Helios / Policy
Privacy policy
Understand what is handled, where it goes, and what you can control.
This policy describes the current Helios implementation by Prismtrade LLC and this informational website. Helios is in development and is not publicly available yet. Your independently operated workspace server may have its own privacy policy.
Data the app handles
- Connection and session information: the server address, pairing credential, device token, session identifier, company identifier, and expiration time are used to establish and maintain authorized access.
- Workspace information: company and profile details, organization information, chat metadata, approval records, and any message history supplied by your server are received to display your workspace. Supplied history can include sender names, message text, and timestamps.
The current connection flow keeps the retrieved workspace in memory. It stores the server address and session information in Apple Keychain using device-only, when-unlocked protection. Network requests use an ephemeral URL session. These controls are not a guarantee against access to a compromised device or server.
Where information goes
The app sends pairing and authenticated workspace requests to the HTTPS server you enter. The server operator controls that service and the records it supplies. Pairing is scoped to one company. Prismtrade LLC does not automatically receive your self-hosted workspace simply because you use the app.
The current app contains no analytics or advertising SDKs. It does not implement message sending, agent execution, or AI chat. No workspace content is sent to an AI provider by this current connection flow.
The included local backend
The development backend stores company profiles, chat metadata, session and pairing credential hashes, and any provisioned approval and audit records in local SQLite. SQLite storage is not encrypted by this implementation; the operator must protect the host and backups.
Pairing credentials are single-use and expire after five minutes. Device sessions expire after 24 hours and can be revoked. Only SHA-256 hashes of these credentials are stored by the backend. Credential expiration is not a deletion schedule for database records.
The optional Teams cache adapter imports chat topics and types, along with private source identifiers and provenance timestamps. It does not import member emails, member lists, message bodies, HTML, or previews, and is not a live synchronization service. The included backend does not currently ingest full message history; the client can nevertheless read history supplied by a compatible server.
Retention and disconnection
Workspace, audit, backup, and operational-log retention depends on the server administrator’s configuration and practices. There is no universal automatic deletion period promised here, and the development backend does not provide a complete retention-management system. Ask your operator what is retained and for how long.
“Revoke session & disconnect” is not account or workspace deletion. The app asks the server to revoke the token and verifies that the session can no longer read the workspace before removing its saved Keychain connection and in-memory snapshot. If revocation cannot be confirmed, it reports an error and retains the connection so you can retry. Uninstalling the app is not a reliable substitute for server-side revocation or deletion.
This website and support email
This static website embeds no cookies, analytics, tracking scripts, advertising, external fonts, third-party asset dependencies, or submission forms. It is hosted by GitHub Pages, which processes request information to operate and secure hosting. See GitHub’s privacy statement. A hosting service may process operational request information such as IP addresses, requested pages, timestamps, and browser information to deliver and secure the site. The actual host’s configuration and policy determine logging and retention; no exact hosting-log retention period is represented here.
If you email support, Prismtrade LLC receives your email address, message, and any attachments you choose to send, for responding to your request. Email services process that correspondence. Do not include tokens, pairing credentials, passwords, or confidential workspace exports. Support correspondence retention depends on handling needs and applicable obligations; this policy does not promise a fixed deletion period or a particular vendor guarantee.
Your choices and privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or object to processing of personal information, or request a portable copy. Contact your workspace administrator for server-held records. Contact info@iqonhealth.com for Prismtrade LLC privacy questions, support-correspondence deletion, or help directing a request. We may need to verify your identity and authority without asking for your session token.
Deleting a device session does not delete organizational records, audit history, backups, or records held by other services. Your administrator should explain any technical or legal limits on deletion. You may also have the right to contact your local data protection authority.
Changes and contact
We will revise this page as actual product behavior changes. Future capabilities are not covered as if already implemented. For questions, email info@iqonhealth.com or visit support.