Privacy Policy
Last updated: 13 August 2026
HelperMate is a cooking collaboration app used by a household: an employer plans dishes, and a domestic helper cooks them, each reading in their own language. This policy explains exactly what we store, why, and how you get rid of it.
We have tried to write this so that it can actually be read. Where something is a limitation rather than a feature, we say so.
1. Who is responsible
| Service | HelperMate (helper.luy.li) |
| Operator | Senob |
| Data Protection Officer | bones7456+helpermate@gmail.com |
| General enquiries | bones7456+helpermate@gmail.com |
Singapore's Personal Data Protection Act (PDPA) requires us to name a Data Protection Officer. The contact above reaches a person, not a ticket queue.
2. There are two kinds of account
This matters, because they hold different data.
Employer — signs up with an email address and password. Creates a household, adds recipes, assigns dishes.
Helper — does not need an email address or a phone number. She joins with an invite code from her employer and picks a 6-digit PIN. We generate a login name for her. We do not ask for, and do not store, her passport number, work permit number, employer contract, salary, or any other employment record.
3. What we collect
From everyone
- Display name. Whatever you type. It does not have to be your legal name.
- Language preference. Used to decide which translation to show you and which language to write your notifications in.
- Sign-in credentials. Employer: email address and a password, stored only as a PBKDF2-SHA256 hash. Helper: a generated login name and a 6-digit PIN, also stored only as a hash. We cannot read either one back.
- Session tokens, so you stay signed in.
- Failed sign-in attempts, to lock an account after repeated wrong guesses. Deleted once the lock expires.
Created while using the app
- Recipes you write, import, or adapt, including their translations.
- Cooking tasks: which dish, which day, which meal, how many servings, and any note the employer adds.
- Photos of finished dishes, uploaded by the helper when she chooses to submit one.
- Messages in the one-to-one chat between employer and helper, including photos sent in chat, and cached translations of those messages.
- Notification settings, including your quiet hours.
- Push tokens for the device you enabled notifications on.
Collected automatically
Very little, and deliberately so:
- The timestamp of actions, so the app can show a task history.
- Your household's time zone, so reminders arrive at a sensible hour.
- Standard web server logs at our infrastructure provider (IP address, browser user agent), retained by that provider for a short period for security and abuse prevention.
4. What we deliberately do not collect
This section is not decoration. Singapore has a strong public interest in the treatment of migrant domestic workers, and we have designed against a specific failure mode: this app becoming a surveillance tool.
- No location. We never ask for, request permission for, or store location of any kind.
- No time tracking. No clock-in, no clock-out, no working-hours totals.
- No background or scheduled photography. The camera opens only when the helper taps to submit a photo herself. Never at any other time.
- No performance scores. Overdue tasks are shown to the employer so they can plan meals. They do not produce a rating, a score, a penalty, or a permanent record against anyone.
- No export of chat as "evidence." The employer cannot export the helper's messages. Neither party's data export contains the other party's messages.
- No advertising, no analytics SDKs, no cross-app or cross-site tracking, no device fingerprinting, no IDFA. The iOS app's privacy manifest declares tracking as false and lists no tracking domains.
- No contacts, no calendar, no microphone, no health data.
5. Why we use your data
We use it to run the features you asked for, and for nothing else:
- To sign you in and keep your household separate from every other household.
- To show a recipe in the language you chose.
- To deliver notifications you turned on, subject to your quiet hours.
- To keep the service secure — rate limiting, lockout after repeated failed sign-ins.
We do not use your content to train AI models. See the next section for exactly what is sent where.
6. Who else processes your data
We keep this list short on purpose. These are all the third parties involved.
| Who | What reaches them | Why |
|---|---|---|
| Cloudflare, Inc. | Everything you store: account records, recipes, tasks, messages, photos | Hosting, database, file storage, content delivery |
| Our LLM provider | The text to be translated or structured: recipe text, imported recipe sources, and the body of a message when someone taps "translate". Screenshots when you use screenshot import. | Machine translation and turning pasted text or screenshots into a structured recipe |
| Apple (APNs) | A push token, plus the notification's title and body | Delivering notifications to the iPhone app |
| Google, Mozilla, Apple (Web Push) | An encrypted notification payload | Delivering notifications to the helper's web app. The payload is encrypted so the delivery service cannot read the contents |
Notes that matter:
- The AI provider sees the text you asked to be translated or imported. It does not receive your email address, your name, or your account identifiers. Dish photos and submitted photos are never sent to it. Chat messages are sent only when someone explicitly taps "translate" on that message.
