Privacy Policy
This policy explains how data is handled on the Heliarko website and in any optional online function during the public-test period.
The plain-language explanation of the Heliarko privacy model lives on the Privacy page. The two pages are meant to describe the same reality; if they disagree, that is something we need to fix.
Your Capsule and this policy
Heliarko is designed around a personal Capsule created and stored on your own computer or external storage. The website you are reading is a separate thing from that Capsule.
This policy covers the public website and any optional online functions operated by Heliarko. It does not describe the contents of your local Capsule, which the website does not receive.
The precise technical behaviour of Heliarko 1.0.12, including exactly what an optional online AI function transmits, is subject to a technical review. Until that review is published we describe the architecture and our intent, and we do not assert stronger security claims than the software has been shown to support.
Controller
The controller responsible for processing under the GDPR is Mikalai Skachko, operated during the testing period under CEIDG, Poland.
Business address: Aleje Jerozolimskie 85/21, 02-001 Warszawa, Poland.
Email: info@heliarko.com.
No separate Data Protection Officer contact is published for the testing period; privacy requests go to info@heliarko.com.
Website data we process
When you visit the site, the web server (nginx, on a server rented from Hetzner Online GmbH, Nuremberg, Germany) writes technical access-log entries: your IP address, the date and time of the request, the requested path, the referring page, and your browser and operating system (the user agent).
This is necessary to deliver the site securely and reliably; the logs are kept for operation and security and are removed on the server’s log-rotation cycle. Downloads of the program are logged in the same way.
The operator also turns these first-party access logs into aggregate operational statistics: page views, approximate unique visitors, requested paths, referring domains, HTTP errors, starts and resumptions of the public ZIP download, transferred bytes, and registration outcomes.
The analytics database never stores the raw IP address, full user agent, query string, email address, messages, prompts or capsule contents. To estimate unique visitors without a tracking account, it keeps only a keyed pseudonymous digest made from a coarse network prefix and user agent, for no more than 35 days.
The website sets no tracking or analytics cookies, writes no browser storage, runs no client-side analytics, and uses no advertising or third-party analytics service.
When you contact us
If you write to info@heliarko.com, we process your email address, your message, and any details you choose to share, solely to handle your enquiry and any follow-up.
Please do not send Capsule content when a description or a privacy-safe screenshot is enough.
Public-test registration
If you request an activation code, we process your email address, preferred site language, acceptance time and the technical account and activation status needed to issue and bind the code.
The server creates the activation account and sends the personal activation code directly to that email address. The code is never displayed in the public website response or written into website address logs.
No phone number, payment details or website password are requested for the public test.
Testing period and payments
Free during the testing period. Payments are not accepted during testing.
If commercial terms are introduced later, this policy and the Terms will be updated before paid use starts.
Optional online AI
Some Heliarko functions may use an external AI service. Those functions are optional and separate from the local Capsule.
When such a function is used, a network connection is required and the information needed to process that request may leave your device so the external service can produce an answer.
We do not claim that only a specific narrow payload is transmitted, and we do not claim that the entire Capsule is uploaded. The exact behaviour will be described here once it has been verified against the published build.
Provider-specific processing and retention terms depend on the provider active at the time of use and will be reflected here before commercial operation.
Purposes and legal bases (GDPR Art. 6)
- Operating and securing the website: our legitimate interest (Art. 6(1)(f)).
- Registering you for the public test and issuing the activation code you request: steps necessary to provide the test service (Art. 6(1)(b)).
- Responding to your enquiries: pre-contractual or contractual steps and our legitimate interest (Art. 6(1)(b) and (f)).
- Providing an optional online function you choose to use: performance of a contract (Art. 6(1)(b)).
- Anything based on consent (none required as currently built): your consent (Art. 6(1)(a)), which you may withdraw at any time.
Recipients and processors
We share data only with service providers acting on our behalf: Hetzner Online GmbH (Nuremberg, Germany) provides the server that hosts the website and the program downloads; email providers are used to receive and answer messages; and — only for an optional online AI function when it is used — a third-party AI provider.
These providers act as processors or as independent parties under their own terms and applicable agreements.
International transfers
Some providers may process data outside the European Economic Area, including in the United States.
Where this happens, transfers should be protected by appropriate safeguards such as European Commission Standard Contractual Clauses, an adequacy framework, or equivalent provider safeguards required by applicable law.
Retention
The registration service stores the verified email, acceptance record, account reference and activation status needed to operate the public test and prevent duplicate or abusive code use.
The web server’s technical access logs are kept for operation and security and are deleted on the default log-rotation cycle.
Enquiry emails are kept only as long as needed to handle the matter and to meet any legal retention duties.
Your rights under the GDPR
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time.
To exercise any right, email info@heliarko.com.
You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland.
US privacy rights (CCPA/CPRA and similar)
If you are a US resident, you may have rights to know, access, correct, and delete personal information, and to opt out of its sale or sharing.
We do not sell your personal information and do not share it for cross-context behavioural advertising.
We honour verifiable requests and will not discriminate against you for exercising these rights. To make a request, email info@heliarko.com.
Children
The website and product are not directed to children.
We do not knowingly collect personal data from children under 16, or the applicable age in your jurisdiction such as 13 in the United States.
If you believe a child has provided us data, contact us and we will delete it.
Security
We use reasonable technical and organisational measures to protect the data we process.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We do not publish absolute security claims about the product — such as encryption at rest, zero knowledge, or the absence of any master key — until the current build has been technically reviewed and the claim can be supported.
Changes and contact
We may update this policy as the product, providers and law evolve.
Last revised: 28 August 2026.
Questions: info@heliarko.com.
Review note
This policy reflects the current website, email-confirmed registration and the free testing period.
It must be reviewed again before paid service, browser-based tracking, additional processors, or any transfer of the operator to a new company.
A technical privacy review of the published Heliarko 1.0.12 build is outstanding, and this policy will be updated when it is complete.
- Controller
- Mikalai Skachko · CEIDG, Poland
- Business address
- Aleje Jerozolimskie 85/21, 02-001 Warszawa, Poland
- Privacy contact
- info@heliarko.com
- Last revised
- 28 August 2026
- Effective from
- The public release of Heliarko 1.0.12
- Supervisory authority
- Prezes Urzędu Ochrony Danych Osobowych, Warszawa