Effective Date: 2026-06-23 Last Updated: 2026-08-25
This Privacy Policy explains how HelixWrks LLC ("HelixWrks," "we," "us"), an Arizona limited liability company located at 7090 N Oracle Rd, Ste 178, PMB 2035, Tucson, AZ 85704, collects, uses, and shares information in connection with the BenchForge application and related services (the "Service"). BenchForge is a product of HelixWrks LLC.
By using the Service, you agree to this Policy. If you use the Service on behalf of an organization, this Policy applies to that organization's use, alongside any executed Data Processing Addendum ("DPA"), which controls in the event of a conflict for business-customer data.
BenchForge is an economics and operations planning tool, not a clinical or patient-records system. It is not designed to collect or process Protected Health Information (PHI), patient identifiers, specimen-level data, or individual test results, and you agree not to submit such data (see the Terms of Use). The information in the Service is intended to be aggregate laboratory configuration and self-entered operational figures.
a) Account information. When you register, we (through our authentication provider) collect your email address, authentication credentials, and basic profile and membership/role information.
One account may belong to several workspaces — for example a consultant invited into more than one client lab. Where it does, the administrators of each workspace can see your email address and your role in theirs, because they granted that access and must be able to review and withdraw it. They cannot see which other workspaces you belong to, and no workspace's data is visible from another.
b) Customer Data you provide. Laboratory configuration, workflows, assays, cost and capacity assumptions, default-value overrides, reimbursement and payer-mix inputs, snapshots/scenarios, and actuals you enter or import (for example, via CSV import or, where available, an API). If you connect the optional read-only LIMS connector, we also hold the endpoint address and read-only credential you supply — stored sealed, readable by no client role — and the workflow structure, volume, and turnaround figures it pulls on a schedule; fields shaped like identifiers are excluded before anything is mapped, and volume records are counted and discarded rather than stored. This data is provided and controlled by you. If you import an 835/ERA remittance file, the file is parsed in your browser and only aggregate per-billing-code economics (amounts, claim counts, and the remitting payer's business name) are stored — the raw file, which can contain patient identifiers, is never uploaded and never reaches our servers.
c) Files you attach. Standard operating procedure (SOP) documents and diagrams you attach are stored in our managed file storage (Supabase, US). When you use the AI SOP-import feature, only the SOP text you paste or upload is sent once to our AI sub-processor (Anthropic) to draft a structured process for your review — not per sync, and it is screened server-side for high-confidence identifiers (e.g., SSN, email, date of birth) before it is sent — you are responsible for de-identifying SOP text. Attached PDF or image files are never sent to the AI sub-processor — only text is. Provide de-identified procedures, not patient data.
d) Usage and analytics. We collect limited usage analytics to understand and improve the Service: product-usage events (for example, which features are used) tied only to a random, pseudonymous session identifier — not to your name or account — stored in our Supabase database. On the public landing and demo pages, before sign-in, the same stream records a fixed short list of funnel events (page viewed, demo opened, signup started/submitted) through a narrow allow-listed endpoint that accepts no free text. Analytics are opt-out, and we honor browser "Do Not Track" (DNT) signals. We do not use this data to build advertising profiles. (Vercel Web Analytics — third-party page-view measurement — is not currently enabled for the Service. If we enable it, we will add it to the sub-processor table in Section 4 first.)
e) Technical/log data. Our infrastructure providers process standard technical data (e.g., IP address, timestamps, request metadata) to operate, secure, and troubleshoot the Service.
f) Cookies/local storage. We use essential cookies and browser local storage to keep you signed in and to store your working data. We do not use third-party advertising cookies.
g) Error and diagnostic reports. When the application fails, we record a diagnostic entry in our own Supabase database — no additional vendor and no new data egress. Each entry holds: a short scope tag naming the code path, the error message truncated to 500 characters, a small set of non-identifying context values (counts, flags, short status codes), the deployment environment, and — stamped server-side from your session, never supplied by the browser — your account and workspace identifier.
This stream is deliberately NOT subject to the analytics opt-out in Section 2(d), and not gated by Do Not Track. We consider that the honest trade and are disclosing it rather than burying it: if a crash only reaches us from users who left telemetry on, the users most affected by a fault become the ones whose faults we never see. It is operational, not analytical — it is not used to measure or profile your usage, is readable only by our operators, and is never shared with an advertising or analytics vendor. Error messages are not expected to carry your data, and we truncate them for that reason, but a thrown error can echo a fragment of a value that was being processed — which is one more reason for the rule that governs every field in the Service: do not enter PHI or patient-identifiable data. Retention is covered in Section 6.
We use information to: (a) provide, maintain, secure, and support the Service; (b) authenticate users and enforce access controls and roles; (c) save and sync your Customer Data; (d) maintain audit and security logs; (e) improve the Service using anonymous/aggregate analytics and truly non-re-identifiable aggregated data; (f) communicate with you about the Service; and (g) comply with law and enforce our Terms.