- Apple's push service can read the notification title and body, because APNs payloads are not end-to-end encrypted. Notification text is short and contains a dish name, a sender's display name, or a message preview. If that is a concern, turn notifications off in the app.
- We do not sell personal data. We do not share it for advertising. There is no advertising in this app.
7. Data leaving Singapore
Our infrastructure runs on Cloudflare's global network, and AI processing happens on servers outside Singapore. Under PDPA this is a transfer of personal data out of Singapore, and we disclose it here. We rely on the contractual terms offered by these providers, which are intended to give a standard of protection comparable to PDPA.
If you are not comfortable with this, the app is not usable without it, and you should not create an account.
8. How long we keep things
| Data | Kept |
|---|---|
| Your account and its content | As long as the account exists |
| Everything, after you delete your account | Deleted immediately — see section 9 |
| Notification de-duplication records | 30 days, then automatically purged |
| Failed sign-in records | Until the lock expires |
| Administrative audit log | Retained for security review. It records that an action happened, not the content |
A limitation we should state plainly. When an employer unlinks a helper from a household, the household keeps its own records — the tasks that were assigned and the recipes it owns. The photos the helper submitted stay attached to those tasks until she deletes her account. If she wants them gone sooner, she can delete her account, which removes them (section 9). We do not currently expire that data automatically on unlinking, and we would rather say so than imply a retention period we do not enforce.
9. Your rights, and how to use them
Under PDPA you may access, correct, and withdraw consent for your personal data. All of it is available inside the app, without emailing anyone.
Get a copy of your data
iPhone app: Household → Account and data → Export my data. Helper web app: Home → Account and data → Export my data.
You get a JSON file containing your profile, your household memberships, your notification settings, the messages you sent, your submissions, and your tasks. It deliberately does not contain the other person's messages — that is their data, not yours.
Correct your data
Your display name and language are editable in the app. Ask us at the address above for anything else.
Delete your account
iPhone app: Household → Account and data → Delete account. Helper web app: Home → Account and data → Delete account.
You will be asked to type DELETE to confirm. This is deliberate: it is not reversible.
If you are a helper, deleting removes the photos you submitted, the messages you sent (and their cached translations), your notification settings and push tokens, and unlinks you from your household. Your employer's household, recipes, and task records remain theirs. Any conversation you were part of becomes read-only for them, with your messages gone.
A consequence you should know about before you start. Your account belongs to the household that invited you. It cannot be carried to a new employer, and if your employer removes you or deletes their own account, your account ends with it. Working for a new family means being invited again and setting up a fresh account there. If you want to keep anything, export it (above) before that happens. If you have been removed but not deleted, you can still sign in for one purpose: to export or delete your own data.
If you are an employer, and you are the only employer in your household, deleting also deletes the household itself: its tasks, its recipes, its chat history, its imports, and its uploaded images. The helper accounts in it are closed as well, because a helper account belongs to the household that invited it and cannot be moved elsewhere — once the household is gone, the account can never be used again. If another employer shares the household, only your membership is removed, and the household and its helpers continue.
In both cases, your name, email or login name, and password or PIN hash are erased, and the account can never be signed in to again. Your email address is released, so you could sign up again later as a completely new account with no connection to the old one.
One technical detail, stated honestly: we do not delete the database row that other records point to. We erase every piece of personal data in it and leave an anonymised placeholder, so that, for example, a task history does not break. That placeholder contains no name, no contact detail, and no credential.
10. Security
- All traffic is over HTTPS.
- Passwords and PINs are stored only as PBKDF2-SHA256 hashes with per-user salts, never in a form we can reverse.
- Photos are served through short-lived signed URLs, not public links.
- Each household's data is isolated in application code, and a helper cannot read another helper's tasks or her employer's conversation with a different helper.
- Web push payloads are encrypted so the delivery service cannot read them.
No system is perfect. If you find a security problem, please write to the address in section 1 and we will treat it seriously.
11. Children
HelperMate is for adults running a household. It is not directed at children and we do not knowingly collect data from anyone under 13.
12. Changes
If we change this policy in a way that affects what we collect or who receives it, we will update the date at the top and, for material changes, notify you in the app before the change takes effect.
13. Contact
Questions, requests, or complaints: bones7456+helpermate@gmail.com Data protection matters, including PDPA requests: bones7456+helpermate@gmail.com
If you are in Singapore and you are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC).