Legal
Privacy policy
Last updated: 31 July 2026
This privacy policy applies to coaches who use helping.app and, where relevant, to their clients. It was last updated on 31 July 2026. This is a first draft for review by a qualified lawyer, not legal advice.
About this privacy policy
helping.app is a messaging-based accountability platform used by coaches to send automated check-ins to their clients over SMS and Telegram. Clients reply by message — they never create an account or log in. This privacy policy explains what personal data we handle, why we use it, and the choices available to you.
It applies to two groups of people:
- Coaches who hold a helping.app account — our customers. For the personal data of coaches (such as account and billing details), we act as the data controller.
- Clients of coaches — the people a coach adds so that they can be messaged. Clients do not create a helping.app account and are not our customers. For the personal data of clients that a coach causes us to process, the coach is the data controller and helping.app is the data processor. We process that data only on the coach's instructions to deliver the service. See our data processing agreement.
In this policy, “we”, “us”, and “the service” mean helping.app.
Who operates helping.app
helping.app is operated by Darren, a sole trader (autónomo) registered in Spain.
- Operator: Darren (a sole trader (autónomo) registered in Spain).
- Trading as: helping.app (helping.app).
- Contact: hello@helping.app. We provide a registered business address and our tax details on legitimate request (for example, for an invoice or a data-processing agreement).
Because the operator is an individual sole trader rather than a registered company, there is no separate corporate entity involved; the founder is the operator. If you need a formal counterpart name for a contract, contact us at hello@helping.app.
What personal data we handle
Coach data
To set up and run your account, we handle:
- your name and email address;
- authentication data, such as the credentials used to sign in;
- billing information, which is handled by our payment provider, Stripe (we do not store your full card number);
- usage data, such as when you sign in and how you use the dashboard, used to operate, secure, and improve the service.
Client data (handled on behalf of the coach)
To send check-ins on a coach's instructions, we handle, on the coach's behalf:
- a client's name or identifier;
- phone number (used for SMS) — these are protected with field-level encryption for phone numbers;
- Telegram handle or identifier;
- check-in messages and the client's replies;
- response rate, streak, and engagement data;
- timezone, so check-ins land at the right local time.
What we do not collect from clients
Clients never create an account, never sign in, and never provide payment data to us. The only piece of the web a client ever sees is an optional, read-only progress link a coach chooses to share, which expires within 24 hours.
Why we use it (lawful bases)
Where the EU GDPR or UK GDPR applies, we rely on the following lawful bases, depending on the data:
- Performance of a contract — to provide the service to the coach under our agreement with them.
- Legitimate interests — to operate, secure, and improve the service, including aggregated product analytics and fraud prevention, balanced against your rights.
- Legal obligation — where we are required to keep records or respond to lawful requests.
- Consent — where we rely on it for specific, optional activities.
For clients: their personal data is processed as the coach's processor, on the coach's instructions and under the coach's own lawful basis for contacting them. We do not decide to message a client — the coach does. It is the coach's responsibility to have a lawful basis (including any required consent) to contact each client.
Who is responsible for client data
The coach is the data controller for their clients' personal data. They decide which clients to add, what to ask, when to message, and on which channel, and they are responsible for collecting and using that data lawfully, including any required consent and opt-out handling.
helping.app is the data processor for that client data. We process it only to deliver the service on the coach's instructions, as set out in our data processing agreement and our terms of service.
Sharing & subprocessors
We share personal data only with the third parties needed to run the service, and only as necessary. Our current subprocessors are:
- Twilio (and Telnyx, where applicable) — SMS delivery for check-ins and replies.
- Telegram Messenger Inc. — Telegram message delivery for check-ins and replies.
- Stripe — Payment processing and billing.
- Self-hosted infrastructure — Hosting and storage of account and client data, on infrastructure the operator controls (not a shared public cloud).
- Glitchtip (or a Sentry-compatible service) — Error monitoring and application diagnostics.
Each subprocessor is bound by written terms that require appropriate confidentiality and security. We do not sell personal data, and we do not allow subprocessors to use it for their own marketing.
International transfers
Because our subprocessors operate globally (and several — Stripe, Twilio, and Telegram — are based in the United States), personal data may be processed outside the country in which it was collected, for example when a message is routed by a carrier or platform. Where this happens, we put appropriate safeguards in place, as described in our data processing agreement.
