Privacy Policy
1. Who we are
Helpdesky (helpdesky.io) is operated by Massive Monkey Ltd, 54 Derby Square, Douglas, Isle of Man, IM1 3LP ("Helpdesky", "we"). Helpdesky is a support platform: a hosted help center, an Ask AI assistant trained on that help center, and a shared inbox fed by a chat widget, a contact form, a ticket center and forwarded email. You can reach us at support@helpdesky.io, through helpdesky.io/contact, or by post at the address above.
2. Operators, customers and roles
Two groups of people use Helpdesky:
- Operators are the businesses and team members who sign up, create a helpdesk and answer conversations. For operator account data, Helpdesky is the data controller.
- Customers (visitors) are the people who read an operator's help center, chat through the widget, send a contact form message, open a ticket or email the operator's support address. For this content Helpdesky acts on the operator's instructions as a processor; the operator decides what is collected and how long it is kept. Questions about a specific help center should go to that business first.
Operators whose business needs a data processing agreement (DPA) covering the customer data we process for them can request one through the contact form at helpdesky.io/contact.
3. What we process
3.1 Operator accounts
- Name, email address and a hashed password.
- Team membership: which helpdesks you belong to, your role (owner or staff), your permissions, whether you have accepted an invitation, and your notification preferences. Your name and email address are visible to the other members of those helpdesks; your name also appears next to the articles you write and on the replies you send to customers.
- Helpdesk settings: name, logo, colours, custom domain, subfolder or headless address, operator permissions, notification preferences and extra notification addresses, language.
- Billing status: your plan, usage against plan limits and the identifier of your subscription with our payment provider. Card details are entered on, and held by, the payment provider — Helpdesky never sees the full card number.
- Credentials you add deliberately, such as an AI provider API key: stored encrypted, shown only in masked form, and used solely to call that provider on your behalf.
- API keys, personal MCP tokens and connected-agent (OAuth) grants: stored hashed, with the time they were last used, so you can review and revoke them.
- Service email we send you: account messages, notifications about new conversations, and (if you enable them) scheduled reports. Open tracking on notification email is used only to avoid sending a notification you have already seen.
3.2 Help center content
Articles, categories, redirects, images and attachments you publish or draft, including content written with AI assistance, the name of the team member who created or edited each article, article view counts, plus external URLs you add as data sources for Ask AI. Published articles are public by design: they are served on your help center address, included in its sitemap and llms.txt, returned by the Content API, and may be read by search engines and AI agents. Embeddings (numerical representations) of published articles and data sources are generated so that search and Ask AI can find them.
3.3 Customer conversations
- Messages, attachments and the name and email address a customer provides in the widget, the contact form, the ticket center, or by emailing the operator's forwarded support address (including the email headers needed to thread replies).
- For the ticket center, the user identity your own application signs and passes to Helpdesky (an ID, and optionally name and email) so a signed-in user sees only their own tickets.
- What operators add to a conversation: replies, internal notes (visible to the team, never sent to the customer), assignment, status, and whether a contact is blocked.
- Questions asked to Ask AI and the answers given, kept so operators can see what customers ask and improve their articles.
- Technical data attached to a message or visit: IP address, user agent and referring page. This is used for spam protection, rate limiting, blocking abusive senders, and the article view statistics shown to operators.
- Delivery data for email notifications to customers (sent, opened) so operators know whether a reply reached them, and the language we detect a message is written in so operators can translate it.
3.4 Website visitors on helpdesky.io
Server logs (IP address, requested page, user agent) kept for security and debugging, and messages you send through the contact page. We do not run third-party advertising trackers on helpdesky.io.
4. AI providers
Ask AI answers, AI-written article drafts, translations, the AI SEO advisor and semantic search work by sending text to a large-language-model provider and using the result. Specifically:
- If you configure your own provider (for example OpenAI, Anthropic or Google), article text and customer questions for that helpdesk are sent to that provider under your account and their terms.
- If you do not, Helpdesky's default providers are used: Google (Gemini models) for answers and generation, and OpenAI for embeddings. These calls carry only the text needed for the request — article passages, the question, and conversation context for the current answer — not your account details or billing information.
- AI providers are instructed not to train on this data where their API terms allow it; we do not use your content to train models of our own.
- AI clients you connect yourself through the MCP server are different: they are not our providers, and what they receive is described in the next section.
5. MCP server and connected AI clients
The MCP server lets an operator connect an AI client of their choice (for example Claude, ChatGPT, Cursor, Claude Code or Replit Agent) to their helpdesk. The client acts as that operator, within the permissions the helpdesk owner has given them, and only when the operator asks it to do something. Depending on which tools the operator uses and on their permissions, a connected client can receive:
- The operator's own account: name, email address, role, permissions and plan.
