helfin

Privacy Policy

helfin app & website

Last updated: 1 July 2026

This policy explains what personal data helfin processes — in the helfin web application and on this website — why we process it, and the rights you have. helfin is built to hold as little of your data as possible: your accounting is encrypted on your device before it reaches our servers, and we cannot read it.

1. Who is responsible

The controller responsible for the data processing described here is:

Korner Studio Sàrl
Impasse des Amandiers 4
1585 Salavaux VD, Switzerland
Email: privacy@helfin.ch

For any question about your data or this policy, write to the email above.

2. The short version

3. Data the helfin app processes

Your account

To create and secure your account we process your email address and a password (kept only as a salted, one-way hash — we never store the password itself). This is used to sign you in, sync your data across your own devices, and contact you about your account and service.

Your accounting data

When you use helfin you create financial and business data — invoices and offers, expenses and receipts, your ledger and journal, VAT figures, your clients' and suppliers' details (names, addresses, IBANs), payroll, and, if you connect a bank via EBICS, payment and statement data.

This data is encrypted on your device with a key derived from your password (zero-knowledge). It is stored on our Swiss servers only in encrypted form, so neither helfin nor our hosting provider can read it. We use it solely to provide the app's features and to sync your data across your own devices. We do not use it to profile you, and never for advertising.

Documents and receipts

Photos and scans of documents and receipts are processed on your device, including text recognition (OCR) — the images do not leave your device to be read. If you attach a document to an entry, it is encrypted and stored like the rest of your data.

Location — only if you turn it on

If you enable the optional work time-clock location, helfin records your position at the moment you clock in or out, or log travel, to confirm you were on the job site. It is off by default, used only while the app is open (never in the background), and you can switch it off at any time in the app or in your device settings. If you use the time-clock as an employee of a company (see below), your clocked hours and — if you enabled it — the location stamp are sent to that employer.

Teams — employees and their employer

A company can let its staff submit expenses and work hours from their own phone, using a code the employer gives them. When a worker submits an item, helfin's server relays it to that one employer's account — for an expense: the receipt, amount, date and category; for hours: the times, the worksite, and any location stamp. The worker's identity is tied to the code the employer created, so submissions always belong to the right person. The employer then imports the item into their (encrypted) books, after which the relayed copy is deleted from our server.

Face ID / biometrics

If you enable Face ID or biometric unlock, it is handled entirely by your device's operating system (Apple / Google). helfin never receives your biometric data — the device only tells the app whether unlocking succeeded.

Technical data

Like any online service, our servers process basic connection data — such as IP addresses and request times — as needed to deliver the service and keep it secure. We keep server logs for a limited period and use them only for operating, debugging and securing helfin.

4. The website

On this website we collect personal data when you contact us — for example through the contact form or by email — namely the details you choose to give us (such as your name and email), used only to reply to you and, if you ask, to send occasional helfin updates. With your consent we also collect optional website-analytics data. We do not buy data about you or build profiles of you. When you create an account or subscribe to helfin, the app collects your account data under the app's own privacy terms.

The interactive QR-bill and ledger demo on this site runs entirely in your browser; the sample figures you adjust are not sent to us or stored anywhere.

Website analytics — only if you accept. If (and only if) you accept analytics in the cookie banner, this website sends usage events to our first-party analytics system on our Swiss-hosted infrastructure. These events can include pages viewed, links clicked, an anonymous session identifier, referral or campaign source, device type, and an approximate location derived from the connection IP. We retain them for no more than 90 days and use them only to understand and operate the website. The site may also load Google Analytics (Google LLC, United States), which sets cookies and can transfer similar website-usage data to the United States under your consent. If you decline or ignore the banner, neither optional analytics service receives usage events; strictly necessary server security logs described in §3 remain. The helfin app contains no analytics of this kind. We do not use advertising or cross-site tracking cookies.

5. Where your data is processed

We use Infomaniak Network SA (Geneva, Switzerland) as our processor for hosting and storage of the app's data, the website, and our contact emails. Infomaniak hosts its infrastructure in Switzerland and acts under our instructions. Your helfin data therefore stays in Switzerland and is not handed to any other company. The only exception is the optional website Google Analytics described in §4, which — if you accept it — transfers some website-usage data to Google in the United States.

6. Legal basis and purpose

We process personal data under the Swiss Federal Act on Data Protection (FADP / nLPD) and, for users in the EU/EEA, the GDPR. Our legal bases are:

Purposes are limited to running helfin, supporting you, and keeping the service secure — never advertising or profiling.

7. How long we keep it

We keep your account and its encrypted data for as long as your account exists; you can delete your account and its data from the app at any time. Relayed employee expenses and hours are removed from our server once the employer imports them. Data you send us through the contact form or by email is kept only as long as needed to handle your request, or until you ask us to delete it. Backups and technical logs are kept for a limited period and then deleted.

8. Your rights

Under the FADP (and the GDPR for EU/EEA users) you have the right to:

To exercise any of these, contact us at privacy@helfin.ch. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC / PFPDT), www.edoeb.admin.ch; EU/EEA users may also complain to their local data-protection authority.

9. Security

Your accounting data is end-to-end encrypted on your device before it reaches us, hosted in Switzerland, and backed up in encrypted form. We protect our systems with access controls and offer optional two-factor authentication and Face ID / biometric unlock. No system can be guaranteed perfectly secure, and we ask you to keep this in mind — in particular, keep your password safe, as it is the key to your encrypted data.

10. Children

helfin is a professional accounting and business tool intended for use by businesses and adults. It is not directed to children, and we do not knowingly collect data from children.

11. Changes to this policy

We may update this policy as helfin develops. The current version is always the one published on this page, with the date shown at the top; where changes are significant, we will take reasonable steps to let you know.