Legal
Privacy Policy
Last updated: September 2026
Who is responsible
Helix Labs operates the Helix website, dashboard, and Discord bot infrastructure. For dashboard accounts, Helix Labs determines why and how account and authentication data is processed. For data created inside a Discord server, the server operator or server administrator is generally the relevant controller, and Helix Labs acts as a service provider or processor for the features that administrator chooses to enable.
This policy explains the data used by the Helix website, dashboard, and bot. It does not replace Discord’s privacy policy or a server administrator’s own privacy notice. Contact us at team@helix.angellabs.xyz with privacy questions or requests.
Data Helix processes
Helix receives Discord identifiers and metadata needed to operate the bot, including user IDs, server IDs, channel IDs, role IDs, usernames, display names, avatars, membership events, and server or channel names. A server administrator can configure a prefix, roles, welcome and farewell messages, moderation and logging channels, AutoMod rules, verification settings, leveling rules, reaction-role menus, Reddit feeds, economy settings, cards, warning thresholds, and other module preferences.
When a user uses Helix features, Helix may store the user ID, username, discriminator, server membership information, last-seen timestamp, economy balance, level, experience, inventory, transactions, game or activity statistics, warnings, moderation restrictions, and related dates. These records are used to provide commands, keep game and economy state consistent, enforce warnings, and prevent abuse.
Helix reads messages and other Discord events while the bot is present in order to execute commands, apply AutoMod, calculate activity, and provide configured logs. Helix does not maintain a general copy of server message history. If a server enables message-edit or message-delete logging, or enables custom AutoMod logging, relevant message text may be copied into that server’s configured Discord log channel. Those messages are then subject to Discord’s and the server administrator’s retention settings.
The dashboard uses Discord OAuth to identify the signed-in user and list servers the user can manage. The dashboard session is held in an encrypted, HTTP-only cookie and includes the short-lived Discord access and refresh tokens needed for that session. Helix does not store those OAuth tokens in its database. Dashboard access checks the user against Discord permissions and Helix’s configured owner/developer list.
AI and other third-party services
When a user invokes an AI feature, Helix sends the prompt and the configured model/system instructions to the AI endpoint configured by the Helix operator. The prompt is used to generate the response; Helix does not automatically send the server’s message history. The AI provider or self-hosted AI service may process that prompt under its own configuration and retention terms. Other commands may use external services such as Discord, search, media, or utility APIs; the data sent depends on the feature and the command used.
Helix does not sell personal data, run advertising profiles, or share server data for unrelated marketing. Infrastructure providers such as the hosting provider, MongoDB deployment, and Cloudflare may process connection, IP-address, and delivery information to provide security and network services.
International transfers
Some providers may process data outside the country where you live. Where that happens, Helix relies on the provider’s applicable data-processing terms and transfer safeguards, including standard contractual clauses or an equivalent mechanism where required. Contact us if you need more information about the providers relevant to your use of Helix.
Why the data is processed
Helix processes data to provide the service requested by the user or server administrator, perform commands, secure the service, prevent abuse, maintain audit and moderation functions, respond to support requests, and improve reliability. Where consent is used as the legal basis, users can withdraw it at any time, although some service features may then be unavailable.
Retention and deletion
Server settings and user activity records are retained while the relevant server or feature uses Helix, and for a reasonable period afterward to support recovery, security, abuse prevention, and legal obligations. OAuth sessions expire according to the session lifetime or token expiry. Technical logs are retained only as long as needed for operations and security. Data in Discord log channels is controlled by the server administrator and Discord.
You may request access, correction, export, restriction, objection, or deletion of personal data by emailing team@helix.angellabs.xyz. We may verify your identity before acting on a request. If backups are enabled, deleted data may remain in a backup for the provider’s limited backup-retention period before being overwritten. We do not currently provide self-service deletion of all server data in the dashboard; use the contact above for a deletion request.
Your rights
If you are in the EEA, UK, or another jurisdiction with similar rights, you may have rights to access, rectify, erase, restrict, object to, or export personal data, withdraw consent, object to direct marketing, and lodge a complaint with your local data-protection authority. Mandatory data-protection law takes priority over any limitation in this policy.
Security and children
Helix uses access controls, encrypted connections, encrypted dashboard sessions, and limited production access. No system is perfectly secure; do not submit secrets or sensitive information that a command or AI feature does not require. If a personal-data breach occurs, Helix will investigate and mitigate it and will notify affected people and authorities where required by applicable law. Helix is not directed to children under 16, and users must not use Helix to collect or process a child’s personal data without a valid lawful basis and appropriate safeguards.
Changes
We may update this policy as the service, providers, or legal requirements change. The date at the top identifies the latest version. Material changes will be announced through the support server or another appropriate Helix channel.