Privacy Policy

How Helix Athletic collects, uses, keeps, and deletes your information.

Last updated: August 18, 2026

Who we are

Helix Athletic provides training-programming and athlete-management software to gyms and athletic training facilities. When you train at a gym that uses Helix, your gym’s coaches and physiotherapists enter, review, and act on your information inside Helix. Helix operates the software; your gym runs the training relationship.

Helix is not a healthcare provider, a health plan, or a healthcare clearinghouse, and it does not operate as a HIPAA covered entity. Nothing on this page should be read as a claim that HIPAA governs your information here. The laws we do operate under are described below.

What we collect

We collect the following categories of information:

  • Account information — your name, email address, password (stored only as a one-way hash), and, if you sign in with Google or Apple, the account identifier that provider returns.
  • Profile and contact information — preferred and legal name, phone number, date of birth, profile photo, and emergency-contact details you or your gym provide.
  • Health and fitness information — physiotherapy assessments, movement screens, injury history, medical considerations, medications, training programs, completed workouts, loads and repetitions, personal records, and coaching notes about your training. Where you are seen by a physiotherapist, this also includes the reason you were referred and the referring clinician.
  • Billing information — membership status, invoices, charges, refunds, and payment-method metadata (card brand and last four digits). Full card numbers are entered directly into our payment processor and never reach Helix servers.
  • Agreements you sign — liability waivers and other e-signed documents, including the signed document itself and the signing metadata: who signed, when, the IP address the signature came from, and — where a parent or guardian signs for an athlete — the signer’s name and their stated relationship to the athlete.
  • Messages — messages you exchange with your gym’s coaches and staff inside Helix, and the notifications we send you about them. If you emailed the gym before you joined, and the gym connects its inbox to Helix, the body of that email thread is stored against your enquiry record too.
  • Enquiry records — if you contacted a gym before joining, the contact details and notes captured about that enquiry, including anything the gym recorded while following up.
  • Crash and performance diagnostics — when the app errors or runs slowly, a technical report is sent to our error-monitoring provider. It can include the identifier of the signed-in account, so we treat it as linked to you rather than anonymous.
  • Usage and security information — sign-in events, IP address, device and browser information, and access logs recording which staff account viewed which records.
  • Scheduling information — bookings, attendance, and, if you connect a calendar, the calendar events Helix creates for your sessions.

How we use it

We use your information to generate and deliver your training programs, to let your coaches and physiotherapists do their work, to run your membership and billing, to schedule and record sessions, to keep the service secure, and to meet legal and tax obligations.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act. We do not use your health or fitness information for advertising of any kind.

Health and fitness data

Assessments, injuries, medical considerations, and medications are the most sensitive information Helix holds. Medical considerations and medications are encrypted at rest with AES-256-GCM, and every staff read of a record containing health information is logged.

Some of that information can describe a health condition or disability. Where you are seen by a physiotherapist, we hold the reason you were referred and by whom; coaches and physiotherapists also write free-text notes about your training and your injuries. We do not ask you to declare a disability, and there is no field for one — but we do not claim that what is written in these records could never amount to that, and we disclose it here rather than leave you to infer it.

We treat this information as medical information under California’s Confidentiality of Medical Information Act (Cal. Civ. Code § 56.06), which applies to businesses that offer software to consumers for managing medical information. We do not disclose it without your authorization except as that law permits.

Helix is also a health app subject to the FTC Health Breach Notification Rule. If health information is acquired without your authorization, we will notify you, the Federal Trade Commission, and — where the Rule requires it — the media, within the timelines the Rule sets.

Not medical advice. Helix generates training programs from assessment data. It does not diagnose, treat, cure, or prevent any disease or injury, and it is not a substitute for professional medical care. Consult a physician before beginning any training program. Training carries inherent risk of injury. The full disclaimer is in our Terms of Service.

Who we share it with

Your gym. Staff at the gym you train with — coaches, physiotherapists, front-desk staff, and administrators — can see the records their role permits. Your information is scoped to your gym; staff at other organizations using Helix cannot see it.

Service providers. We use vendors to run the service, each with access limited to what their function requires: Stripe (payments), Amazon Web Services (hosting, storage, and email delivery), Google (calendar sync and email intake, only where your gym has connected them), and Sentry (crash and performance diagnostics, which can carry the identifier of the signed-in account).

Helix support staff. A small number of Helix platform administrators can enter an organization to provide support. Those sessions are time-limited and logged.

Legal. We may disclose information when required by law, to enforce our agreements, or to protect the rights and safety of our users.

Your privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights to:

  • Know and access — what personal information we collect, the sources, the purposes, and who we disclose it to, and to receive a copy in a portable format.
  • Delete — request deletion of the personal information we hold about you, subject to the legal-obligation exceptions described in the next section.
  • Correct — ask us to fix inaccurate personal information.
  • Opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of; we will tell you here if that ever changes.
  • Limit the use of sensitive personal information — we use sensitive information, including health information, only to provide the service you asked for.
  • Non-discrimination — we will not deny service, charge a different price, or provide a lower quality of service because you exercised a privacy right.

