Privacy and data use
HelixAuth collects only the information needed to operate access, agreements, credentials, verification, and security records.
Last updated August 10, 2026Information processed
- Account identity, organization, invited audience, and passkey credential metadata.
- Agreement versions, signatures, consent records, and privacy-preserving request fingerprints.
- Files and metadata submitted for credential issuance, plus custody and transparency events.
- Operational, audit, and security events needed to protect the service.
How information is used
Information is used to authenticate users, enforce access boundaries, execute requested product workflows, preserve exact agreement and credential records, investigate errors or abuse, and improve the beta.
Storage architecture
Structured operating state is stored in the site data service. Versioned business records use the configured private GitHub repository, and artifact files use managed object storage. Public verification exposes only the records intended for independent verification.
Sharing
HelixAuth does not sell personal information. Data is disclosed only to service infrastructure, authorized Helix operators, intended workflow participants, or when required to protect users and comply with applicable obligations.
Retention and choices
Security, signature, custody, revocation, and transparency records may need to be retained to preserve integrity and accountability. For access or correction questions, use the project contact or administrator through which your Helix access was issued.
Sensitive submissions
Do not upload regulated, highly sensitive, or unrelated personal information unless the applicable pilot agreement and workflow expressly authorize it.