Helisoma

Legal

Privacy Policy

Effective date: 2 July 2026 · Last updated: 2 July 2026

1. Who we are

This Privacy Policy explains how Helisoma (“Helisoma”, “we”, “us”), the data controller, collects and uses your personal data when you use the Helisoma website and application (the “Service”).

Controller: Helisoma. Contact: hello@helisoma.com. Data protection contact: hello@helisoma.com.

2. The data we collect

3. How we use your data and our legal bases

Under the GDPR we rely on the following legal bases:

4. Connecting AI assistants (Claude, ChatGPT, Gemini)

You can choose to connect a third-party AI assistant to your account so it can read your genome report and answer your questions. This connection is optional and started by you. When you authorize it, Helisoma transmits your genome report data — at your direction — to the AI platform you selected (for example Anthropic’s Claude, OpenAI’s ChatGPT, or Google’s Gemini) through our connector.

From that point the platform processes your data under its own privacy policy and terms, as an independent controller. We do not control how it uses your data once it reaches them, and depending on that provider’s terms and your settings there, it may retain or use your data to improve or train its models. Please review the provider’s policy before connecting. You can revoke a connection at any time from your account settings.

5. Who we share data with

We do not sell your personal data. We share it only with:

A current list of processors is available on request at hello@helisoma.com.

6. Cookies and analytics

We use strictly necessary cookies to run the Service (e.g. your login session); these do not require consent.

Anonymous visit statistics (no cookies). To know how many people visit our pages, we count page views in a way that cannot identify you: nothing is stored on your device (no cookies, no local storage), your IP address is not recorded or used to derive your location, and each visit appears under a random identifier that exists only in your browser's memory and is gone when you leave. This measurement is processed by Mixpanel on EU servers. We rely on our legitimate interest (Art. 6(1)(f)) in understanding overall traffic for this minimal, cookie-free counting, and it stays on even if you reject analytics cookies.

Full analytics (only with your consent). To understand how the Service is used across visits, we also use Google Analytics 4 (Google) and Mixpanel (Mixpanel, Inc.), which use cookies or similar identifiers and record page views and interactions such as clicks. We do not use session recording or screen replay. These analytics cookies load only after you accept them in our cookie banner. If you reject them, only the anonymous cookie-free counting described above continues. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer.

7. International transfers

Some providers (such as Google, Mixpanel and Stripe) may process data outside the European Economic Area / United Kingdom, including in the United States. Where this happens, we rely on appropriate safeguards such as the UK extension to the EU-US Data Privacy Framework, the EU Standard Contractual Clauses, and the UK International Data Transfer Addendum.

8. How long we keep your data

We never receive or store your raw DNA file: it is read on your own device, and only the markers our reports use are sent to us. We keep those extracted markers and your generated reports for as long as your account is active. If you delete your genetic data or your account, we delete the extracted markers and generated reports within 30 days. Markers sent for the free landing-page analysis without an account are deleted automatically after at most one hour unless you create an account and claim them in that time. We keep transaction and tax records for 6 years to meet UK accounting and tax law (HMRC), even after account deletion; these do not include your genetic data.

9. Your rights

Under the EU GDPR and UK GDPR you have the right to:

To exercise any right, email hello@helisoma.com. You can delete your genetic data and account yourself at any time in the app’s account settings.

10. Security

We use technical and organizational measures to protect your data, including encryption in transit, hashed passwords, and access controls. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authority of any breach as required by law.

11. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy. We will post the new version here and update the “Last updated” date, and for material changes we will notify you by email or in the app.

13. Contact

Questions about this policy or your data? Email hello@helisoma.com.