We measure the pipe, not what goes through it.
Helix exists to tell you how good your connection is. That needs timing and loss data about probe packets we send ourselves. It does not need — and does not collect — anything about what you do online.
What is collected, and what is not.
Collected
- Round-trip timings, loss counts and loss-run lengths for probes Helix sends
- Outage spans and the fault domain concluded for them
- DNS resolution timings and failures
- Total bytes in and out per connection, for usage and quotas
- Speed-test results, including the loaded-latency delta and bufferbloat grade
- Traceroute and MTR hop addresses when you run a path analysis
- Your public IP address, network operator and connection type, to identify which line a measurement belongs to
- Network adapter details and Wi-Fi signal strength, for local diagnosis
Not collected
- The content of anything you send or receive
- Which websites or services you visit
- Which applications use the network — per-application monitoring is not in this release, and if it ships it will be local by default, separately opted in, and never shared with an ISP
- Anything from other devices on your network
- Any packet Helix did not send itself — there is no traffic capture and no packet inspection
Three destinations, and you control the second and third.
-
Your machine, always
Everything is written to a local database under %PROGRAMDATA%\Helix first. With no account and no network, Helix is fully functional. Uninstalling deliberately leaves that folder alone; delete it yourself if you want it gone.
-
The Helix cloud, only after you enrol the device
Sync is off until you paste a device token into the app. From then on, measurement windows upload so you have history across devices. Turn it off and uploading stops immediately — no restart, no delay.
-
Your ISP, only if you link and share
A separate, explicit decision on top of having an account. It is per-link and per-connection, and it is off until you turn it on.
Third parties the agent contacts by design. To measure anything, Helix has to send packets somewhere. By default it probes your own router plus three public resolvers run by different operators — Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9). Three operators, so one of them having a bad day is not mistaken for your line having one. Speed tests run against Cloudflare's speed-test endpoints. Those providers see the connections, as they would from any device on your network.
Treated as personal data, because they are.
Short-lived where it is identifying
Your public IP is a connection attribute with a short life. The long-lived analytical record keeps the network operator and a coarse region, not the address itself — because what the analysis needs is “which ISP, roughly where”, and that is a much weaker identifier.
Redaction before publishing
A diagnosis report contains your IP, your ISP and the hostnames along the path. If you publish one, you are shown what it contains and can mask the last part of your public IP and hide hostnames — and the redaction is applied before the upload, not by hiding fields in the viewer afterwards.
Published reports
A published report lives at an unguessable link, is rate-limited, is marked not to be indexed by search engines, and can be revoked at any time. You can set it to expire.
Path hop countries are registry data
Each hop in a path analysis is annotated with the network that owns it and the country that network is registered in. That is not geolocation and it is not where the equipment is. We label it as registry country so nobody reads it as a location.
Two gates, and both fail closed.
Sharing with an ISP is not one switch with a permission attached. It is two independent questions asked on every single read, and either one saying no means nothing is returned.
Gate one: consent
Did you turn sharing on for this link, and have you not withdrawn it? This is a live condition in the query itself, not a flag checked once and cached. There is nothing to expire and no job to wait for.
Gate two: scope
Which of your connections may this particular ISP see? For an ISP that operates its own network, that is the connections on their network. For a reseller or a carrier-grade-NAT operator without one, it is only the connection you explicitly pinned to them — and if you pinned nothing, they get nothing.
What they see
Latency, packet loss, outages and speed tests for the shared line, as counts and distributions over a window they choose, plus tickets you raised with them. They see your service ID because you gave it to them; they do not see your other connections, and there is no browsing or traffic data to see because none exists.
Their staff are limited too
Inside an ISP organisation, access is by capability rather than seniority. Their billing and CRM staff have no permission to read connection quality at all, because your consent was given for support purposes and a design that let a billing clerk browse your history would be a failed design.
Off means off, on the next query.
What happens immediately
Turn sharing off in the dashboard and the very next request your ISP makes returns nothing for you. You disappear from their subscriber list entirely — not greyed out, not marked as revoked. An ISP has no business knowing that somebody used to share with it.
Every consent and every revocation is recorded as an immutable event, so what you agreed to and when is answerable.
Copies outside Helix
Telemetry is read from Helix per service and time-bounded. It is deliberately never bulk-exported into a database the ISP operates, because the moment a copy lives there, revocation stops being something the code enforces and becomes something a contract promises.
Where an ISP has legitimately retained something — a report you attached to a ticket, for instance — deletion is a contractual obligation on them, not a technical guarantee we can make on this page.
Raw measurements are kept 30 days. For everyone.
One policy, not three
The storage-limitation policy for raw telemetry is a uniform 30 days on every tier, free included, applied by an automatic sweep. The 3-, 10- and 30-day tiers are access entitlements: how far back the service will serve you. They are not deletion schedules and we never describe them as such — not to users and not to regulators.
That is also why upgrading is instant rather than starting a new collection.
Summaries and account deletion
Downsampled summaries persist while your account is active and are deleted with the account. Delete the account and the local database on your machine is still yours — it is not reached by anything the cloud does, and you remove it by deleting the folder.
Data requests: [email protected]
The site you are reading is not the product.
Everything above describes the Helix Internet Monitor software. This section is about helixaicloud.com itself, which is a different thing with different visitors, and it would be a strange omission on a page like this one.
Two third parties run on these pages
Secure Privacy provides the consent banner, and Google Analytics measures which pages people read. Both are loaded from their own servers, so both see your IP address and your browser's user agent, as any embedded script does.
The consent manager loads first, deliberately. It decides whether the analytics tag is allowed to run, which only works if it is running before the tag rather than beside it.
What that is used for
Aggregate readership: which pages are found, which are read to the end, which are never reached. It is how a documentation page that nobody can find gets discovered and fixed.
It is not connected to your Helix account. Signing in happens on a different host, and nothing here is joined to a subscriber record.
Downloads are counted
When you download the installer, the request passes through a Helix-operated endpoint that records the time, the version, a coarse location derived from the address, and the address itself. That serves two purposes and only two: knowing how many people are running which version, and rate-limiting abuse of the download.
It is kept for 30 days, the same uniform window as everything else in this product, and then deleted. Why 30 days →
Your choice actually applies
Decline in the consent banner and the analytics tag does not run. You can change your mind from the banner's control at any time.
The download counter and its rate limit are not analytics and are not covered by that choice: they are the operational record of a file transfer you asked for, in the same way a web server logs a request. We would rather say that plainly than bury it.
What we are not claiming.
This page describes what the software does. It is not a legal notice and it does not assert a certification, because none has been earned.
- No compliance certification is claimed. Independent audit is on the roadmap ahead of general availability of the ISP platform; it has not happened.
- Refresh tokens do not yet have reuse detection. A stolen session token stays valid for up to 30 days. That is acceptable for a controlled pilot and it is not acceptable for general availability, which is why it is written here.
- The installer is not code-signed, so you cannot currently verify the publisher of the binaries by their signature. Compare the published checksum instead.
- EU data residency is designed for and not yet offered. Ask us where your data sits before you assume.
Questions before you install?
The download page is equally blunt about what happens on your machine, and the docs walk through every step where you are asked to consent to something.