initiated sign-in reuses the existing HelperAI website session. Its debugger, tab, scripting, window, and website-access permissions are used to find an existing tab, dispatch trusted input, read task-required page structure, and verify results only after an explicit request. These permissions are used only for sign-in, automation, status checks, and result verification that you initiate. You can revoke them in operating-system, browser, or device settings.
6. Third parties and sharing
HelperAI may share information necessary to provide a feature with sign-in, cloud-hosting, payment, AI, or target-service providers that you select. We do not sell personal information or provide it to third parties for their independent targeted advertising.
We may disclose information when required by law, to protect users or service security, or as part of a corporate reorganization, while continuing to apply appropriate safeguards.
7. Retention and security
Local settings, logs, and task materials generally remain on your device until you clear them, uninstall the software, or choose to remove personal settings. Server-side account, subscription, license, support, and security records are retained only as long as needed to provide services, resolve disputes, perform contracts, and meet legal obligations.
We use measures such as access controls, encrypted transport, signature verification, and data minimization to reduce risk, but no system can guarantee absolute security.
8. Your choices and rights
You can review or update account details, manage subscriptions, revoke system permissions, clear local logs and settings, and choose to remove personal settings during uninstall. For information retained by HelperAI services, use the public channel below to request access, correction, deletion, or another applicable right. We may verify your identity to protect the account.
9. Children
HelperAI is not directed to children below the age at which they can independently consent in their region. A parent or guardian who believes a child provided personal information without appropriate consent should contact us.