Skip to main content
Last updated: July 27, 2026

1. Introduction and Scope

Helium (“Helium,” “the Service”) is a hosted, multi-tenant REST API, MCP (Model Context Protocol) server, and Slack app for fundraising research — helping a founder identify and research VCs, angels, and other investors to raise from, or helping a fund identify LPs (family offices, HNW individuals, recently-exited founders, and institutional investors) to raise from. Helium is operated by Gravity GTM, Inc. (“Gravity GTM,” “we,” “us,” “our”), a sub-product of gravitygtm.com, sharing its underlying account, credit, and Slack-app infrastructure with our related product Horizon. Helium is live at lite.gravitygtm.com with documentation at docs.gravitygtm.com/helium. This Privacy Policy covers three distinct categories of data, and it is important to understand the differences between them: (a) Your account data. Information about you or your organization as a Helium customer — your email address, billing information, API key records, and, if you use our Slack app, your Slack workspace information. For this data, Gravity GTM is the data controller. (b) Your fundraising profile and connected-Gmail data. Information you provide directly about your own raise (stage, sector, geography, fund thesis, target LP types, and similar), any LinkedIn connections data you choose to upload for warm-path matching, and, if you connect your Gmail account, data from that connected Google account. This is your own data, provided or authorized by you, used to power the Service on your behalf. Gravity GTM is the data controller for this category too. (c) Third-party lookup data. Helium’s core function is helping customers research other entities — investors, funds, family offices, and companies. The names, firm data, LinkedIn profile data, and company data returned by the Service are personal or business data about those third parties, not about you. For this category, Gravity GTM generally acts as a processor (or sub-processor, one level removed) — we process this data only as instructed by, and on behalf of, the customer who submitted the research request. If you are a data subject whose information was looked up through Helium by one of our customers, please direct data rights requests to that customer in the first instance, though we will assist where we are able to.

2. Information We Collect

Account and billing data. When you sign up, we collect your email address and, via our payment processor Stripe, billing and payment details. Gravity GTM never directly handles or stores raw card numbers. API keys. Shown to you once at creation and stored on our systems only as a one-way SHA-256 hash. We cannot retrieve a plaintext key after issuance; a lost key can only be rotated or revoked. Slack workspace data. If you install the Helium Slack app, we store: the Slack bot token and the workspace’s Helium API key, both in reversibly-encrypted form (AES-256-GCM), because they are needed to make live calls on the workspace’s behalf; and, in plain (unencrypted) form, the Slack workspace ID, workspace name, the ID of the Slack user who installed the app, and install/uninstall timestamps. Fundraising profile data. If you use set_fundraising_profile (via the API, MCP, or Slack app), we store what you tell us about your raise: whether you’re a founder raising equity or a fund raising from LPs, stage, sector, geography, round size or check size, known competitors or fund thesis, target LP types, and (optionally) your own and your company’s LinkedIn URLs. This data is used only to power your own search and scoring results — never shared with other customers. Network import data. If you upload your LinkedIn connections export (via import_network) to power warm-path matching in investor/LP search, we store the parsed rows (name, company, and, where present, LinkedIn URL and email address, as exported by LinkedIn) against your account. This data is used only for your own warm-path matching and is not shared with other customers. Connected Gmail/Calendar data. If you connect your Gmail account, we store your Google account’s email address and an encrypted OAuth refresh token (AES-256-GCM), obtained with your explicit authorization via Google’s own consent screen, scoped to: sending email on your behalf, reading your Gmail inbox, and reading your calendar’s availability. This connection exists to let Helium send fundraising outreach you’ve approved, detect when an investor has replied so a sequence can be paused rather than continue landing in an inbox that’s already responded, and propose real, available meeting times rather than a fabricated scheduling link. We do not independently retain the content of your emails or calendar beyond what is needed to perform the specific action it was fetched for (e.g., checking a thread for a reply). You can revoke this access at any time directly through Google (myaccount.google.com/permissions), which immediately invalidates our stored refresh token, or by contacting us at help@gravitygtm.com to have your connection removed on our end. Cached lookup results. To reduce cost and latency, certain investor/LP/company research results are temporarily cached and may be shared across customers. Operational logs. Our systems log metadata only: request ID, tenant/account ID, API key ID, which endpoint was called, credits charged, cache hit/miss status, and timestamps. Logs never contain the substantive content of a lookup or of any connected-Gmail data.