Retention
We keep personal data only for as long as we need it. In broad terms:
- Coach data is retained while your account is active, and for a short period after closure so we can complete export, fulfil legal obligations, and handle cancellation, after which it is deleted.
- Client data is retained while the coach keeps the client in helping.app. When a coach removes a client, the data is kept for 30 days and then anonymised.
Security
We are self-hosted on infrastructure the operator controls, not a shared public cloud. Data is protected with encryption in transit (TLS) and encryption at rest, phone numbers benefit from field-level encryption for phone numbers, and access to data is restricted to authorised personnel on a least-privilege basis. No system can be guaranteed secure, and we do not make absolute promises, but we design the service with security and privacy in mind from the start.
Your rights (GDPR & UK GDPR)
If you are in the EU, EEA, or UK, or otherwise covered by the EU GDPR or UK GDPR, you may have the right to ask us to:
- be informed about how your data is used;
- access the personal data we hold about you;
- rectify (correct) inaccurate data;
- erase your personal data (the “right to be forgotten”);
- restrict how we process your data;
- receive a copy of your data in a portable format (data portability);
- object to certain processing; and
- withdraw consent, where we rely on it.
You also have the right to lodge a complaint with your data protection regulator. For coaches, these rights apply to your account data. For a coach's clients, the coach is the controller, so clients usually exercise these rights through their coach; a client may also contact us directly and we will cooperate with the coach as the controller. See our plain-English rights page for more.
Your privacy rights in the United States
The United States has no single federal privacy law. Instead, a growing number of states give their residents privacy rights. If you are a US resident, the rights below may apply to you depending on your state. We do not sell personal data.
California — CCPA and CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the right to:
- know what personal information we have collected about you and how it is used or shared;
- delete your personal information;
- correct inaccurate personal information;
- opt out of the “sale” or “sharing” of your personal information for targeted advertising or cross-context behavioural advertising; and
- limit the use of sensitive personal information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Whether our use of analytics or subprocessors could count as a “share” under the CPRA is something to assess with a lawyer before launch; our position today is that these are service providers acting on our behalf under written terms, not recipients that “share” data for their own advertising.
You can exercise these rights by emailing hello@helping.app. You will not be discriminated against for exercising them.
Other US state privacy laws
Several other states have comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, and Montana, with more taking effect over time. Across these laws, residents generally have a common set of rights:
- access and confirm the personal data we hold about you;
- delete your personal data;
- correct inaccurate personal data;
- opt out of targeted advertising, the “sale” of personal data, and certain profiling that produces legal or similarly significant effects; and
- appeal a decision we make about your request.
As above, we do not sell personal data or use it for targeted advertising. If any of these rights apply to you, contact us at hello@helping.app and we will respond within the timeframe your state's law requires. Where a request is denied, we will tell you how to appeal.
Data-breach notification
All 50 US states (and US territories) have their own data-breach notification laws, which differ in scope and timing. Because we store phone numbers and messages, we treat the security of that data seriously. If a breach occurs that triggers notification obligations, we will follow the applicable state requirements and notify affected individuals and regulators as required.
Cookies
Our marketing site uses only essential cookies needed to function. We do not use advertising or cross-site tracking cookies.
Children
helping.app is not directed at anyone under 18, and is not intended for use by children under 13 (or any higher minimum age in the relevant US state). Coaches must only add clients who are adults, or for whom they hold appropriate authority to act. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes & contact
We may update this policy from time to time. When we do, we will revise the “last updated” date above and, for material changes, give reasonable notice. Continued use of helping.app after a change takes effect indicates acceptance of the updated policy.
You can complain to your data protection regulator. In the EU or EEA, contact your national authority; because we are established in Spain, our lead supervisory authority under the GDPR is the Spanish Data Protection Agency (AEPD — Agencia Española de Protección de Datos). In the UK, contact the Information Commissioner's Office (ICO). If you are in the United States, you may also contact your state attorney general. We would welcome the chance to put things right first, but you are free to go to your regulator at any time.
Questions about this document? Email hello@helping.app.
This is a first draft for review by a qualified lawyer, not legal advice.