Privacy
What Helix collects, and why.
Helix is engineering intelligence. We store the minimum needed to index a repository, answer from evidence, post Helix Review, and bill a workspace.
Account
Sign-in uses Google, X, or email. We keep your account id, email if the provider sends one, plan, and Stripe customer id.
GitHub
Indexing reads merged pull-request metadata: titles, authors, reviewers, and changed file paths. We do not clone the repository or store file contents. If you save a GitHub token, it is encrypted at rest and used to index private repos and to submit pull request reviews. Rotate it in GitHub, then replace it in Settings.
Ask Helix
Workspace Ask may send your question and a small evidence slice from the graph to xAI to write the answer. We do not send repository file bodies. We do not train Helix on your graph. The public API Ask path answers from the graph only, without a language model.
Billing
Payments run through Stripe. Helix stores customer and subscription ids so the workspace plan stays in sync. Card numbers never touch our database.
Retention
Saved indexes, Ask history on Team and Scale, API keys, and posted review records stay until you delete them or close the account. Email hello@helix-engineering.dev to export or delete a workspace.
Last updated August 28, 2026