Privacy Policy

Effective Date: August 12, 2026

1. Core Philosophy

Heliox OS is a local-first, open-source desktop agent. This policy explains which data stays on the device, when an optional external provider can receive data, and which controls remain with the user.

2. Local-First Execution

The daemon, action execution, permission checks, audit records, settings, learned preferences, and supported local speech or vision components run on the user's device. Heliox does not operate a central prompt or telemetry service. Local execution does not by itself guarantee that every configured feature is offline: network actions, integrations, model downloads, and cloud model providers communicate with their respective external services when the user enables or invokes them.

3. Hybrid Cloud Mode (Optional)

Users can configure external model providers such as Anthropic Claude, OpenAI, Google Gemini, or Meta. When an external provider is selected:

  • Prompts and the context needed for the requested task are sent directly from the device to that provider. Depending on the feature, context can include user instructions, extracted screen text, screenshots, files, or action results.
  • Heliox OS acts purely as a local interface client.
  • We do not intercept, store, log, or proxy your prompts or the responses through any central Heliox servers.
  • The provider's own privacy, retention, account, and billing terms apply.

4. Telemetry and Analytics

The current release contains no first-party analytics or automatic crash-reporting service. Local logs and audit databases are created so users can inspect execution and diagnose failures; they remain on the device unless the user exports or shares them. Operating systems, model providers, integrations, package registries, and downloaded dependencies can have separate logging or telemetry policies outside Heliox's control.

5. Credentials, Sensors, and Local Records

API credentials are stored through the operating system credential service: Windows Credential Manager, macOS Keychain, or a Secret Service-compatible keyring on Linux. Heliox fails closed when secure credential storage is unavailable. Camera, microphone, gaze, gesture, screen-supervision, and neural-research features are opt-in and can create local runtime state or consented recordings as described by their controls. Users should review those controls before enabling an always-on sensor.

6. Open Source Verifiability

Because the core engine is open-source, you do not have to trust our words blindly. You can independently verify our data routing and privacy claims by reviewing the underlying Python code and execution nodes directly at our GitHub Repository.

7. Contact Information

For privacy-related inquiries, open-source feedback, or to discuss our cryptographic protocols, please reach out via email: .