Privacy Policy

Last updated: April 2026

What Data We Collect

Email address

Used for authentication (magic link login) and account identification. No passwords are stored.

Research data

Datasets you upload (XLSX, CSV) and analyses you run — variables, test configurations, results, and project metadata — are stored so you can access them across sessions.

AI chat history

Messages sent to the AI assistant during your session are used to provide contextual responses. Chat content is not persisted on our servers after your session ends.

Waitlist information

If you join our waitlist, we collect your email address to notify you when access is available.

Usage analytics

We collect anonymized usage data to understand how the product is used and improve it. See the Analytics section below for details.

How We Use Your Data

Provide the service

Store and retrieve your projects, process AI-assisted statistical analysis requests, manage your account.

Improve the product

Analyze usage patterns to prioritize features, fix bugs, and improve the user experience.

We do not sell your data

We do not sell, rent, or share your personal information or research data with third parties for marketing or advertising purposes.

AI Data Processing

AI analysis requests are proxied through our server-side API gateway and sent to third-party AI providers for processing.

Per their API terms of service, our AI providers do not use API data to train their models. Providers may temporarily retain requests for abuse monitoring and safety purposes.

Your browser never communicates directly with AI providers — all requests are routed through our API proxy.

Data Storage

Data is stored in a managed cloud database service with encryption at rest (AES-256).

All data in transit is encrypted with TLS 1.3.

API keys (admin and user-provided) are encrypted with AES-256-GCM before storage.

Analytics

We use the following categories of analytics and monitoring services:

Product analytics

We use a product analytics service to understand feature usage and user flows. Users are identified by anonymized IDs. Respects Do Not Track browser settings.

Traffic analytics

We use a traffic analytics service to understand how visitors find GraphHelix and measure marketing effectiveness.

Error tracking

We use an error tracking service to detect and fix bugs. It captures error context but not research data content.

Advertising conversion tracking

We use conversion tracking pixels for our advertising campaigns. These measure whether ad clicks result in signups. They do not track your activity outside of this conversion flow.

Third-Party Service Providers

We use third-party service providers for database hosting, authentication, analytics, error monitoring, advertising measurement, and AI processing. These providers process data on our behalf and are contractually obligated to protect it. We do not share your research data with these providers except as necessary to deliver the service (e.g., sending analysis requests to AI providers).

Data Retention

Projects and analyses

Stored indefinitely while your account is active. You can delete individual projects at any time.

Usage logs

Detailed AI usage logs are rolled up into monthly aggregates after 90 days. Individual request-level data is then deleted.

Your Rights

Export your data

You can export your analysis results at any time in CSV or publication-ready formats.

Request deletion

Email hello@graphhelix.ai to request complete deletion of your account and all associated data. We will process your request within 30 days.

Opt out of analytics

You can enable Do Not Track in your browser settings. Our product analytics service respects this signal.

California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale of your personal information (we do not sell personal information)
  • Non-discrimination for exercising your privacy rights

To exercise these rights, contact hello@graphhelix.ai.

Cookies

GraphHelix uses cookies and similar technologies for product analytics, traffic measurement, error tracking, and advertising conversion measurement. Session cookies are used for authentication. We do not use cookies for advertising purposes beyond conversion tracking for our own marketing campaigns.

Children

GraphHelix is not designed for or directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.

Changes to This Policy

We may update this policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top of this page indicates when this policy was last revised.

Privacy questions or data requests? Contact us at hello@graphhelix.ai