Skip to main content
Legal

Privacy policy

Public draft · last updated 2026-08-27.

This privacy policy is in public draft during our beta. It accurately describes how we handle data today. Material changes will be announced via in-app notice and email 30 days in advance of taking effect.

Our commitments

  • We do not sell user data.
  • We do not train third-party models on user content without consent.
  • Research data uploaded to the platform is encrypted at rest and in transit.
  • You can export your data at any time, and delete your account and its private data at any time.
  • Institutional deployments can opt in to additional data-residency controls.

Data-handling practices

  • TLS for data in transit (1.2 minimum, 1.3 negotiated in practice); AES-256 at rest on standard commercial cloud infrastructure.
  • Least-privilege access controls on engineering and support tooling.
  • Research and partnership data shared in project workspaces stays private to invited members.
  • We don’t sell account data to third parties and don’t share it with advertising networks.

Marketing email

Separately from your platform account, we run an opt-in mailing list: Helikon Field Notes, our research newsletter, and short follow-up sequences attached to a specific download or assessment you asked for. Subscribing is never a condition of using the platform, and the two systems are kept apart.

  • Double opt-in. Giving us an address sends you one confirmation email and nothing else. Until you click that link we send you no marketing mail, and the link expires. Our lawful basis is your consent, which you can withdraw at any time.
  • What we store. Your email address, your first name and role category if you gave them, the page that captured the signup, and tags recording which download or sequence you asked for. We also record delivery, open, click and bounce events for the emails we send you, which is how we tell a broken sending setup from an uninteresting newsletter.
  • Unsubscribing takes one click. Every marketing email carries an unsubscribe link and the one-click unsubscribe headers your mail client uses, so Gmail and Outlook can offer the control directly. Unsubscribing stops all marketing email and lands you on a confirmation page. We don’t ask you to sign in first, and we don’t email you to confirm it.
  • How long we keep it. If you never confirm, we delete the record about 30 days after the confirmation link expires, unless you have already used it to download something or take an assessment. If you unsubscribe, we keep a minimal suppression record of your address so that we do not mail you again by mistake. Ask us to erase it entirely and we will.

To be removed completely, including the suppression record, send us a note.

Public scientific record

Publication and patent data surfaced on the platform comes from public research records (OpenAlex, PatentsView, ORCID™, and ROR). This data is part of the public scientific record and is not deleted when an individual account is closed. For corrections upstream, contact the indexing source directly. See our Attributions page for full trademark and licensing details on these sources. For copyright concerns about hosted or indexed content, see our DMCA and copyright policy.

Account data on deletion

When you delete your Helikon Labs account, your profile, private projects, messages, and files enter a 30-day grace period (during which recovery via support is possible). After 30 days, personal identifiers are permanently removed. Publication and patent records remain in the public research index and are unaffected.

Minimum age

Helikon Labs is built for researchers, university staff, and industry professionals. You must be at least 16 years old to create an account, and we ask you to confirm this at signup. We do not knowingly collect personal information from anyone under 16.

If you believe someone under 16 has created an account or given us personal information, tell us and we will delete the account and the associated personal data. Publication and patent records already in the public research index are drawn from public scholarly sources and are handled under Public scientific record rather than this section.

Compliance programs (roadmap)

Formal SOC 2 certification, FERPA, and GDPR programs are on our roadmap for institutional customers. If your institution has a specific compliance requirement, send us a note and we’ll share where we are on the path.

Contact us about privacy

All privacy, data-subject, and GDPR requests are handled through our contact form. We don’t list inboxes publicly, so legitimate requests don’t get buried in spam.

Submissions are routed to the right team internally. We acknowledge data-subject requests within 30 days as required by applicable privacy law.