Helix Privacy Policy
Applies to the Helix website, Lens, and related services
Last updated: August 29, 2026
1. Who we are
Helix ("Helix", "we", "us", or "our") provides software engineering products and services, including Lens. The Helix entity responsible for a customer relationship is the entity identified in the applicable order form, checkout, account registration, or other commercial agreement. Our website is https://gethelixworks.com/.
2. Information we collect
Account and contact information
We may collect names, business email addresses, organization information, account identifiers, and other information provided when a person creates or uses an account, requests access, contacts us, or communicates with us.
Authentication and source-control information
Lens currently relies on connected source-control and identity providers, including GitHub and GitLab, for authentication and repository authorization. We may receive account identifiers, organization and repository metadata, access tokens or equivalent authorization credentials, and permission information required to provide the Service.
Customer repository content and derived data
When an authorized customer connects a repository, Lens may collect and store source code and repository content, together with derived architectural representations, relationships, indexes, metadata, and other information generated by Lens to provide architectural context and related functionality. We refer to this information as "Customer Data."
Usage, device, and diagnostic information
We may collect service usage information, IP address, browser and device information, timestamps, event logs, error logs, performance information, and similar diagnostic data used to operate, secure, troubleshoot, and improve the Service.
Communications
We collect information you provide when you contact us, request support, participate in product discussions, provide feedback, or otherwise communicate with Helix.
3. How we use information
Provide, operate, maintain, secure, and support Lens and other Helix services.
Authenticate users and enforce organization and repository access permissions.
Process connected repositories and generate architectural representations and other service outputs.
Monitor availability, diagnose technical problems, prevent abuse, and protect the security and integrity of the Service.
Communicate with users and customers about accounts, product updates, support, security, legal notices, and requested information.
Understand product usage and improve product performance, reliability, usability, and features using service telemetry and feedback.
Comply with applicable law, enforce our agreements, and protect the rights, property, and safety of Helix, our users, customers, and others.
4. No training on Customer Data
Helix does not use Customer Data — including source code, repository content, architectural representations, or private customer content — to train Helix models or third-party models.
This restriction does not prevent Helix from using operational metrics, de-identified telemetry, or customer-provided feedback that does not contain Customer Data to operate and improve the Service, subject to applicable agreements and law.
5. AI and model processing
Lens primarily uses models hosted within Helix-controlled Google Cloud Platform infrastructure. For selected tasks, Lens may use third-party model infrastructure through Google Cloud services such as Vertex AI. Where Customer Data is provided to a model service, it is processed only to provide the requested Service and is subject to Helix contractual and technical controls. Customer Data is not used for model training.
6. How we disclose information
We may disclose information in the following limited circumstances:
Service providers and subprocessors. We use vendors that provide cloud infrastructure, model infrastructure, email, monitoring, logging, analytics, and related operational services. Our current subprocessor list is published separately.
Customer-directed integrations. If a customer connects GitHub, GitLab, or another third-party service, information may be exchanged with that service as directed by the customer and subject to the third party's terms and privacy practices.
Legal requirements and protection. We may disclose information when required by law or legal process, or when reasonably necessary to protect rights, security, users, customers, or the public.
Business transactions. Information may be transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate confidentiality protections.
With direction or consent. We may disclose information when a customer or user directs us to do so or otherwise provides valid consent.
7. Hosting and international processing
The standard Lens environment is hosted on Google Cloud Platform in the United States, currently using a U.S. Central region. Enterprise customers may contact Helix regarding alternative regions or deployment within a customer-controlled cloud environment, where offered and agreed in writing. Information may be processed in locations where Helix and its service providers operate, subject to applicable contractual and legal safeguards.
8. Repository access and permissions
Lens is designed to respect the permissions made available by the connected source-control system and the customer's Helix organization configuration. Customers are responsible for administering their source-control permissions and for authorizing the repositories and users that may access Lens. Helix may also provide organization-level controls for customer administrators.
9. Data retention and deletion
Helix retains information for as long as reasonably necessary to provide the Service, maintain security and operational integrity, comply with applicable law, resolve disputes, and enforce agreements. When an authorized user disconnects or unlinks a repository, Helix deletes the repository source code and the associated Lens-derived repository data from the active Helix environment, and the disconnected repository can no longer be used through Lens unless it is connected again. Limited records that are required for security, legal, billing, or audit purposes may be retained where necessary. Data contained in backups, if any, is removed in accordance with the applicable backup lifecycle and is not restored for ordinary product use after deletion.
10. Security
Helix uses administrative, technical, and organizational measures designed to protect information against unauthorized access, disclosure, alteration, and destruction. No system can guarantee absolute security. Customers are responsible for protecting their accounts, access tokens, source-control permissions, and user devices.
11. U.S. privacy rights
Depending on where you live and the law that applies, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information, and to appeal a decision relating to a privacy request. Helix does not sell Customer Data. Helix also does not use Customer Data for cross-context behavioral advertising.
To submit a privacy request, contact srinivas.palepu@gethelixworks.com. We may need to verify your identity or authority before completing a request.
12. Cookies and similar technologies
We use cookies and similar technologies that are necessary to operate the website and Service, maintain sessions, improve security, remember preferences, and understand service usage. Additional information is provided in the Helix Cookie Policy.
13. Children
Helix services are intended for business and professional use and are not directed to children under 13. We do not knowingly collect personal information from children under 13 through the Service.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date when we make changes and may provide additional notice of material changes where appropriate.
15. Contact
Questions or privacy requests may be sent to srinivas.palepu@gethelixworks.com or through the contact methods published at https://gethelixworks.com/.
| Scope: This Privacy Policy explains how Helix collects, uses, discloses, and protects personal information in connection with the website, Lens, and related services. Customer repository content and other data processed on behalf of an organization are handled as Customer Data under the applicable agreement and, where applicable, the Data Processing Addendum. |
| Commitment: Helix does not use Customer Data - including source code, repository content, architectural representations, or private customer content - to train Helix models or third-party models. |