- Team members: names, email addresses, roles, invitation status, permissions and notification preferences, plus any extra notification addresses set on the helpdesk.
- Customers and conversations: customer names and email addresses, conversation subjects, status and channel, the full text of messages including internal notes written by the team, attachment names, types, sizes and download links, when a customer read a reply, the detected language, and whether a contact is blocked.
- Ask AI activity: the questions visitors asked the help center's AI assistant and the answers given.
- Help center content: articles (published and draft) with the names of the team members who wrote them, categories, redirects, view counts, data-source URLs, SEO suggestions and link-scan results.
- Helpdesk configuration: branding, hosting addresses (custom domain, subfolder or headless), widget, contact form, ticket center, messaging, notification and automation settings, which AI provider is selected and whether a key is saved for it.
Connected clients never receive passwords, API keys, MCP tokens, ticket-center signing secrets, AI provider keys or visitors' IP addresses. We send this data to a client only in response to the operator's requests; what the client vendor then does with it is governed by that vendor's own privacy terms, so only connect clients you trust. If you connect a client to a helpdesk that holds customer data, you are responsible for making sure that is acceptable under your own privacy commitments to your customers. Operators can see and revoke every connected client and personal token in Dashboard → MCP, and revoking stops access immediately.
6. Hosting and subprocessors
We use the following providers to run the service. Each only receives the data needed for its function.
| Provider | Purpose | Data |
|---|---|---|
| DigitalOcean | Application servers and the primary database | All service data |
| Cloudflare | DNS, CDN, custom-domain routing, Turnstile spam protection, R2 file storage | Request metadata, uploaded images and attachments |
| Postmark | Sending and receiving service and notification email, inbound email forwarding | Email addresses, message content, delivery events |
| Polar | Subscriptions and payments | Billing contact details, payment method (held by Polar) |
| Google (Gemini) and OpenAI | Default AI answers, generation and embeddings | Article text and questions, as described above |
| Sentry | Error monitoring | Technical error reports, which may include request metadata |
| Google Fonts | Web fonts on marketing pages | IP address and browser headers of the page visitor |
Operators may additionally connect their own providers (AI providers, MCP clients, custom domains, their own email forwarding) which are governed by those providers' terms. We will update this list when a subprocessor is added or replaced.
7. Cookies and local storage
- Session cookie for signed-in operators (strictly necessary).
- Widget and ticket-center storage: a small identifier in the visitor's browser (cookie or local storage) that keeps a chat conversation attached to the same visitor and remembers preferences such as language and light/dark mode. It is scoped to the operator's site and is not used to track visitors across other websites.
- Turnstile (Cloudflare) sets what it needs to tell humans from bots on forms.
We do not use advertising or cross-site analytics cookies.
8. Retention and deletion
- Help center content, conversations, contacts and the Ask AI question log are kept for as long as the helpdesk exists. Operators can delete individual articles, conversations and contacts at any time, and can ask us to delete a whole helpdesk, which removes its content.
- When an operator account is deleted, the account and the helpdesks it owns are removed. Helpdesks shared with other operators remain with them.
- Database backups are kept for a limited period for disaster recovery and are then overwritten; deleted data disappears from backups on that cycle.
- Server and security logs are kept for a short, rolling period.
- Revoked API keys, MCP tokens and OAuth grants stop working immediately and are removed from the account.
9. Security
All traffic is encrypted in transit (TLS). Passwords, API keys and MCP tokens are stored hashed; provider credentials you add are stored encrypted. Access to production systems is limited to the people who operate the service. Operators control team access through per-member permissions, and every API and MCP call is checked against those permissions. If you believe you have found a security issue, email support@helpdesky.io.
10. Your rights
Depending on where you live you may have the right to access, correct, export or delete personal data, to object to or restrict processing, and to complain to a supervisory authority (for us that is the Isle of Man Information Commissioner; you can also complain to the authority where you live). Operators can do much of this directly in the dashboard (edit their profile, delete articles, conversations and contacts) and can ask us to delete a helpdesk or their account entirely. For data held in an operator's helpdesk about you as their customer, please contact that business; we will support them in responding. For anything else, email support@helpdesky.io.
Helpdesky is not directed at children and we do not knowingly collect data from anyone under 16.
11. Changes and contact
When this policy changes we update the date at the top; for material changes we notify operators by email or in the dashboard. Questions about this policy: support@helpdesky.io, helpdesky.io/contact, or by post to Massive Monkey Ltd, 54 Derby Square, Douglas, Isle of Man, IM1 3LP. See also our Terms of Service.