Under the Confidentiality of Medical Information Act you may also request a copy of the medical information we maintain about you.

To exercise any of these rights, email support@helixathletic.com. We will verify your identity against your account before we act on a request, and you may use an authorized agent. Deletion can also be done yourself, in the app — see Account deletion.

What we keep, and for how long

Deleting your account does not erase every record. Some categories are kept because a law, a tax rule, or a legal-evidence obligation requires it. This is what happens to each category when your account is deleted:

How long we keep each category. Signed waivers and their PDFs are held under a storage lock that runs to the longest of the applicable claim periods — four years for a standard agreement, seven where a tax rule reaches it, and up to twenty-two years where the signer was a minor, because the claim period does not begin until they reach adulthood. Audit and access logs are retained for six years. Financial and billing records are retained for as long as tax and accounting law requires, which in California is currently four years from the filing they support. Training, assessment, injury and message records have no fixed period: they are the gym’s business record and the gym decides how long its business records live, so the criterion is the gym’s own retention practice rather than a period we set. A suppressed email address is kept indefinitely, because its whole purpose is to keep working.

  • Sign-in credentials and sessions — deleted. Your password hash, connected Google/Apple accounts, and all active sessions are destroyed.
  • Your identity on your profile — erased. Names, email address, phone number, date of birth, profile photo, and emergency contacts are removed or replaced with placeholders. Two exceptions are named below and are not covered by this line: the name on a waiver you signed, and an email address you asked us to stop mailing.
  • Medical considerations and medications — deleted.
  • Personal preferences — partly deleted. Favorites, notification settings, interface preferences, and any connected calendar are removed. The training preferences your programs were built from — your equipment, your emphasis choices — stay with the training record they shaped, identity-reduced like the rest of it.
  • Training, assessment, and injury records — retained as the gym’s business record, identity-reduced. The workouts, assessments, injuries, needs analyses, programs, and personal records stay in your gym’s data set, with your identity severed from them. Where you were seen by a physiotherapist, the reason you were referred and the referring clinician are retained with that record too. We do not describe these records as de-identified or anonymized: free-text coaching notes, assessment dates, and performance patterns can carry residual identifying detail, and calling them anonymous would be an overclaim.
  • Signed waivers and agreements — retained as legal records, including the signed PDF. A waiver is the gym’s evidence of the agreement you made; it survives the account it was signed under. The signer’s full legal name is retained with it, whether you signed for yourself or a parent or guardian signed for you. So is the rest of the chain of custody: the IP address the signature was made from, and, where someone signed on your behalf, their stated relationship to you. A signature with no record of who made it, from where, is not evidence of anything — which is why this is the one place your name is not erased.
  • Messages with your gym — retained as the gym’s business record, identity-reduced. Messages between you and your gym’s staff record what was asked, advised, and agreed about your training, so they are kept for the same reason coaching notes are, and with your identity severed from them in the same way. Anything you wrote in a message stays as you wrote it, which is why we describe it as identity-reduced rather than anonymous.
  • Financial and billing records — retained. Invoices, charges, refunds, and membership history are kept to meet tax and accounting obligations. Stripe, our payment processor, also retains its own customer record — including the name and email address on file with Stripe — under the same legal-obligation carve-out. Deleting your Helix account does not delete Stripe’s record.
  • Audit and access logs — retained. Records of who accessed what, and when, are security and forensic evidence; deleting them on request would defeat their purpose.
  • An email address you asked us to stop mailing — retained, on purpose. If you unsubscribed or a message to you hard-bounced, we keep that address on a suppression list. Deleting it would make us start emailing you again, which is the opposite of what you asked for. It is stored only to NOT send.
  • The link between your billing records and Stripe — retained. Your gym keeps its financial records, and those records carry the customer reference that joins them to Stripe’s own copy of your name and email. We are explicit about this because it means the identity severed from your training data is still reachable through the billing side, by your gym and by Stripe.

Deleting your account

You can delete your account yourself, at any time, from inside the app: Profile → Security → Delete account. You will be asked to confirm who you are and to type DELETE. If you cannot sign in, email support@helixathletic.com from your account address and we will verify the request and delete the account for you. Either way deletion is irreversible: there is no grace period and no undo.

Deleting your account does not cancel your gym membership or stop billing. Contact your gym to end a membership.

Step-by-step instructions, and the full list of what is deleted versus retained, are on the Account deletion page.

How we protect it

Data is encrypted in transit with TLS and at rest. Medical considerations and medications carry an additional application-layer AES-256-GCM encryption. Staff accounts are protected by role-based access controls and multi-factor authentication where enrolled, and reads of health information are recorded in an audit log. No system is perfectly secure, but these are the controls we run.

Children

Helix is not directed to children under 13, and we do not knowingly collect their information. Athletes under 18 are enrolled by a gym with a parent or guardian, who signs the waiver and manages billing. If you believe a child’s information has been provided to us without the right authorization, contact us and we will remove it.

Changes to this policy

When we change this policy we update the “Last updated” date at the top of this page. Material changes will also be announced in the app.

Contact us

Questions, requests, and complaints about this policy go to support@helixathletic.com.