Limits on how we use your Customer Data. We will not use your identifiable operational, economic, or configuration data to train, tune, or improve any shared, cross-customer, or third-party model, benchmark, or dataset without your opt-in consent. Any aggregated or statistical use of Customer Data is limited to information that is truly non-re-identifiable, and you may opt out of such aggregated use (see the Terms of Use, Section 7). We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
a) Sub-processors / service providers. We share information with vendors who help us run the Service, under contracts requiring appropriate confidentiality and security. Our current core sub-processors are:
| Sub-processor | Role | Data location |
|---|---|---|
| Supabase, Inc. | Authentication, managed Postgres database (per-tenant data), file storage (attached SOPs/diagrams), and pseudonymous product-usage analytics events | United States |
| Vercel, Inc. | Application hosting / content delivery | United States |
| Anthropic PBC | AI parsing of SOP text you provide and de-identified data-import rows, at your request (one-time, not per sync; PDF/image files are never sent) | United States |
| Resend, Inc. | Transactional email — sends workspace invitation emails (the invitee's email address, which may belong to someone who is not yet a user), trial-ending notices, operational alerts, reconciliation-staleness nudges, and forwarded support requests to workspace owners / our operators (recipient email address, workspace name, reconciliation status, and the subject + message content of any support request you submit) | United States |
| Stripe, Inc. | Payment processing and billing-related email, when billing is enabled | United States |
Anthropic does not use data submitted through its API to train its models, and retains it for a limited period for trust-and-safety purposes before deletion, per Anthropic's then-current Commercial Terms of Service.
The authoritative, current list is provided in the Data Processing Addendum (DPA) we enter into with business customers at contracting.
b) Legal and safety. We may disclose information if required by law, legal process, or to protect the rights, safety, and security of HelixWrks, our users, or the public.
c) Business transfers. If HelixWrks is involved in a merger, acquisition, financing, or sale of assets, information may be transferred subject to this Policy.
The Service and its core sub-processors are hosted in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States. Where applicable, transfers of personal data from the EEA/UK/Switzerland are made under appropriate safeguards (e.g., Standard Contractual Clauses) as described in the DPA.
We retain Customer Data for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce agreements. Upon account closure, you may export your data for 30 days, after which we may delete or de-identify it.
Automated retention windows. A nightly automated sweep enforces the following, so these are the windows that actually hold rather than the ones we would like to advertise:
| Record | Retained |
|---|---|
| Audit / security log | 180 days, then deleted |
| Product-usage events (Section 2(d)) | 90 days, then deleted |
| Data-import records (consumed and pending) | 90 days, then deleted |
| Error / diagnostic reports (Section 2(g)) | 90 days, then deleted — the same window as product analytics |
| Platform enforcement decisions (see below) | Kept indefinitely — deliberately outside the sweep |
Platform enforcement decisions are kept indefinitely, and we would rather say so than let you find out. If we grant or withdraw a consultant designation, or suspend an account, we keep a record of that decision: the email address it concerned, what was decided, when, by whom, and the reason given. It is not deleted by the nightly sweep.
The reason is that these are the records you need precisely when a decision is challenged, and a retention window would mean the evidence expiring before the dispute does. It is a small, operational log — it holds no Customer Data and no workspace contents — and it is readable only by our operators. If you believe a record about you is inaccurate, contact us (Section 8); where erasure rights apply we will assess the request against our need to keep the record for establishing or defending legal claims.
Audit entries cannot be altered or deleted by any account before they age out — the update and delete privileges are revoked from every API role — but they are not permanent; the sweep is the only thing that removes them. If your policy requires a longer audit window, tell us before you rely on one.
We implement administrative, technical, and physical safeguards appropriate to the data, including encryption in transit (TLS) and at rest, tenant isolation, role-based access controls enforced server-side, and an append-only audit log of access and security-relevant events. See the Security White Paper for details. If we become aware of a breach affecting your personal data, we will notify affected customers without undue delay as required by applicable law. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to opt out of certain processing. Account holders can update or delete much of their data within the Service. You can opt out of analytics in Settings, and we honor DNT. To exercise other rights, contact tyler@helixwrks.com; we will respond as required by applicable law. For business-customer Customer Data, requests are handled per the DPA, typically through the customer's administrator.
U.S. state privacy laws (e.g., California/CCPA-CPRA). We do not sell or "share" personal information for cross-context behavioral advertising. California residents may request access and deletion and will not be discriminated against for exercising their rights.
EEA/UK (GDPR). Where GDPR applies and HelixWrks is a controller, our legal bases are performance of a contract, our legitimate interests in operating and improving the Service, your consent (e.g., optional analytics), and compliance with legal obligations. You also have the right to lodge a complaint with your local data-protection supervisory authority. Where HelixWrks acts as a processor for business-customer data, processing is governed by the DPA.
The Service is for business use and is not directed to children under 16, and we do not knowingly collect their personal information.
We may update this Policy. Material changes will be posted in the application with a new "Last Updated" date and, where required, notified to you. Continued use after the effective date constitutes acceptance.
HelixWrks LLC — Privacy 7090 N Oracle Rd, Ste 178, PMB 2035, Tucson, AZ 85704 tyler@helixwrks.com
© 2026 HelixWrks LLC. BenchForge is a product of HelixWrks LLC. All rights reserved.