Privacy Policy

Last updated: February 2026

Introduction

Helmwise (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use our AI-powered passage planning platform at helmwise.co (the “Service”). By using the Service, you agree to the collection and use of information in accordance with this policy.

1. What Data We Collect

1.1 Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you subscribe to a paid plan, we collect billing information through our payment processor, Stripe. We do not store full credit card numbers on our servers.

1.2 Vessel Data

You may provide vessel information including vessel name, type, length, beam, draft, displacement, fuel capacity, water capacity, and engine specifications. This data is used to generate accurate passage plans and safety assessments tailored to your vessel.

1.3 Passage Plans

We collect and store the passage plans you create, including departure and arrival ports, waypoints, route data, weather briefings, tidal analyses, safety assessments, and any exported documents (GPX, PDF). This data is essential for providing the Service and maintaining safety audit trails.

1.4 Usage Analytics

We collect anonymous usage data to understand how the Service is used and to improve it. This includes pages visited, features used, session duration, browser type, device type, and general geographic region. We use Sentry for error tracking, which may collect technical information about errors and crashes you encounter.

2. How We Use Your Data

2.1 Passage Planning

Your vessel data and route information are processed by our AI agents to generate comprehensive passage plans, including weather routing, tidal predictions, safety assessments, and port information. This is the core purpose of the Service.

2.2 Safety Analysis

Vessel specifications and route data are used to calculate safety margins, identify hazards, assess weather risks, and generate GO/CAUTION/NO-GO recommendations. Safety audit logs are maintained to support the integrity of our safety systems.

2.3 Service Improvement

Aggregated and anonymized usage data helps us improve the accuracy of our AI agents, identify areas where the Service can be enhanced, and prioritize new features. We may analyze passage plan patterns in aggregate to improve route recommendations and safety assessments.

2.4 Communications

We may use your email address to send transactional messages (account verification, password resets, subscription confirmations), service announcements, and safety-related notifications. You can opt out of non-essential communications at any time.

3. Data Sharing

3.1 Third-Party APIs

To generate passage plans, we send route and location data to third-party data providers including NOAA (National Oceanic and Atmospheric Administration), the National Weather Service, OpenWeather, and NDBC buoy networks. These requests include geographic coordinates but do not include your personal information.

3.2 Service Providers

We use trusted service providers to operate the platform, including Supabase (database and authentication), Stripe (payment processing), Sentry (error tracking), Upstash (caching), and Resend (transactional email). These providers access only the data necessary to perform their services and are bound by their own privacy policies.

3.3 No Sale of Personal Data

We do not sell, rent, or trade your personal information to third parties. We do not share your vessel data, passage plans, or personal information with advertisers, data brokers, or any other commercial entities.

3.4 Legal Requirements

We may disclose your information if required to do so by law, in response to valid legal process, to protect our rights or property, or in the event of an emergency involving potential threats to personal safety.

4. Data Retention

While your account is active, we retain your account information, vessel data, and passage plans to provide the Service. Safety audit logs are retained for compliance and safety improvement purposes.

Upon account closure: When you request account deletion, we will delete your personal data, vessel information, and passage plans within 30 days. Anonymized and aggregated data that cannot be used to identify you may be retained for analytical purposes. Safety audit logs may be retained in anonymized form as required for regulatory compliance.

5. Your Rights

You have the following rights regarding your personal data:

  • Access: You can request a copy of all personal data we hold about you.
  • Correction: You can update or correct inaccurate information through your account settings or by contacting us.
  • Deletion: You can request deletion of your account and associated personal data. We will process deletion requests within 30 days.
  • Export: You can export your passage plans in GPX and PDF formats at any time. You can also request a complete export of your personal data.
  • Restriction: You can request that we restrict the processing of your data in certain circumstances.
  • Objection: You can object to the processing of your data for specific purposes, including direct marketing.

To exercise any of these rights, contact us at privacy@helmwise.co.

6. GDPR Compliance

If you are located in the European Union or the European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your data based on your consent (account creation), contractual necessity (providing the Service), and legitimate interests (service improvement and safety).
  • Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to be Forgotten: You can request complete erasure of your personal data, subject to legal obligations we may have to retain certain records.
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection supervisory authority.
  • Data Transfers: Your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place for such transfers.

7. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL), encryption at rest, row-level security policies on our database, secure authentication through Supabase Auth, and regular security reviews. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

8. Children's Privacy

The Service is not intended for children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we may also send a notification to the email address associated with your account. Your continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

For questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:

privacy@helmwise.co