Algorail AI
HelmPilot
Algorail AI, LLC

Privacy Policy

Effective date: August 15, 2026

Algorail AI, LLC (“Algorail,” “we,” “us,” or “our”) respects the privacy and confidentiality of the people and organizations that use our website and HelmPilot.

This Privacy Policy explains how we collect, use, disclose, and retain information when you:

  • visit algorail.ai;
  • contact Algorail;
  • request or participate in a HelmPilot guided evaluation;
  • use HelmPilot; or
  • purchase HelmPilot or another Algorail service.

This Policy should be read together with the applicable Terms of Service.

1. Information We Collect

The information we collect depends on how you interact with Algorail and HelmPilot.

Website and inquiry information

When you contact us or request a guided evaluation, we may collect information such as:

  • your name;
  • email address;
  • institution or organization;
  • project name or description;
  • professional contact information; and
  • the contents of messages you send to us.

We use this information to respond to inquiries, evaluate whether HelmPilot may fit your needs, schedule and support evaluations, and maintain appropriate business records.

Website analytics

We use Plausible Analytics to understand aggregate use of our public website, such as which pages are visited and how visitors reach the site.

Plausible may process information such as:

  • the page visited;
  • referring website or campaign information;
  • browser and operating-system type;
  • device type; and
  • approximate geographic location derived from the visitor’s IP address.

Plausible is designed not to use cookies or persistent visitor identifiers. According to Plausible, raw IP addresses and full user-agent strings are not stored, and its analytics are intended to measure aggregate website traffic rather than track individuals across websites or over time.

We use this information to understand website traffic and improve our public website and outreach.

Account information

When you use HelmPilot, we may collect and maintain account information such as:

  • your name;
  • institutional or business email address;
  • professional contact information;
  • institution or organization;
  • role or affiliation;
  • account identifiers;
  • authentication and account-status information; and
  • information about the HelmPilot workspace or projects you are authorized to access.

Customer Content

“Customer Content” means documents, project information, text, data, contact information, budgets, and other materials submitted to or maintained in HelmPilot by a Customer or its Authorized Users.

HelmPilot is designed to process ordinary professional and project information used to manage research projects and grants. Customer Content may include:

  • grant proposals;
  • project plans;
  • statements of work;
  • budgets and budget justifications;
  • milestones and deliverables;
  • reporting requirements;
  • progress information;
  • reports;
  • investigator, collaborator, and institutional-contact information; and
  • other information reasonably related to project execution and reporting.

Customer Content remains subject to the data-use and confidentiality provisions of the HelmPilot Terms of Service.

HelmPilot is not intended for certain regulated or unusually sensitive information, including CUI, export-controlled technical data, protected health information, identifiable human-subject research data, FERPA-covered student records, Social Security numbers, payroll or HR records, authentication secrets, and other information identified as prohibited in the Terms of Service.

Payment and transaction information

If you purchase HelmPilot, we may collect or receive information needed to administer the transaction, such as:

  • billing contact information;
  • institution or organization;
  • billing address;
  • tax or tax-exemption information;
  • purchase amount;
  • invoice or purchase-order information;
  • payment status;
  • payment-method type; and
  • transaction identifiers.

Payment credentials such as full card numbers or bank-account credentials should be provided through our designated payment processor rather than entered into HelmPilot.

Our payment processor may collect additional information directly from you as necessary to process payments, prevent fraud, handle disputes, calculate taxes, or comply with financial-services requirements.

Product-usage telemetry

HelmPilot records limited information about how users interact with product features so that we can understand feature adoption, identify usability problems, and improve the service.

HelmPilot’s product-usage telemetry is designed to exclude Customer Content and direct personal identifiers.

Usage telemetry may include information such as:

  • which HelmPilot feature or action was used;
  • basic counts;
  • workflow or wizard progress;
  • action duration;
  • application version;
  • timestamps;
  • pseudonymous account or project identifiers; and
  • similar operational usage information.

Product-usage telemetry is separate from Customer Content, support communications, feedback, security records, and diagnostic information.

Security and diagnostic information

We may collect and process technical information needed to protect, operate, and troubleshoot our services.

Depending on the event, this may include:

  • account or pseudonymous user identifiers;
  • IP addresses;
  • request or access information;
  • authentication failures;
  • security events;
  • project or artifact identifiers;
  • timestamps;
  • application and service errors;
  • performance information; and
  • other diagnostic metadata.

Security and diagnostic systems serve different purposes from product-usage telemetry and may contain information that product-usage telemetry deliberately excludes.

We seek to avoid placing Customer Content into security or diagnostic logs unless it is reasonably necessary to investigate or resolve a specific problem.

Authentication and session technologies

HelmPilot uses authentication, session, and related technical mechanisms necessary to provide secure account access and operate the service.

Our website and services may also generate ordinary server, security, and access logs when you interact with them.

