Privacy Policy
Effective date: August 20, 2026 · Last updated: August 20, 2026
0. The short version
| Question | Answer |
|---|---|
| Do you host my files? | No. Your Vault lives on your computer, or in a cloud folder that belongs to you (Dropbox, OneDrive, Google Drive). We have no copy and no access. |
| Do you read my notes, documents or conversations? | Not in ordinary use. They never reach our servers on their own. There is one exception, and you control it: if you ask us for help with a problem and choose to send a diagnostic log, that log contains your conversation with HELIOS. You package it yourself and read it before it goes. See Section 4.4. |
| Do you train AI on my data? | No. We do not train models, and we do not license your content to anyone who does. |
| What does the app send you? | Once a day it checks that your licence is valid. That check carries your licence, a hashed device fingerprint, the version number you are running and the time of the check. It also looks for a new version, which tells our update service which version you are running and, as any download does, discloses your IP address to the service delivering the file. Crash reports are off unless you turn them on, and you see the contents before they send. Diagnostic logs are never sent automatically; you package one yourself and read it first. |
| Does anything else leave my machine? | Yes, and you should understand exactly what. When you speak, your audio goes to your own Deepgram account to be transcribed. When HELIOS answers out loud, the text of the answer goes to your own ElevenLabs account. When the crew thinks, your request and whatever Vault material is relevant to it go to your own Claude or ChatGPT account. Those are your accounts, under your contracts with those companies, and we are not in the middle of them. |
| What do you actually hold about me? | Your name and email, your country and line of work if you gave them on the waitlist, your licence and subscription status, your payment records held by our payment processor, and any messages or logs you send us. |
| Do you track me around the web? | No. No advertising cookies, no ad networks, no analytics SDK in the application, and no sale of personal information. |
Section 3 explains the architecture precisely, because that architecture, not this document, is what actually protects you.
1. Who we are and how to reach us
We are the controller (the "business", in the language of United States state privacy law) of the personal information described in Section 4. Depending on where you live, that responsibility arises under the California Consumer Privacy Act as amended (CCPA/CPRA) and the other United States state privacy statutes that apply to us, and under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) together with provincial legislation including Quebec's Law 25 where our customers are located in those provinces.
- All enquiries, including privacy requests: support@heliosvault.io
- Person responsible for privacy: Phillip Cloutier, Founder and CEO, reachable at support@heliosvault.io
2. Scope, and where the Service is offered
This policy covers:
- the Site: heliosvault.io, including the waitlist form and the "Ask HELIOS" website concierge;
- the Software: the HELIOS Vault application you install on your computer, including the crew of AI agents, the HUD, and the setup wizard;
- the Account and Licence Service: sign-in, subscription, and licence validation;
- our correspondence with you by email or support channels.
Where we offer the Service. HELIOS Vault is currently offered to customers in the United States and Canada only. We do not offer or sell it in the European Economic Area, the United Kingdom or Switzerland, and we take technical measures to decline signups and payments from those regions. See Section 11.4 if you are in one of them.
This policy does not cover, and we are not responsible for, the privacy practices of the Connected Services you choose to use with HELIOS (Section 6), or of any cloud storage provider on which you choose to keep your Vault. Those relationships are directly between you and them.
3. How HELIOS is built, and why that matters more than a promise
Most software sends your data to the company's servers and then promises to behave. HELIOS is built the other way around: we designed the product so that the sensitive material never reaches us in the first place. The only material that does reach us is what you deliberately hand over, and this section lists all of it.
Runs on your device, and stays there:
- your Vault: notes, documents, decisions, imported files, calendar and task data, and everything the crew writes into it. It is ordinary files in ordinary folders that you can open, move, back up or delete without us;
- your voiceprint, if you turn that feature on (Section 5);
- your configuration, including which specialists you have hired, your widget layout, and your preferences;
- your API keys and tokens for Connected Services, stored in your operating system's credential store or a local file on your machine;
- local logs written by the Software for troubleshooting, which stay on your machine unless you choose to send one to us;
- temporary audio files created during local transcription, which are deleted immediately after use.
Sent from your device to the Connected Services you have chosen, under your own accounts:
- speech: while HELIOS is awake and listening for your turn, microphone audio is streamed to Deepgram for transcription using your Deepgram credentials. A short rolling buffer of audio is held in your computer's memory so the start of your sentence is not clipped. If Deepgram is unavailable or not configured, transcription falls back to a speech model that runs entirely on your computer;
- your requests and relevant Vault material: sent to the AI engine you connected, which is either Anthropic's Claude (through Claude Code, using your Claude subscription) or OpenAI's ChatGPT Codex (using your ChatGPT subscription). If you have connected both, HELIOS can fall back to the other engine when one reaches its limit;
- the text of spoken replies: sent to ElevenLabs for text to speech using your ElevenLabs credentials;
- anything you explicitly connect: if you ask the crew to wire HELIOS to a calendar, mailbox, task manager, market data feed or similar service, the relevant requests go to that service under the credentials you supplied.
