Privacy Policy
Effective 28 September 2026. This explains how we handle personal data when you visit or use Shardflux.
Who is responsible
Helios One Oy, Business ID 3596623-5, is the controller for Shardflux account, billing, website and support data. Contact: shardflux@heliosone.fi; c/o Victor Ocampo, Servin Maijan tie 10 B 19, 02150 Espoo, Finland.
For personal data you put in workspaces, you determine its purpose and we process it on your behalf under the Data Processing Addendum. If an organization manages your account, its administrators can access and manage the organization's resources and membership.
What we use and why
- Accounts: name, email, password hash, authentication records, organization membership and settings. We use these to create and secure your account and provide the service. The basis is performance of our contract with you, or our legitimate interest in serving your organization.
- Billing: plan, usage, Stripe customer and subscription identifiers, payment status, invoices and billing or tax details. We use these to charge for the service and keep required financial records, based on contract and legal obligations. Stripe collects payment details; we do not receive or store full card numbers.
- Operations and security: IP addresses, user-agent information, request and session records, resource identifiers, usage and errors. We use these to operate the service, troubleshoot and prevent abuse, based on contract and our legitimate interests in reliability, security and fraud prevention.
- Workspace content: files, code, commands, outputs, configured secrets and saved workspace state that you send to the service. We process these to run, store and restore your workspaces under your instructions.
- Communications: messages you send us and service emails such as verification, password reset, billing and security notices. We use these to respond and administer the service, based on contract, legal obligations or our legitimate interest in answering enquiries.
Data comes from you, your organization's administrators, your use of the service and payment updates from Stripe. Required account and billing information is needed to provide the corresponding service. We do not sell personal data, use workspace content to train AI models, or run advertising profiles. We do not make solely automated decisions with legal or similarly significant effects on you; you can ask us to review an account restriction.
Providers and locations
- Amazon Web Services: hosting, workspace compute and storage, databases, security and content delivery. The service's primary region is US West (Oregon),
us-west-2; edge delivery can operate globally. - Stripe: payments, subscriptions, billing and fraud prevention. Stripe also processes some information as an independent controller under its privacy policy.
- Scaleway: transactional email delivery through its Paris region, including recipients, message content and delivery records.
Data may be processed outside the EEA, including in the United States. For transfers requiring safeguards, we use applicable provider data-processing terms and European Commission standard contractual clauses, or an applicable adequacy decision. AWS's data-processing terms include these clauses. Contact us for details or a copy of the safeguards relevant to your data.
We disclose data where necessary to comply with law, protect rights and security, or to professional advisers bound by confidentiality. Services you connect from a workspace receive the data you send them under their own terms.
Cookies and browser storage
The dashboard uses __Host-sf_session to keep you signed in and __Host-sf_csrf to protect requests. The sign-in cookie lasts up to seven days unless the session ends sooner; the CSRF cookie lasts for the browser session.
Browser storage remembers your chosen organization and project, editor drafts, accessibility settings and the working state of features you use. Tab storage also carries invitation and terminal state. Tab data ends with the tab; local settings and drafts remain until cleared or replaced. You can clear storage through your browser, but this may sign you out or remove unsaved drafts.
Our website and dashboard use no advertising or optional analytics cookies. These functional uses support features you request. Stripe-hosted payment pages have their own cookie information.
Retention and security
We keep account and workspace data while needed to provide your account and the resources you retain. You can delete workspace resources through the service and request account closure by email. After closure, we delete or anonymize data no longer needed for those purposes.
Retention of remaining records depends on their purpose: billing and tax records follow statutory accounting periods; security and support records remain while needed to investigate an incident, resolve a request or establish or defend a legal claim. Backup copies expire through backup rotation rather than disappearing immediately. We restrict retained records to those purposes. Contact us for the retention applicable to a particular record.
We use encrypted connections, access controls and isolated workspaces to protect data. Access is limited to what is needed to operate, secure and support the service. No system can remove every risk.
Your rights and contact
Depending on applicable law, you can ask for access, correction, deletion, restriction or a portable copy of your personal data, and object to processing based on legitimate interests. Where we rely on consent, you can withdraw it without affecting earlier lawful processing.
Email shardflux@heliosone.fi from your account address. We may need to verify your identity and normally respond within one month. For data controlled by a customer, contact that customer; we assist them with requests.
You can complain to the Finnish Data Protection Ombudsman or your local data-protection authority. The service is intended for adults. If we learn that a child has supplied account data, we will address it, including deletion where appropriate.
We update this page when practices change and provide notice of material changes by email or in the service. The effective date appears above.