Use Cases Ask AI Pricing Embeds AI Skill MCP Server Sign in Get Started
Legal

Privacy Policy

Last updated: 3 October 2026 · Applies to helpdesky.io, help centers hosted by Helpdesky, the embeddable widget, contact form and ticket center, the REST API, the Content API and the MCP server.

In short: Helpdesky stores the help center content and support conversations that you and your customers put into it, uses them only to run your helpdesk, and does not sell or share them for advertising. AI features send text to the AI provider you configure (or Helpdesky's default provider) only to produce the answer or embedding you asked for. AI clients you connect through the MCP server receive data from your helpdesk only when you ask them to act on it.

1. Who we are

Helpdesky (helpdesky.io) is operated by Massive Monkey Ltd, 54 Derby Square, Douglas, Isle of Man, IM1 3LP ("Helpdesky", "we"). Helpdesky is a support platform: a hosted help center, an Ask AI assistant trained on that help center, and a shared inbox fed by a chat widget, a contact form, a ticket center and forwarded email. You can reach us at support@helpdesky.io, through helpdesky.io/contact, or by post at the address above.

2. Operators, customers and roles

Two groups of people use Helpdesky:

Operators whose business needs a data processing agreement (DPA) covering the customer data we process for them can request one through the contact form at helpdesky.io/contact.

3. What we process

3.1 Operator accounts

3.2 Help center content

Articles, categories, redirects, images and attachments you publish or draft, including content written with AI assistance, the name of the team member who created or edited each article, article view counts, plus external URLs you add as data sources for Ask AI. Published articles are public by design: they are served on your help center address, included in its sitemap and llms.txt, returned by the Content API, and may be read by search engines and AI agents. Embeddings (numerical representations) of published articles and data sources are generated so that search and Ask AI can find them.

3.3 Customer conversations

3.4 Website visitors on helpdesky.io

Server logs (IP address, requested page, user agent) kept for security and debugging, and messages you send through the contact page. We do not run third-party advertising trackers on helpdesky.io.

4. AI providers

Ask AI answers, AI-written article drafts, translations, the AI SEO advisor and semantic search work by sending text to a large-language-model provider and using the result. Specifically:

5. MCP server and connected AI clients

The MCP server lets an operator connect an AI client of their choice (for example Claude, ChatGPT, Cursor, Claude Code or Replit Agent) to their helpdesk. The client acts as that operator, within the permissions the helpdesk owner has given them, and only when the operator asks it to do something. Depending on which tools the operator uses and on their permissions, a connected client can receive:

Connected clients never receive passwords, API keys, MCP tokens, ticket-center signing secrets, AI provider keys or visitors' IP addresses. We send this data to a client only in response to the operator's requests; what the client vendor then does with it is governed by that vendor's own privacy terms, so only connect clients you trust. If you connect a client to a helpdesk that holds customer data, you are responsible for making sure that is acceptable under your own privacy commitments to your customers. Operators can see and revoke every connected client and personal token in Dashboard → MCP, and revoking stops access immediately.

6. Hosting and subprocessors

We use the following providers to run the service. Each only receives the data needed for its function.

ProviderPurposeData
DigitalOceanApplication servers and the primary databaseAll service data
CloudflareDNS, CDN, custom-domain routing, Turnstile spam protection, R2 file storageRequest metadata, uploaded images and attachments
PostmarkSending and receiving service and notification email, inbound email forwardingEmail addresses, message content, delivery events
PolarSubscriptions and paymentsBilling contact details, payment method (held by Polar)
Google (Gemini) and OpenAIDefault AI answers, generation and embeddingsArticle text and questions, as described above
SentryError monitoringTechnical error reports, which may include request metadata
Google FontsWeb fonts on marketing pagesIP address and browser headers of the page visitor

Operators may additionally connect their own providers (AI providers, MCP clients, custom domains, their own email forwarding) which are governed by those providers' terms. We will update this list when a subprocessor is added or replaced.

7. Cookies and local storage

We do not use advertising or cross-site analytics cookies.

8. Retention and deletion

9. Security

All traffic is encrypted in transit (TLS). Passwords, API keys and MCP tokens are stored hashed; provider credentials you add are stored encrypted. Access to production systems is limited to the people who operate the service. Operators control team access through per-member permissions, and every API and MCP call is checked against those permissions. If you believe you have found a security issue, email support@helpdesky.io.

10. Your rights

Depending on where you live you may have the right to access, correct, export or delete personal data, to object to or restrict processing, and to complain to a supervisory authority (for us that is the Isle of Man Information Commissioner; you can also complain to the authority where you live). Operators can do much of this directly in the dashboard (edit their profile, delete articles, conversations and contacts) and can ask us to delete a helpdesk or their account entirely. For data held in an operator's helpdesk about you as their customer, please contact that business; we will support them in responding. For anything else, email support@helpdesky.io.

Helpdesky is not directed at children and we do not knowingly collect data from anyone under 16.

11. Changes and contact

When this policy changes we update the date at the top; for material changes we notify operators by email or in the dashboard. Questions about this policy: support@helpdesky.io, helpdesky.io/contact, or by post to Massive Monkey Ltd, 54 Derby Square, Douglas, Isle of Man, IM1 3LP. See also our Terms of Service.