// privacy_policy

Privacy Policy

Last updated: June 8, 2026

HeliusOne handles sensitive brokerage and AI workflow data. This policy explains what data is processed, who may receive it, and the controls available to you.

1. Introduction

HeliusOne ("HeliusOne," "we," "us," or "our") provides software for market monitoring, portfolio tracking, AI-assisted research, and order-management workflows. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our website, terminal, and related services.

HeliusOne is not a registered investment adviser, broker-dealer, tax adviser, or law firm. Our privacy practices are designed around the sensitive nature of brokerage, AI, and trading workflow data.

2. Information We Collect

  • Account information, such as your email address, display name, login metadata, consent records, user preferences, and account settings.
  • Brokerage information, such as brokerage account metadata, positions, balances, buying power, orders, transactions, fills, watchlists, market data subscriptions, and OAuth token data used to access your connected brokerage account.
  • Financial workflow information, such as P&L, cost basis, tax-lot estimates, wash-sale indicators, holding-period estimates, risk settings, trading caps, AI portfolio holdings, rebalance proposals, and trade-history records.
  • AI and research information, such as prompts, model selections, AI analysis outputs, uploaded research documents, symbol-specific notes, news context, and generated recommendations or signals.
  • Chat and collaboration information, such as messages, shared analysis summaries, attachments, direct-message metadata, channel membership, and user-discovery preferences.
  • Technical and diagnostic information, such as device/browser details, IP-derived metadata, application events, error messages, security events, and temporary diagnostic logs.
  • Payment and subscription information, if applicable, processed by third-party payment providers. We do not intentionally store full payment card numbers in the terminal.

3. How We Use Information

  • To provide and operate the terminal, including authentication, brokerage connection, market data display, portfolio tracking, alerts, order workflows, chat, and account settings.
  • To generate AI-assisted analysis, alerts, portfolio proposals, daily insights, and research summaries using the AI providers you enable.
  • To enforce user-configured safety controls, including consent gates, trading toggles, dollar caps, holding-period checks, and logging preferences.
  • To improve reliability, security, fraud prevention, debugging, and product quality.
  • To comply with legal obligations, respond to user requests, enforce our Terms, and protect users, HeliusOne, and third-party services.

4. AI Providers and Third-Party Processing

When you enable and use AI features, relevant portfolio, market, document, and account-context information may be sent to third-party AI providers, including Anthropic Claude and Google Gemini. These providers process the information according to their own terms and privacy policies.

AI workflows may include symbols, market prices, holdings, P&L, cost basis, transaction context, tax-lot estimates, uploaded document text, risk settings, and news context. You can disable AI providers and related features in the terminal settings.

5. Brokerage Integrations

When you connect a brokerage account, HeliusOne uses OAuth tokens and brokerage API access to request account data, market data, orders, transactions, and related brokerage information. You are responsible for reviewing and complying with your brokerage provider's terms.

Brokerage tokens are sensitive. You should keep your account secure, sign out on shared devices, and promptly report unauthorized access.

6. Logs, Diagnostics, and Debug Controls

Terminal diagnostics are temporary and limited to the latest 500 messages in the application session. Sensitive payloads are redacted before display or export. Users can set logging to standard, debug, or off in user-scoped settings.

Debug mode may include more technical metadata, but the application is designed to redact account numbers, tokens, API keys, prompts, transaction payloads, positions, cost basis, balances, order payloads, and similar sensitive information from logs.

7. Information Sharing and Disclosure

  • Service providers: We may share information with infrastructure, authentication, hosting, analytics, payment, AI, communication, and support providers as needed to operate the service.
  • Brokerage and market data providers: We exchange information with connected brokerage and data providers at your direction.
  • AI providers: We send relevant prompts and context to AI providers you enable.
  • Chat participants: If you share messages or analysis in chat, selected summaries and attachments may be visible to the relevant channel or direct-message participants.
  • Legal and safety: We may disclose information if required by law, legal process, security investigation, or to protect the rights, safety, and integrity of users, HeliusOne, or third parties.
  • Business transfers: Information may be transferred in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

8. Cookies and Tracking Technologies

Our website and terminal may use cookies, local storage, authentication state, and similar technologies to support login, account state, security, user preferences, analytics, and product functionality. You can manage some browser-based controls through your browser settings, though disabling storage may break parts of the service.

9. Data Retention

We retain information for as long as necessary to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business operations. Retention periods vary by data type. Temporary diagnostic logs are limited in the application session, while account, consent, brokerage workflow, and trading records may be retained longer.

10. Your Choices and Rights

  • You can disable AI providers, Express Approval trading, price-prediction gating, model-training contribution, and debug logging in settings.
  • You can request access, correction, export, or deletion of personal information by contacting support@heliusone.com, subject to identity verification and legal or operational retention requirements.
  • You can opt out of non-essential marketing communications, though we may still send transactional or security-related messages.

11. Security

We use technical and organizational safeguards designed to protect sensitive information, including access controls, provider-specific authentication, consent gates, redaction, and user-scoped settings. No system is perfectly secure, and you are responsible for protecting your devices, passwords, brokerage sessions, and API keys.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise a privacy request, contact us at support@heliusone.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy and update the effective date. Continued use of the service after an update means you accept the revised policy.