Sent to us, and nothing else:
- the daily licence check described in Section 4.2;
- an update check, when the Software looks for a new version, which discloses the version you are running and, to our provider, your IP address transiently;
- a crash report, only if you have switched crash reporting on, and only after you have seen what it contains;
- a diagnostic log, only when you decide to run the command that packages one and send it to us. A log contains your conversation with HELIOS and may include file names, paths and the contents of notes he read aloud, which is exactly why you review it before it goes (Section 4.4);
- whatever you write to us directly.
There is no analytics SDK in the application, no third-party tracking library, no background reporting of what you do with the Software, and no feature-usage telemetry of any kind.
Read this carefully. "Your files stay on your machine. Never on our servers." is a statement about your files, and it is true. It is not a claim that no data ever leaves your computer. Using an AI assistant means the material you ask about is sent to the AI provider you chose, under your own account with that provider. HELIOS makes that relationship direct and visible instead of hiding it behind our servers.
4. What we collect, why, and on what legal basis
4.1 Waitlist
When you join the waitlist we collect your name, email address, country, operating system and line of work, together with the date of submission. We use this to manage beta invitations and to understand which platforms and use cases to build for. The form includes a hidden anti-spam field; if it is completed, the submission is discarded and nothing is stored. Legal basis: consent, and our legitimate interest in operating a waitlist.
4.2 Account, licence, and the daily check
When you create an account we collect your email address, authentication identifiers, plan and subscription status, and seat assignments (a Business plan owner may invite one additional person by email).
Once a day, the Software contacts our licence service to confirm your subscription is current. That request carries:
- your signed licence token;
- a hashed device fingerprint, a one-way value that lets us count device activations against your seat limit and nothing more;
- the version number of the Software you are running;
- the date and time of the check.
We keep a count of how many active installations are running each version, so that we know a release is working and know when it is safe to retire an old one. This is part of validating your licence and keeping the Software functional; it is not optional analytics, there is no separate analytics service involved, and it carries nothing about what you do with the Software.
We do not store IP addresses in licence records. Our hosting provider processes them transiently to deliver the request and to prevent abuse. Legal basis: performance of our contract with you, and our legitimate interest in preventing licence abuse.
4.3 Crash reports, off unless you turn them on
Crash reporting is off by default. If you switch it on, and the Software crashes, it prepares a report and shows you its contents before anything is sent. You decide whether to send it.
A crash report contains the technical circumstances of the failure: the error, where in the Software it happened, the version, and your operating system. It does not contain Vault content, file names, file paths, transcript text or prompt text. You are the final check, not our scrubbing alone. You can switch crash reporting off again at any time. Legal basis: consent.
4.4 Diagnostic logs you choose to send
HELIOS collects no diagnostic data automatically. If you choose to send us a log, you run a command that packages the log files yourself. That log contains your conversation with HELIOS, what you said and what he replied, and may include file names, paths, and the contents of any notes he read aloud. It does not contain your API keys. Review it before sending.
Once we receive a log it is personal information that we hold, and it is covered by the retention period in Section 9. Please do not send us a log containing another person's sensitive information. Ask us at support@heliosvault.io and we will delete any log you have sent. Legal basis: consent.
4.5 Payment
Payments are processed by Stripe. We do not receive or store your full card number. We receive and retain the transaction record, the last four digits and card brand, billing country, and invoice and tax data that we are required to keep. Legal basis: contract, and compliance with legal obligations including tax and accounting law.
4.6 Support and correspondence
If you contact us, we hold that correspondence and its contents. Please do not include material in a support message that you do not want us to have. Legal basis: legitimate interest in supporting our customers.
4.7 Site usage
The Site uses Cloudflare Web Analytics, which is privacy-preserving, does not use cookies for tracking, and does not fingerprint visitors. Our hosting provider processes standard server log data, including IP address, user agent and timestamps, for delivery and security. The "Ask HELIOS" website concierge processes the messages you type into it in order to answer them, and applies a per-IP rate limit to prevent abuse. Do not type confidential information into the website concierge. Legal basis: legitimate interest in a secure and functioning website.
4.8 What the Software does not send us
The Software does not send us, and we do not otherwise collect, your Vault content, your files, your microphone audio, your transcripts, your prompts, your AI conversations, your voiceprint, your Connected Service credentials, your contacts, your location, your browsing history, or any record of which features you use.
