RenderHelm.

Legal

Privacy Policy

Version 2026-07-20

RenderHelm is a developer API. We collect the minimum needed to run it, we don't sell your data, and we don't use it for advertising. This policy explains what we process, why, how long we keep it, and your choices.

Part of Keelhelm. RenderHelm is operated by Keelhelm. This notice adds the RenderHelm-specific detail on top of the company-wide Keelhelm Privacy Policy, which sets our baseline practices and your rights and applies to RenderHelm. Read both together; where they differ for RenderHelm, this notice controls. You can browse every company policy in the Keelhelm policy library.

What we process

  • Account email — to verify your account, issue and deliver your key, sign you in by magic link, and reach you about your account or the Service.
  • Render inputs — the URLs, HTML, template parameters, and options you submit. For a URL, our servers fetch and render that page; for HTML, we render what you send. We don't use your inputs to train models.
  • Rendered output — the screenshot, PDF, or image produced. On paid plans, output is stored in your private render cache so an identical repeat is fast and free; on the free plan, output is not cached.
  • Usage records — counts of your renders, timestamps, render type, and browser time, so we can meter your plan and keep the Service reliable.
  • Request metadata — your IP address and basic request details, kept briefly for rate-limiting and abuse prevention.
  • Analytics — aggregate, privacy-preserving usage metrics about the site and API; we don't build advertising profiles. Our public marketing site also uses Google Analytics (cookies subject to your choices) — see the Keelhelm Cookie Policy.
  • Consent record — the version of the Terms and this policy you agreed to, and when.

Why we process it

We process account and render data to perform our contract with you (to provide the Service), and request metadata and analytics under our legitimate interests in security, abuse prevention, and improving the Service. Where required, marketing email relies on your consent.

How long we keep it

We keep personal data only as long as needed to provide the Service to you, meet our legal, tax, and accounting obligations, resolve disputes, and detect and prevent fraud and abuse. Retention isn't a single fixed period — it depends on the category of data and the purpose it serves:

  • Render inputs & the browser rendering — processed to fulfill your request; we don't keep a separate copy beyond what's needed to complete it and, where applicable, populate your cache.
  • Cached output — free plan: none (every render is fresh). Paid plans: governed by your plan's cache size and freshness rules, described on pricing — you can pin an item to keep it, or delete it, at any time; add-ons can change how a cache behaves.
  • Render logs — an operational log used for metering, reliability, and abuse investigation; kept only as long as it serves those purposes, then deleted on a rolling basis.
  • Usage records — kept while your account is active and for as long afterward as needed for billing, accounting, and legal recordkeeping.
  • Request metadata — kept only as long as needed for rate-limiting and abuse prevention, then discarded.
  • Account email & consent record — kept until you delete your account (and, where the law requires, briefly afterward to meet a legal obligation or resolve a dispute).

When data is no longer needed for these purposes, we delete or anonymize it. You can ask us to delete your account and associated data at any time — see "Your rights" below.

Sub-processors

We rely on a small number of infrastructure providers to run the Service — for hosting and compute, object storage, email delivery, and (for paid plans) payment processing. They process data only to provide those services to us and under appropriate confidentiality and data-protection terms.

What we don't do

We don't sell or rent your data. We don't use it for advertising or profiling. We don't add you to a newsletter unless you explicitly opt in at signup, and you can leave anytime.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to access, correct, delete, export (port), or restrict processing of your personal data, to object to certain processing, and to withdraw consent. California residents may request the categories and specifics of data we hold and ask us not to sell it — we don't sell personal information. These are the same rights described in the Keelhelm Privacy Policy (Your rights), which explains the response times and how to complain to a data-protection authority. To exercise any right, email hello (at) keelhelm (dot) com or use the Keelhelm privacy request form; we'll verify and respond within the time the law allows. You won't be discriminated against for exercising a right.

International transfers

Your data may be processed in the United States and other countries where our providers operate.

Security & children

We protect data with reasonable technical and organizational measures; secret keys are stored only as hashes. The Service isn't directed to children under 16, and we don't knowingly collect their data.

Changes

If we make a material change, we'll update the version and date above and, where appropriate, notify you by email or ask you to re-consent.

Keelhelm company privacy policy

RenderHelm is operated by Keelhelm. This notice covers the app specifically; the company-wide Keelhelm Privacy Policy also applies and describes our baseline practices and your rights. You can exercise any privacy right for a Keelhelm service — including access or deletion — through the Keelhelm privacy request form.

Contact

Questions or requests: hello (at) keelhelm (dot) com.