Privacy Policy

This policy explains what HELIOROUTE collects, why, and what we do with it. We keep it deliberately small: no identity documents, no card data, no ad tracking.

Last updated 2 October 2026

1. Information you give us

  • Account identifier — an email address, or a wallet address where you sign up with one.
  • Password — stored only in hashed form. We never store or log your password in plain text.
  • Support messages — whatever you choose to include when you email us (for example an order reference or a transaction hash).

2. Information the service generates

  • API keys — we store what is needed to authenticate, meter and revoke a key. The console only ever shows you a masked form of the key; the full secret is shown to you once, at creation.
  • Usage records — for each request we record the model used, token counts, the amount spent and a timestamp, so your balance and usage dashboard are accurate.
  • Technical and security data — IP address and user-agent on requests to the panel and API, used for rate limiting, abuse prevention and audit.

3. What we do NOT collect

We run no KYC. We do not ask for, and do not want, any of the following:

  • Government-issued identity documents of any kind.
  • Card numbers, bank details or bank statements — we do not accept cards.
  • Your name, address or date of birth as a verification requirement.

4. Payment data

Payments are crypto-only. To match an incoming payment to your order, we store the on-chain details involved in that transaction — the deposit address, the amount, and the transaction hash. Note that this information is already public on the blockchain; we simply record it so we can credit the right account.

We do not store any private key, seed phrase or card data, because we never hold any.

5. How we use your information

  • to run the service and serve your API requests;
  • to bill accurately — meters, balances and invoices;
  • to prevent abuse, fraud and attacks, and to enforce our rate limits and terms;
  • to respond to your support requests;
  • to meet legal and regulatory obligations that apply to us.

6. Who we share it with

We share the minimum necessary to operate. Two main categories:

  • Model providers — to answer a request, the prompts and inputs you send are forwarded to the upstream provider that serves the model you chose, for inference only.
  • Infrastructure providers — hosting and database providers that run the platform, under their own security and confidentiality obligations.

We do not sell your personal information, and we do not share it for advertising.

7. Retention

We keep account and usage records for as long as your account is active, and for a reasonable period after it closes so we can meet billing, accounting and legal obligations, and to preserve audit logs for security and abuse investigations. When data is no longer needed for these purposes, we delete or anonymise it.

8. Security

Access to production data is restricted, passwords are hashed, API keys are masked in the interface, and traffic is served over HTTPS. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data — and we deliberately hold as little of it as possible.

9. Your rights

You can ask us to access, correct or delete the personal data we hold about you — for example your account email and its usage records. Email support@helioroute.com from the address on the account. Some records may be retained where we have a legal or legitimate reason to keep them.

10. Cookies

We use a single session cookie to keep you signed in. It is httpOnly and is not used for advertising. We do not run third-party analytics or ad-tracking cookies.

11. Changes to this policy

We may update this policy from time to time. The current version is always the one published on this page, with the date shown at the top. See our Terms of Service for the rules that govern your use of the service.

12. Contact

Privacy questions or requests: support@helioroute.com.