The one exception is material you deliberately send us yourself. A diagnostic log (Section 4.4) contains your conversation with HELIOS and may contain file names, paths and the contents of notes read aloud. A crash report (Section 4.3) contains technical failure data. Neither leaves your computer unless you choose to send it, and in both cases you see what it contains first. Anything you type into the website concierge (Section 4.7) or write to us in a support message also reaches us, because you sent it.
4.9 Sensitive information
We do not ask for and do not want special categories of personal information (health, racial or ethnic origin, political or religious belief, sexual orientation, biometric identifiers, government identifiers, or financial account credentials). Your voiceprint is biometric information; it is created and kept only on your device, only if you enable it, and we never receive it. See Section 5.
5. Voice, the microphone, and your voiceprint
Because HELIOS listens, this section deserves to be read in full.
When the microphone is used. HELIOS captures audio while it is awake and taking your turn. It is not a background recorder, and it does not upload your day. You can mute the microphone from the HUD at any time, and you can quit the Software.
Where speech is transcribed. Audio is streamed to your own Deepgram account for transcription. When Deepgram is unavailable or not configured, the Software falls back to a speech recognition model that runs locally on your computer. Some checks always run locally, including detecting when the wake name is spoken.
Your voiceprint, which is off until you turn it on. So that HELIOS can respond to you and not to a voice on a television, the Software can build a voiceprint, a numerical representation of the characteristics of your voice. This feature is off by default. If you enable it, the voiceprint is learned from your own accepted turns, is stored in a single file inside the Software's folder on your computer, and is never transmitted to us or to anyone else. It cannot be played back as audio. You can erase it at any time by asking HELIOS to clear your voiceprint, by switching the feature off, or by deleting that file. Switching it off stops the Software creating a new one.
Other people's voices. A microphone in a room hears everyone in it. You are responsible for the people around you. Some places, including the two-party consent states such as California, Florida, Illinois, Pennsylvania and Washington, and most of Canada, require the consent of everyone recorded or identified, and some states regulate voice biometrics specifically, including Illinois, Texas and Washington. Do not run HELIOS in a meeting, a household or a workplace where others have not agreed, and do not enable the voiceprint feature where it could capture someone who has not consented. If someone else's voice is captured and processed on your computer, that processing is yours, not ours.
Children. HELIOS is not for people under 18 (Section 12), and the voiceprint feature must not be used to identify a child.
6. Connected Services, and what we are not responsible for
HELIOS is designed as a bring-your-own-account product. The services below receive data directly from your computer under credentials you supply. They are not our subprocessors; they are your providers, they act under their own terms and privacy policies, and their handling of your data is between you and them. Their retention and training practices depend on the plan and account type you hold with them, and they can change without notice to us.
| Service | What it receives | Whose account |
|---|---|---|
| Anthropic (Claude, via Claude Code) | Your requests and the Vault material relevant to them | Yours |
| OpenAI (ChatGPT Codex) | Same, when selected or used as fallback | Yours |
| Deepgram | Microphone audio during your turn | Yours |
| ElevenLabs | The text of spoken replies | Yours |
| Dropbox, OneDrive, Google Drive or similar | Your Vault, if you choose to keep it there | Yours |
| Any service you ask the crew to connect | Whatever that integration requires | Yours |
We encourage you to read those providers' policies, and, where they offer it, to turn off any option that allows your content to be used for model training.
7. Who we share your information with
We do not sell your personal information, we do not share it for behavioural advertising, and we do not disclose it for anyone else's marketing. We use the following service providers (processors), each bound to handle information only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, DNS, security, privacy-preserving analytics, licence service and database, email routing | United States and global edge |
| Clerk, Inc. | Account authentication. We never receive or store your password | United States |
| Stripe, Inc. | Payments, subscriptions, invoicing, tax | United States |
| Google LLC | The waitlist spreadsheet and its receiving script, and our business email | United States |
We may also disclose information to professional advisers under a duty of confidentiality, to authorities where we are legally required to do so or where it is necessary to protect our rights or someone's safety, and to a successor in the context of a merger, acquisition or sale of assets, in which case we will notify you and this policy will continue to apply to the transferred information.
We will resist overbroad demands where we lawfully can. Note the practical point: we cannot hand over what we do not hold. Your Vault content is not ours to produce.
8. Where your information is processed
We are a United States company, and the personal information described in Section 4 is processed in the United States and, through our providers, at their global infrastructure.
If you are in Canada, your personal information is processed in the United States and is therefore subject to lawful access by United States authorities. Canadian privacy law permits this provided we remain accountable for it, which we are, and provided we tell you, which this section does.
