Privacy Policy
Last updated: 22 September 2026
Stivan Technologies ("Stivan Technologies", "we", "us" or "our") operates ProjectHelm, a platform that lets you describe an application in chat and have it designed, generated and deployed as a real, running app with its own database, sign-in and admin dashboard (the "Platform" or "Service"). This Privacy Policy explains what personal data we collect through the Platform, why, who we share it with, and the choices you have.
This policy covers data we process about you as a ProjectHelm customer. If you build an application on the Platform and that application collects data from its own users - your customers, not ours - you are responsible for that data and for giving your own users their own privacy notice. Section 6 explains this in more detail.
1. What data we collect
| Category | What it includes |
|---|---|
| Account data | Your name, email address and password (stored only as a salted hash). If you sign in with Google, we receive your name, email address and profile photo from Google instead. If you enable phone sign-in, your phone number. If you enable two-factor authentication, your TOTP secret (encrypted at rest) and a set of one-time recovery codes (stored as hashes, never in plain text). |
| Billing data | Your credit balance, transaction history, and order records (which payment gateway, its order/payment reference, amount, currency and invoice number). We never receive or store your card, UPI or bank details - Stripe and Razorpay collect those directly from you, under their own terms and privacy policies. |
| Chat and design data | The messages, instructions and files you give the AI assistant, your conversation history, and the designs, page content, workflow checklists and settings it helps you build. |
| Support ticket data | The subject, category, description, project references, status, and any diagnostic messages or logs you provide when raising a support ticket or when automated incident telemetry records an error on your behalf. |
| Application data | The generated source code, database schema, static page content, and any images, files or documents you upload for an app you build on the Platform. |
| Technical data | Your IP address and standard web server logs, used mainly to rate-limit and secure sign-in, sign-up and verification requests against abuse. |
We do not ask for or knowingly collect special category data (health, biometric, racial or ethnic origin, political or religious beliefs) or precise location data.
2. How we use it
- To create and secure your account - account data, to sign you in, keep your session secure and recover access if you forget your password.
- To run the AI assistant and build your app - your chat and design data is sent to our AI model providers solely to generate the response or design change you asked for. We only use providers whose terms commit that data sent through their API is not used to train their models.
- To deploy and host your application - application data is built into a running container and, if you configure a custom domain, a DNS record is created for it.
- To process payments and produce invoices - billing data, handled through Stripe or Razorpay depending on your region.
- To respond to support tickets and resolve incidents - support ticket and incident data, used to investigate technical inquiries, troubleshoot platform issues, and follow up with you.
- To prevent fraud and abuse - technical data, to rate-limit login, registration, two-factor and phone-verification attempts.
- To respond when you contact us - whatever you send us in that request.
- To meet legal and tax obligations - billing records, kept as long as applicable law requires.
We do not use your data for advertising, we do not run behavioural analytics or tracking beyond what section 7 (Cookies) describes, and we do not sell personal data to anyone.
3. Automated decisions
We don't personalise pricing, features or the interface based on automated profiling. Everyone on the same plan sees the same prices and the same set of features.
4. Who we share your data with
| Who | What they do for us |
|---|---|
| AI model providers | Generate the AI assistant's replies and proposed designs from your chat and design data. We may use more than one provider; the current list is available from us on request. |
| Google sign-in (if you use it) and reCAPTCHA, which checks that a sign-up is coming from a real person rather than a bot. | |
| Stripe / Razorpay | Process payments, manage your credit purchases, and collect your card/UPI details directly - we never see or store them. |
| Fast2SMS | Delivers the one-time code used for phone sign-in, if you enable it. |
| OVH | Registers the DNS record behind your app's address, whether a projecthelm.in subdomain or your own custom domain. |
| Our hosting providers | Run the servers, database and container registry behind the Platform and the applications built on it. |
| Zoho / Email delivery | Sends verification, password-reset, invoice, and support ticket notification emails on our behalf. |
We may also disclose data where required by law, to establish or defend a legal claim, or as part of a merger, acquisition or sale of some or all of our business - in which case we'll require the new owner to honour this policy.
5. International transfers
Some of the providers listed above (including our AI model providers, Google and Stripe) may process data on servers located outside your own country. Where that happens, we rely on those providers' own contractual and security commitments to keep your data appropriately protected wherever it's processed.
6. If you build an application with your own users
Applications built on ProjectHelm can have their own sign-up, sign-in and data of their own - your customers, patients, members or whoever else uses the app you built. For that data, you are the controller: you decide why it's collected and how it's used, and you're responsible for giving your own users a privacy notice and for answering their requests about their data. We act as your processor - we host the application and its database, but we don't decide how that data is used.
Public vs. private content: Applications built on ProjectHelm allow you to create standalone static pages (such as public landing pages, about pages, or privacy notices). Pages configured for Anonymous access are intentionally public and served to any visitor without sign-in. Pages configured with Authorize or SuperUser permissions require authentication and are strictly gated by application role-based access controls.
Uploaded files and media: Files, attachments and images uploaded to your application are stored in isolated directories designated specifically for your application. They are validated on upload and served through application routes subject to your configured access rules.
An application you publish is reachable by anyone on the internet at its address unless you restrict access yourself. If you connect a third-party service to your application (a payment gateway, an email provider), that service becomes your processor, not ours.
7. Cookies
We use a small number of cookies to keep you signed in and to protect the Platform from abuse. See our Cookie Policy for the full list.
8. How long we keep your data
We keep your account, application, and support ticket data for as long as your account is open. If you delete your account, we delete or anonymise your personal data, typically within 30 days, except billing and invoice records, which we keep for as long as applicable tax and accounting law requires.
9. Security
Traffic between your browser and our servers is encrypted (HTTPS/TLS). Passwords are never stored in plain text - only as salted hashes. Two-factor authentication secrets are encrypted at rest, and recovery codes are stored as hashes. Sensitive fields (such as Secret properties and credentials) are masked in views and protected against casual inspection.
Uploaded files are validated server-side for permitted extensions and file size limits, and image files are decoded and verified using server-side graphics processing to guard against malicious payloads. Tenant and application isolation is enforced at the database, filesystem and network layer. Access to production systems is limited to the people who need it to operate the Platform. No method of transmission or storage is completely secure, and we can't guarantee absolute security - but we take these steps to reduce the risk.
10. Your rights
You can ask us to give you a copy of the personal data we hold about you, correct anything that's wrong, export your data, or delete your account and personal data. Write to support@stivan.in and we'll respond within a reasonable time, normally within 30 days. Deleting your account doesn't automatically delete billing records we're legally required to keep.
11. Children
ProjectHelm is not directed at children, and we don't knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we'll delete it.
12. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll update the date at the top of this page.
13. Contact us
Questions about this policy or how we handle your data? Email support@stivan.in.
Stivan Technologies, GSTIN 36AJPPV8123R1Z2, registered at Level 6, N Heights, Plot No. 38, Sy No. 64, Hitech City Phase 2, Madhapur, Hyderabad, Telangana 500081, India.