2. How We Use Information

We use information for purposes including:

  • providing and operating HelmPilot;
  • creating, authenticating, and administering accounts;
  • processing Customer Content at the user’s request;
  • providing AI-assisted extraction, organization, summarization, and analysis;
  • conducting guided evaluations;
  • responding to inquiries and support requests;
  • troubleshooting problems;
  • protecting accounts, Customer Content, and infrastructure;
  • detecting misuse, fraud, or security threats;
  • processing payments, invoices, and taxes;
  • managing subscriptions and renewals;
  • understanding how HelmPilot features are used;
  • improving product usability, reliability, and performance;
  • maintaining business, accounting, tax, and legal records;
  • enforcing our agreements; and
  • complying with applicable law.

We do not acquire ownership of Customer Content merely because we process it.

3. Customer Content and AI Training

Algorail may review Customer Content when reasonably necessary to:

  • provide the service requested by the Customer;
  • investigate an extraction or processing problem;
  • troubleshoot an issue;
  • respond to a support request;
  • protect the service; or
  • improve the Customer’s use of HelmPilot.

We may learn from problems encountered while supporting Customer Content and use those lessons to improve HelmPilot generally.

However:

  • we do not use Customer Content to train or fine-tune a general-purpose foundation model;
  • we do not use Customer Content to train or fine-tune a HelmPilot-specific foundation model; and
  • we do not add Customer Content to a reusable AI training or evaluation dataset unless the Customer has given permission.

We may create synthetic or generalized examples based on operational lessons, provided those examples do not reproduce or disclose Customer Content or Customer confidential information.

4. AI-Assisted Processing

HelmPilot uses managed AI services to perform tasks such as identifying, extracting, organizing, summarizing, and analyzing project information.

Algorail may use different foundation models, model providers, or managed AI services over time based on factors such as capability, reliability, security, availability, and cost.

Algorail will not knowingly configure an AI service so that Customer Content submitted through HelmPilot is used to train or improve a general-purpose foundation model.

Our current AI infrastructure and model choices may change over time. More detailed current-state information about material AI providers, data-retention practices, and security architecture may be provided in Algorail’s security or trust documentation.

AI-generated and automatically extracted information can contain errors. Customers remain responsible for reviewing HelmPilot output before relying on it for consequential purposes.

5. When We Share Information

We do not sell Customer Content.

We do not sell personal information.

We do not use Customer Content for targeted advertising.

We disclose information only as reasonably necessary for purposes described in this Policy, including the following.

Service providers

We use service providers that help us operate Algorail and HelmPilot.

Material providers currently include:

  • Amazon Web Services (AWS) for cloud infrastructure and managed services, including AI-assisted processing;
  • Stripe for payment, invoicing, transaction, and related financial-processing services; and
  • Plausible Analytics for privacy-focused, aggregate analytics about use of Algorail’s public website.

We may also use limited service providers for functions such as email delivery, support, business administration, legal services, or accounting.

Service providers may process information only as appropriate to perform the services they provide to us or as otherwise permitted by applicable law and their agreements with us.

Customer organizations and Authorized Users

When HelmPilot is used for an institutional or organizational project, Customer Content and workspace information may be available to other Authorized Users who have been given access to that workspace.

You should not submit information to a shared workspace that you are not authorized to share with the other people who have access to it.

Legal and safety requirements

We may disclose information when we reasonably believe disclosure is required to:

  • comply with applicable law;
  • respond to a valid subpoena, court order, or other legal process;
  • protect the rights, property, or safety of Algorail, our customers, or others;
  • investigate fraud or misuse; or
  • respond to a material security incident.

Where legally permitted and reasonably practical, we will seek to notify the affected Customer before disclosing Customer Content in response to compulsory legal process.

Business transactions

If Algorail is involved in a merger, acquisition, financing, reorganization, or sale of business assets, information may be disclosed as reasonably necessary to evaluate or complete that transaction.

Any successor that receives Customer Content remains subject to applicable contractual and legal obligations concerning that information.

6. Payment Processing

Algorail intends to use third-party hosted payment services rather than collecting full payment-card credentials inside HelmPilot.

Stripe may collect payment and transaction information directly from purchasers and process that information according to Stripe’s own privacy practices and its role as Algorail’s payment-service provider.

Algorail may receive transaction information necessary to administer the customer relationship, such as payment status, amount, billing contact information, payment-method type, and transaction identifiers.

Do not enter full card numbers, bank credentials, or other payment credentials into HelmPilot project fields, support messages, or Customer Content.

7. Product-Usage Telemetry

HelmPilot’s usage telemetry is intentionally separated from project content.

The telemetry system is designed to collect bounded behavioral and operational information rather than the substance of a Customer’s work.

Product-usage telemetry is designed not to contain:

  • proposal or document text;
  • extracted project content;
  • free-text project information;
  • names;
  • email addresses;
  • telephone numbers; or
  • project budget amounts.

