Last updated: July 3, 2026
This Privacy Policy describes how Helion Labs ("Helion", "We", "Us", "Our") collects, uses, and discloses information when You use the Service, and explains Your rights over that information.
By using the Service, You agree to the collection and use of information as described in this Privacy Policy.
Who We Are
Helion is currently operated by Lalit Shrotriya, an individual based in Mumbai, Maharashtra, India, as a sole proprietorship (not a separately registered company). For any privacy question or request, contact:
- General contact: hello@helionlabs.dev
- Grievance Officer / Privacy contact: Lalit Shrotriya, lalit.shrotriya@outlook.com
This Grievance Officer contact is published in accordance with India's Information Technology (Intermediary Guidelines) Rules, 2021 and the Digital Personal Data Protection Act, 2023 ("DPDP Act").
Interpretation and Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access the Service.
- Personal Data means any information relating to an identified or identifiable individual.
- Service refers to the Helion website and the hosted Helion Cloud dashboard.
- Service Provider means a third party that processes data on Our behalf to help deliver the Service.
- Usage Data means data collected automatically from use of the Service or its infrastructure.
- You means the individual using the Service, or the entity on whose behalf they are using it.
What We Do Not Collect
Helion is built around collecting as little data as possible. When the Helion tracking script is used to track visitors on your websites and applications:
- No IP addresses are stored. IP addresses are used transiently to derive city-level geolocation and generate an anonymous visitor identifier, then discarded.
- No cookies are used for analytics tracking.
- No persistent cross-device identifiers. Visitor identifiers are generated from a hash of the IP address, user agent, and project ID combined with a rotating salt, so the identifier cannot be linked back to an individual once the salt rotates.
- No behavioral profiling of individual visitors across sites.
- No data sold to third parties, ever.
If you are evaluating this claim for your own compliance purposes, Helion's source is public — you're welcome to verify these mechanisms directly in the code.
Data We Collect
Analytics data (visitors to your websites, if you use Helion to track them)
- Page URL and referrer
- Browser and OS name/version
- Device type, brand, and model
- City, country, and region (derived from IP at request time; IP then discarded)
- Custom event properties you choose to send
- If you explicitly enable session replay: DOM snapshots and interaction recordings (mouse movement, clicks, scrolls) of your own site's visitors, via rrweb, with text and form inputs masked by default
Account data (Helion dashboard users)
- Email address (required for login and account notifications)
- Name (optional, for display)
- Authentication data if you sign in via Google or GitHub OAuth
Dashboard session
A single server-side session cookie keeps You logged in. It is strictly necessary for authentication, is not used for tracking or analytics, and is deleted on logout or expiry. We also use small local-storage/cookie values for Your own preferences (such as light/dark theme and which login method you used last) — these are not shared with anyone and are not used for tracking.
How We Use Your Data
We use Personal Data to: provide and maintain the Service; manage Your Account; respond to Your requests and support queries; send You service-related communications (such as security notices); and to understand and improve the Service.
We do not use Your data for advertising, and We do not sell or rent it to anyone.
Where Your Data Is Hosted
Today, the Service runs on a single cloud infrastructure deployment. All Service data — regardless of where You are located — is currently processed and stored there. For security reasons, We do not publish the specific infrastructure provider, region, or architecture details of Our deployment.
As Helion grows, We intend to expand to region-specific infrastructure — for example, EU-based infrastructure for European users, US-based infrastructure for US users, and Asia-Pacific infrastructure for APAC users — so that data can be processed closer to where You are, consistent with data residency expectations under GDPR and the DPDP Act. This section will be updated once that expansion happens; until then, the single-region description above applies.
Service Providers We Use
We rely on a small number of third-party service providers to help deliver the Service, including infrastructure hosting and transactional email delivery. Each is bound by appropriate confidentiality and data protection terms. We do not publish the identities of Our infrastructure providers here for security reasons, but You may contact Us for more detail if You need it for Your own compliance purposes (for example, if You are a business customer who needs this information for Your own records of processing activities).
We do not currently use any billing provider or AI/LLM provider — both exist as optional, currently-disabled integrations in Helion's open-source codebase. If We enable paid billing or AI-assisted features in the future, We will update this policy in advance of turning them on, and will name any new sub-processor before it processes Your data.
International Data Transfers
Where Personal Data is transferred outside India or the EEA to one of Our service providers, We rely on the safeguards available to Us under applicable law — including contractual data protection terms with Our providers — to protect that data. If You are in the EEA, transfers to non-adequate countries are additionally governed by Standard Contractual Clauses executed with the relevant provider where applicable.
Your Rights
If the DPDP Act 2023 applies to You (personal data processed in connection with offering goods/services in India), You have the right to: access a summary of Your personal data and processing activities; correct or update inaccurate or incomplete data; erase data that is no longer necessary for the purpose it was collected; withdraw consent at any time; nominate another individual to exercise Your rights in the event of death or incapacity; and file a complaint with Us and, if unresolved, with the Data Protection Board of India.
If the GDPR applies to You (You are in the EU/EEA), You additionally have the right to: access, rectify, or erase Your personal data; restrict or object to processing; request data portability; and lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact Us at hello@helionlabs.dev or Our Grievance Officer above. We will acknowledge Your request promptly and aim to resolve it within 30 days.
Data Retention and Deletion
We retain Your Account data for as long as Your Account is active. Analytics events are retained for as long as the associated project is active; We do not currently enforce a maximum retention period, and will notify You in advance if We introduce one. Session replays, where enabled, are retained for 30 days and then permanently deleted.
You can delete individual projects, all associated data, or Your entire Account at any time from the dashboard. On Account deletion, We delete Your data within 30 days, unless We are legally required to retain it longer.
Children's Privacy
The Service is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect personal data from anyone under 18. If We become aware that We have done so, We will delete that data. If You believe a child has provided Us with personal data, please contact Us.
Links to Other Websites
The Service may link to third-party websites not operated by Us. We are not responsible for the content or privacy practices of those sites, and encourage You to review their policies.
Security
We take reasonable technical and organizational measures to protect Your data, including transport encryption (HTTPS/TLS) and access controls on production systems. No method of transmission or storage is 100% secure, and We cannot guarantee absolute security.
Data Processing Agreement
If You use Helion Cloud to collect analytics on behalf of Your own website's visitors, Helion acts as a data processor and You act as the data controller for that visitor data. Our Data Processing Agreement governs that relationship and forms part of Our Terms of Service.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version here and update the "Last updated" date above. For material changes, We will make reasonable efforts to notify You in advance, such as by email or a notice within the Service.
Contact Us
- By email: hello@helionlabs.dev
- Grievance Officer: Lalit Shrotriya, lalit.shrotriya@outlook.com, based in Mumbai, Maharashtra, India