1. Introduction and Scope
Helium (“Helium,” “the Service”) is a hosted, multi-tenant REST API, MCP (Model Context Protocol) server, and Slack app for fundraising research — helping a founder identify and research VCs, angels, and other investors to raise from, or helping a fund identify LPs (family offices, HNW individuals, recently-exited founders, and institutional investors) to raise from. Helium is operated by Gravity GTM, Inc. (“Gravity GTM,” “we,” “us,” “our”), a sub-product of gravitygtm.com, sharing its underlying account, credit, and Slack-app infrastructure with our related product Horizon. Helium is live at lite.gravitygtm.com with documentation at docs.gravitygtm.com/helium. This Privacy Policy covers three distinct categories of data, and it is important to understand the differences between them: (a) Your account data. Information about you or your organization as a Helium customer — your email address, billing information, API key records, and, if you use our Slack app, your Slack workspace information. For this data, Gravity GTM is the data controller. (b) Your fundraising profile and connected-Gmail data. Information you provide directly about your own raise (stage, sector, geography, fund thesis, target LP types, and similar), any LinkedIn connections data you choose to upload for warm-path matching, and, if you connect your Gmail account, data from that connected Google account. This is your own data, provided or authorized by you, used to power the Service on your behalf. Gravity GTM is the data controller for this category too. (c) Third-party lookup data. Helium’s core function is helping customers research other entities — investors, funds, family offices, and companies. The names, firm data, LinkedIn profile data, and company data returned by the Service are personal or business data about those third parties, not about you. For this category, Gravity GTM generally acts as a processor (or sub-processor, one level removed) — we process this data only as instructed by, and on behalf of, the customer who submitted the research request. If you are a data subject whose information was looked up through Helium by one of our customers, please direct data rights requests to that customer in the first instance, though we will assist where we are able to.2. Information We Collect
Account and billing data. When you sign up, we collect your email address and, via our payment processor Stripe, billing and payment details. Gravity GTM never directly handles or stores raw card numbers. API keys. Shown to you once at creation and stored on our systems only as a one-way SHA-256 hash. We cannot retrieve a plaintext key after issuance; a lost key can only be rotated or revoked. Slack workspace data. If you install the Helium Slack app, we store: the Slack bot token and the workspace’s Helium API key, both in reversibly-encrypted form (AES-256-GCM), because they are needed to make live calls on the workspace’s behalf; and, in plain (unencrypted) form, the Slack workspace ID, workspace name, the ID of the Slack user who installed the app, and install/uninstall timestamps. Fundraising profile data. If you useset_fundraising_profile (via the API, MCP, or Slack app), we store what you tell us about your raise: whether you’re a founder raising equity or a fund raising from LPs, stage, sector, geography, round size or check size, known competitors or fund thesis, target LP types, and (optionally) your own and your company’s LinkedIn URLs. This data is used only to power your own search and scoring results — never shared with other customers.
Network import data. If you upload your LinkedIn connections export (via import_network) to power warm-path matching in investor/LP search, we store the parsed rows (name, company, and, where present, LinkedIn URL and email address, as exported by LinkedIn) against your account. This data is used only for your own warm-path matching and is not shared with other customers.
Connected Gmail/Calendar data. If you connect your Gmail account, we store your Google account’s email address and an encrypted OAuth refresh token (AES-256-GCM), obtained with your explicit authorization via Google’s own consent screen, scoped to: sending email on your behalf, reading your Gmail inbox, and reading your calendar’s availability. This connection exists to let Helium send fundraising outreach you’ve approved, detect when an investor has replied so a sequence can be paused rather than continue landing in an inbox that’s already responded, and propose real, available meeting times rather than a fabricated scheduling link. We do not independently retain the content of your emails or calendar beyond what is needed to perform the specific action it was fetched for (e.g., checking a thread for a reply). You can revoke this access at any time directly through Google (myaccount.google.com/permissions), which immediately invalidates our stored refresh token, or by contacting us at help@gravitygtm.com to have your connection removed on our end.
Cached lookup results. To reduce cost and latency, certain investor/LP/company research results are temporarily cached and may be shared across customers.
Operational logs. Our systems log metadata only: request ID, tenant/account ID, API key ID, which endpoint was called, credits charged, cache hit/miss status, and timestamps. Logs never contain the substantive content of a lookup or of any connected-Gmail data.
3. How We Use Information
We use the information described above to: operate, provide, and bill for the Service, including tracking and deducting prepaid credits; power investor/LP/company search, scoring, and enrichment using your fundraising profile and (where uploaded) your network import data; where you’ve connected Gmail, send fundraising outreach you’ve approved, detect inbound replies to pause a sequence, and check real calendar availability rather than propose a fabricated meeting time; serve cached results to reduce vendor costs and improve response times; detect and prevent fraud, abuse, and security incidents; enforce our rate limits; and respond to support and account requests.4. Subprocessors
We use the following subprocessors to provide the Service. Each receives only the data necessary to perform its function:
This table is the authoritative, current list of our subprocessors. We may update it as our vendors change; material changes will be reflected here, with the “Last updated” date revised accordingly (see Section 11), and, where required by our Data Processing Agreement, by direct notice to affected customers.
5. Data Retention
- Cached lookup results: Investor/LP/company research results are cached for up to 24 hours.
- Fundraising profile and network import data: Retained for the life of your account, or until you update/replace it.
- Connected Gmail/Calendar data: The encrypted refresh token and connected email address are retained until you disconnect (via Google directly, or by contacting us) or your account is closed. We do not independently retain email or calendar content beyond what a specific action needed it for.
- Operational logs: Retained for no longer than 30 days.
- Account data: Retained for the life of your account, and for a reasonable additional period afterward as needed for legal, tax, and accounting purposes.
- Credit balances: Purchased credits do not currently expire.