Privacy Policy
What we collect, why we collect it, who can see it, and the choices you have — one policy for the web app, the iOS app, and this website.
Last updated: August 8, 2026
HelmHOA is an operations and compliance platform used by Florida condominium and homeowners’ associations to manage unit inspections, repairs, maintenance, records, and related obligations. This policy explains what information the platform handles, how it is protected, and the choices available to you. It applies to the HelmHOA web app, the iOS app, and our marketing website.
HelmHOA is typically provided to you through your association, which controls the community’s data and decides who is invited to the platform. Where that is the case, we process data on the community’s behalf as well as under this policy.
Information we collect
We collect only what is needed to run the platform and manage your account:
- Account information — your name, email address, role(s), and the unit(s) or building(s) assigned to you by your community’s management — plus sign-in identifiers from Google or Apple, if you choose those sign-in methods.
- Community & operations data — inspection results, notes, and photos; repair items and proof-of-repair uploads (photos, receipts, permits); equipment details for a unit, such as water heater brand and installation date; work orders and service requests; documents uploaded at the association, building, or unit level; notices and announcements; and in-app activity records (who submitted, approved, or was notified of what, and when).
- Technical & usage data — authentication and security logs, an administrative audit trail, and basic device and browser information (such as app version and error logs) used to keep the service reliable and secure.
The platform is invitation-only. The marketing website does not require an account and does not use advertising trackers.
How we use information
- To operate the platform: run inspections, track repairs and work orders, compute compliance status, generate reports and PDFs, and deliver notices.
- To notify you, by in-app alert and email, about inspections, repair requirements, approvals, and community announcements.
- To keep the service secure: authentication, access control, abuse prevention, rate limiting, and audit logging.
- To meet the association’s record-keeping obligations and help management resolve questions about their community’s data.
We do not sell personal information, and we do not use it for third-party advertising.
AI features
Some platform features can use AI assistance — for example, suggesting a building-model trace from an uploaded floor plan. Where a feature sends content for AI analysis, it is processed by Anthropic’s Claude model through a secure server-side function, and the AI’s output is always presented for human review — it can be edited or discarded before anything is saved.
Content submitted for analysis is used only to produce results for your community. Anthropic does not use data submitted through its API to train its models by default.
Who can see your information
Visibility inside the platform follows your community’s roles, enforced by server-side security rules:
- Owners — see their own unit’s data — and their own units only, if they own several.
- Inspectors and maintenance staff — see only the buildings — and, where configured, only the specific units — they are assigned to.
- Management and board roles — see the buildings they are responsible for; building-scoped administrators cannot see other buildings’ data.
Each association’s data is isolated from every other association on the platform. We share personal information only with the service providers below, when required by law, or with your community’s management as the controller of its own data.
Service providers
We rely on a small number of providers to operate the platform:
- Google Firebase & Google Cloud — authentication, database, file storage, hosting, and server-side functions. Data is stored encrypted in Google Cloud infrastructure.
- Anthropic — AI analysis, as described above.
- Email delivery — transactional email (invitations, notices, reminders) is sent through our email delivery service.
Each provider processes data on our behalf under its own security and privacy commitments. A current list of subprocessors, with the purpose and region for each, is published on our website.
Connecting Claude (or other AI assistants you authorize)
HelmHOA can act as a connector for Claude, Anthropic’s AI assistant. This is optional, off by default for you personally, and works only if you turn it on:
- How it starts — your association’s administrators control whether the connector is available for your community at all. If it is, you can individually link your HelmHOA account to your own Claude account. You approve the link on a HelmHOA consent screen that lists, in plain language, exactly what Claude will be able to do. Nothing is shared until you approve.
- What is shared — when you ask Claude a question about your buildings, HelmHOA answers with data limited to what your own account can already see in the app — checked by the same server-side access rules on every request. HelmHOA never shares through the connector: document files or their contents (titles and counts only), other residents’ contact details, audit logs, or billing information.
- What Claude can do — almost everything is read-only. The one exception: an owner may ask Claude to submit a maintenance request on their own unit, in communities where the association has enabled owner maintenance requests. Claude confirms with you before creating one, the request goes into the same review queue as one submitted in the app, and it is limited to a small number per unit per day. Nothing else can be created, changed, or deleted through the connector.
- Where your questions go — your questions to Claude, and the data HelmHOA returns, are processed by Anthropic under your own Claude account and Anthropic’s terms and privacy policy — not under this policy. HelmHOA does not see your Claude conversations; it sees only the specific data requests Claude makes on your behalf, and it records those requests (and every maintenance request created this way) in the community’s audit trail.
- What we store — a record of your authorization (which Claude client you connected, when, and when it was last used), protected credentials for the connection itself (stored only in hashed form), and usage counters that enforce daily limits. We do not store your Claude conversations.
- Ending it — you can disconnect at any time from Account Settings → Connected apps in HelmHOA, or from Claude’s own connector settings; either side works alone and takes effect within the hour. Your association’s administrators can also switch the connector off for the whole community at any time, which immediately ends all sharing.
Data retention & deletion
Inspection, repair, and equipment records are retained for as long as your community uses the platform, because their value — compliance history, insurance documentation, due-diligence records — depends on continuity. Communities control their own retention decisions, and record deletion by administrators is itself safeguarded: destructive actions require a second administrator’s confirmation and are recorded in the audit log.
You can permanently delete your login at any time from Account Settings — including in the iOS app, where account deletion is available in-app. For your security this requires re-confirming your identity. Records belonging to the community (for example, an inspection performed on a unit) may be retained by the association as compliance records even after a personal account is closed, consistent with legal and association record-keeping requirements.
How we protect your data
- Encryption in transit and at rest — data is transmitted over HTTPS/TLS and stored encrypted by our cloud provider (Google Firebase / Google Cloud Platform).
- Authentication — sign-in is handled by Firebase Authentication, supporting email + password (with a verified email required), Google, Sign in with Apple, and passwordless email-link sign-in.
- Access controls — role- and building-based rules restrict each person to only the units and data they are authorized to see, enforced server-side.
- Accountability — sensitive actions are recorded in an audit trail, permission changes are limited to authorized administrators, and administrators cannot edit their own permissions.
- Session protection — inactive sessions time out automatically.
Our Security Policy, published on our website, describes these protections in full.
Your rights and choices
- View and update your profile in Account Settings, or ask an administrator for help.
- Manage your email notification preferences.
- Request a copy, correction, or deletion of your personal information.
- Depending on where you live, you may have additional rights under applicable privacy laws — we honor valid requests accordingly.
We maintain personal information subject to applicable Florida law, including the data-security and breach-notification requirements of the Florida Information Protection Act (section 501.171, Florida Statutes).
Children
HelmHOA is a tool for property owners, association staff, boards, and inspectors. It is not directed to children, and we do not knowingly collect personal information from anyone under 16.
Contact us
For privacy questions, security concerns, or data requests, contact us at privacy@helmhoa.com. To report a suspected security vulnerability, please include steps to reproduce so we can investigate promptly.
This policy may be updated from time to time. Material changes will be reflected by a new “Last updated” date above, and communities will be notified through the platform before material changes take effect.
Related
- Security Policy — the full description of how customer data is protected.
- Subprocessor list — every service provider, with purpose and region.
- AI Disclosure — where AI is used, where it is not, and what a human confirms.
- Cookie Notice — what this website stores in your browser (very little).