3. How We Use Information

We use the information described above to: operate, provide, and bill for the Service, including tracking and deducting prepaid credits; power investor/LP/company search, scoring, and enrichment using your fundraising profile and (where uploaded) your network import data; where you’ve connected Gmail, send fundraising outreach you’ve approved, detect inbound replies to pause a sequence, and check real calendar availability rather than propose a fabricated meeting time; serve cached results to reduce vendor costs and improve response times; detect and prevent fraud, abuse, and security incidents; enforce our rate limits; and respond to support and account requests.

4. Subprocessors

We use the following subprocessors to provide the Service. Each receives only the data necessary to perform its function: This table is the authoritative, current list of our subprocessors. We may update it as our vendors change; material changes will be reflected here, with the “Last updated” date revised accordingly (see Section 11), and, where required by our Data Processing Agreement, by direct notice to affected customers.

5. Data Retention

  • Cached lookup results: Investor/LP/company research results are cached for up to 24 hours.
  • Fundraising profile and network import data: Retained for the life of your account, or until you update/replace it.
  • Connected Gmail/Calendar data: The encrypted refresh token and connected email address are retained until you disconnect (via Google directly, or by contacting us) or your account is closed. We do not independently retain email or calendar content beyond what a specific action needed it for.
  • Operational logs: Retained for no longer than 30 days.
  • Account data: Retained for the life of your account, and for a reasonable additional period afterward as needed for legal, tax, and accounting purposes.
  • Credit balances: Purchased credits do not currently expire.

6. Data Security

We apply technical safeguards appropriate to the sensitivity of each data type: API keys are stored only as one-way SHA-256 hashes and cannot be recovered in plaintext; Slack bot tokens, workspace API keys, and Gmail OAuth refresh tokens are stored using AES-256-GCM encryption (with a distinct encryption context per record, so a ciphertext copied into the wrong record fails to decrypt rather than silently revealing the wrong value); and all data in transit to and from the Service is encrypted using TLS. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Subject Rights

Depending on your jurisdiction, you may have rights under GDPR, CCPA, or similar laws to access, correct, delete, or receive a portable copy of your personal data. Account, fundraising profile, and connected-Gmail data: To exercise these rights, contact us at help@gravitygtm.com. Gmail disconnection can also be done immediately and independently through Google’s own account permissions page (myaccount.google.com/permissions) without waiting on us. We do not currently offer a self-service tool for deleting account or profile data itself — these requests are handled manually by our team (an operator-assisted process). Cached lookup data: A specific cached lookup result can be deleted ahead of its natural expiry via a self-service API call, the same mechanism Horizon offers — see Horizon’s Errors & Rate Limits page for the exact request shape, which Helium shares. Third-party lookup data: If your information was looked up by one of our customers through Helium, we recommend contacting that customer directly, as they control the purpose and lawful basis of the lookup. We will support such requests as appropriate given our role as a processor.

8. International Data Transfers

Helium’s infrastructure and subprocessors may process and store data in countries other than your own, including the United States. Where we transfer personal data across borders, we aim to use appropriate safeguards consistent with applicable law. We are continuing to formalize our specific transfer mechanisms as part of ongoing compliance work.

9. Children’s Privacy

Helium is a business-to-business service not directed at, marketed to, or knowingly used by children. We do not knowingly collect personal data from individuals under the age of 16 (or the applicable age of consent in their jurisdiction). If you believe a child has provided us with personal data, please contact us so we can address it.

10. California Residents / CCPA

Certain aspects of Helium’s research functionality may be relevant to California’s data-broker-related regulations and similar laws in other jurisdictions, depending on how the Service is used. We are evaluating our obligations, including any applicable registration requirements, as part of our ongoing compliance program. California residents otherwise have rights consistent with those described in Section 7.

11. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable law. We will update the “Last updated” date above when we do, and for material changes we will make reasonable efforts to notify active customers.

12. Contact Us

Questions about this Policy or requests regarding your data can be sent to: help@gravitygtm.com Gravity GTM, Inc. 2995 55th Street, Unit 17033, Boulder, CO 80308