We may use product-usage telemetry to understand which features are useful, identify where workflows are confusing or abandoned, monitor adoption, and improve HelmPilot.

Security logging, diagnostic logging, Customer Content, support requests, and feedback are separate data channels and are governed by their own purposes and controls.

8. Feedback and Support Communications

If you choose to send feedback or request support, we receive the information you include in that communication.

Unlike product-usage telemetry, feedback and support messages may contain free text and may identify you.

Please do not include prohibited regulated or unusually sensitive information in feedback or support communications.

We may use feedback to improve HelmPilot. Providing feedback does not transfer ownership of Customer Content, grant proposals, research results, or other confidential project information to Algorail.

9. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, subject to operational, contractual, legal, accounting, tax, security, and dispute-resolution needs.

Active HelmPilot workspaces

Customer Content is retained while needed to provide the active HelmPilot service.

Expired paid subscriptions

Unless a Customer’s Order provides otherwise:

  1. a paid subscription receives a 14-day renewal grace period after its paid-through date;
  2. the workspace may then remain available in read-only status for up to 30 additional days so the Customer can retrieve information; and
  3. after that period, Algorail may delete Customer Content from active systems.

Customer Content may remain in backups for a longer period until those backups expire through normal retention processes.

Evaluations that do not become paid subscriptions

If a guided evaluation does not result in a paid subscription, Algorail will delete Customer Content from active systems within 30 days after the evaluation ends, unless:

  • the Customer purchases a subscription;
  • institutional procurement or payment is actively underway and the parties have agreed to continue access;
  • Algorail and the Customer expressly agree to extend the evaluation or follow-up period; or
  • Algorail is required to retain specific information for legal, security, or dispute-resolution purposes.

Customer Content may remain in backups for a longer period until those backups expire through normal retention processes.

We do not intend to retain abandoned evaluation workspaces indefinitely.

Business and legal records

We may retain limited information for longer periods when reasonably necessary for:

  • invoices and payment records;
  • tax documentation;
  • accounting;
  • fraud prevention;
  • security;
  • dispute resolution;
  • legal obligations; or
  • documentation of the customer relationship.

Deletion of Customer Content does not require deletion of records that Algorail must reasonably retain for those purposes.

10. Security

We use administrative, technical, and organizational measures intended to protect information against unauthorized access, disclosure, alteration, loss, or misuse.

These measures include controls appropriate to a cloud-hosted service, such as authentication and access controls, logging and monitoring, and protections provided by our cloud-service infrastructure.

No system can guarantee absolute security.

Customers and Authorized Users are also responsible for protecting their login credentials, controlling who has access to their workspace, and avoiding submission of prohibited information.

If we become aware of a security incident involving personal information or Customer Content, we will investigate and provide notifications when required by applicable law or contractual obligations.

11. Your Choices and Privacy Rights

You may contact us to:

  • ask what personal information we maintain about you;
  • request correction of inaccurate account information;
  • request deletion of personal information when appropriate;
  • request a copy of information associated with your account;
  • ask questions about our privacy or data practices; or
  • request that we stop sending non-transactional communications.

Depending on where you live, applicable law may provide additional privacy rights.

We will respond to valid requests as required by applicable law and may need to verify your identity before completing a request.

For information maintained as part of an institutional Customer’s HelmPilot workspace, we may direct a request to the Customer organization when that organization is responsible for deciding how the information is managed.

Some information may not be deleted immediately when we have a legitimate or legally required reason to retain it.

12. Children’s Privacy

HelmPilot is intended for professional use by adults.

We do not knowingly offer HelmPilot to children under 18 or knowingly collect personal information directly from children through HelmPilot.

If you believe a child has provided personal information directly to Algorail, contact us.

13. International Users

Algorail is a United States company, and our services are currently operated primarily from the United States.

If you access our services from outside the United States, information may be transferred to and processed in the United States or other jurisdictions in which our service providers operate.

If future operations require additional contractual or legal safeguards for international data transfers, Algorail will implement those safeguards as required by applicable law.

14. Third-Party Websites and Services

Our website or services may link to websites, payment services, or other resources operated by third parties.

Their privacy practices are governed by their own policies.

This Privacy Policy applies to Algorail’s handling of information and does not control the independent practices of third parties.

15. Changes to This Policy

We may update this Privacy Policy as our services, technology, providers, or legal obligations change.

If a change materially affects how we handle Customer Content or personal information for an existing paid Customer, we will provide reasonable notice when appropriate.

The effective date at the top of the Policy identifies the current version.

16. Contact Us

Questions, concerns, or privacy requests may be directed to:

Algorail AI, LLC
Maryland, United States
info@algorail.ai

© 2026 Algorail AI, LLC. All rights reserved.

algorail.ai
Terms of Service Privacy Acceptable Use Refund & Cancellation Contact