9. How long we keep things
| What | How long | When the clock starts |
|---|---|---|
| Waitlist email address | 24 months, or immediately when you unsubscribe, whichever comes first | When you joined |
| Support conversations | 24 months | Your last message in the conversation |
| Diagnostic logs you send us | 90 days, or as soon as the issue is resolved, whichever comes first | When we receive it |
| Crash reports you send us | 90 days, or as soon as the issue is resolved, whichever comes first | When we receive it |
| Your account record | 12 months after you close your account | The day you close it |
| Registered devices | 90 days after that device last used HELIOS | Last use, not first |
| Payment and invoice records | 7 years | The transaction date |
Vault content has no retention period here, because we never hold it. Deleting your account does not delete your Vault, and closing your account never touches it: it is yours, it is on your storage, and it remains readable in plain files without our software.
10. Security, honestly stated
We use access controls, encryption in transit, encryption at rest with our providers, least-privilege administration and hardened defaults. The Software stores credentials in your operating system's credential store where available, restricts the local bridge it uses to talk to its own interface, and inspects components before they are added to your system.
No system is perfectly secure, and we do not promise that ours is. The largest share of your security here is in your own hands: your device, your disk encryption, your operating system account, your cloud storage provider, and the credentials you give to Connected Services. Where the law requires it, we will notify you and the relevant regulator of a breach affecting your personal information.
11. Your rights
Depending on where you live, you have some or all of the following rights: to know what we hold and to obtain a copy; to correct inaccurate information; to delete it; to withdraw consent; to object to or restrict processing based on legitimate interests; to portability; to not be subject to decisions based solely on automated processing (we make none); and to complain to a regulator.
To exercise a right, write to support@heliosvault.io. We will verify your identity proportionately, respond within 30 days (or within the shorter period your law requires), and will not charge you unless a request is manifestly unfounded or excessive. You may use an authorised agent where the law allows.
11.1 California. We do not sell or share personal information as those terms are defined by the CCPA as amended, we have not done so in the preceding twelve months, and we do not use or disclose sensitive personal information beyond permitted business purposes. You have the rights to know, delete, correct, to limit the use of sensitive personal information, and to be free from discrimination for exercising them. You may appeal a refusal. Complaints go to the California Privacy Protection Agency or the California Attorney General.
11.2 Other United States states. Where a comprehensive state privacy law applies to us, including in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and states whose statutes take effect after the date of this policy, equivalent rights apply, including the right to appeal a refused request and the right to opt out of targeted advertising, sale and profiling, none of which we conduct. Complaints go to your state Attorney General.
11.3 Canada. You may access and correct your personal information and withdraw consent, subject to legal and contractual limits. Complaints go to the Office of the Privacy Commissioner of Canada, or to your provincial regulator. If you are in Quebec, Law 25 also gives you the right to de-indexation in the circumstances the law provides, the right to be informed of the use of technology to identify, locate or profile you (we use none), and the right to complain to the Commission d'accès à l'information du Québec. Our person responsible for privacy is named in Section 1.
11.4 If you are in the EEA, the United Kingdom or Switzerland. We do not currently offer HELIOS Vault in your region, and we decline signups and payments from it. If you joined our waitlist before this policy took effect, we hold only your name, email, country, operating system and line of work. Write to support@heliosvault.io and we will delete that entry, and we will contact you if and when we open in your region. We are not currently established in the EEA or the UK and have not appointed a representative there, because we do not offer goods or services to people in those regions.
12. Age
HELIOS Vault is for adults. You must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, write to support@heliosvault.io and we will delete it.
13. Shared Vaults, and other people's information
If you place a Vault in a shared cloud folder so that a partner or a team can work from the same knowledge, you decide what goes into it and who can reach it. As between you and us, you are responsible for that content and for the privacy rights of the people described in it, including your obligations as an employer or a business. We are not a party to that arrangement, we have no visibility into it, and we cannot retrieve, restrict or delete anything within it on anyone's behalf.
If you use HELIOS for professional work involving other people's personal information, such as bookkeeping, client files or patient information, satisfy yourself first that doing so is lawful for you, and note that we are not acting as your processor, your service provider, or a HIPAA business associate, and that we offer no data processing agreement covering Vault content, because the Software does not send it to us. The exception is a diagnostic log you choose to send, which is covered by Sections 4.4 and 9.
14. Cookies
The Site uses no advertising or cross-site tracking cookies. It uses strictly necessary storage for basic functionality, and, for the website concierge, a short-lived rate-limiting record keyed to your IP address.
15. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means. The Software's AI output is a tool that assists you, and you remain the decision-maker. See the Disclaimer.
16. Changes to this policy
We will post any new version here with a new effective date. For material changes we will give notice by email or in the Software before the change takes effect, and, where the change requires it, we will ask for your consent again. If we ever begin collecting information about how you use the Software, we will tell you plainly and ask first.