HEMELION
Legal

Privacy Policy

Last updated: July 22, 2026

1. Controller

The controller is Gökhan Vodinali, Gäbelbachstrasse 39, 3027 Bern, Schweiz. Privacy requests may be sent to g.vodinali@gmail.com.

2. Data processed

  • Scan content: answers, option labels, decision titles, and response timings submitted during Clarity or MindScan.
  • Session data: a random scan identifier and signed, expiring access tokens stored in an essential HttpOnly cookie or report link.
  • Payment references: Stripe checkout session identifiers, payment status, amount, and currency. Hemelion does not store full card numbers.
  • Technical data: request metadata needed for security, rate limiting, error diagnosis, and infrastructure operation, which may include IP address and user-agent information in short-lived platform logs.
  • Product-use events: privacy-minimized events such as page viewed, scan started, preview viewed, checkout started, and anonymous report usefulness feedback, associated with a random first-party session identifier. Scan answers, report links, names, email addresses, IP addresses, and payment identifiers are not stored in these events. If a visit arrives from a supported AI assistant, Hemelion records only the assistant category and landing-page path once per browser session—not the referring URL, query, or conversation.
  • Beta applications: name, email address, product interest, the challenge you choose to describe, baseline clarity and confidence ratings, and separate contact and optional case-study interest choices. Selected participants may later submit outcome ratings and written critical feedback through a private link. Applicants should not include sensitive identifying details.
  • Embedded tools: free tools may appear on a third-party website. Inputs are processed in the browser and are not sent to Hemelion; a privacy-minimized embed-loaded event may be counted.

3. Purposes and legal bases

Data is processed to save the scan, create and deliver a purchased report, verify payment, measure whether the product journey works, improve the service, prevent abuse, maintain service security, provide support, and meet legal obligations. Depending on your location, the legal bases may include performance of a contract, legitimate interests in secure service operation and product improvement, and compliance with law.

4. Service providers

Hemelion uses specialized processors only as needed to operate the service:

  • Vercel for hosting, delivery, and operational logs.
  • Supabase for server-side storage of scan attempts and reports.
  • Stripe for checkout, payment verification, receipts, fraud prevention, and payment support.
  • OpenAI, when report enhancement is enabled, to process relevant scan content for narrative generation. If unavailable, Hemelion uses a deterministic fallback.

Hemelion does not sell scan data or use it for third-party advertising.

5. Retention

Scan attempts and generated reports are retained for up to 90 days from the start of the scan. Access tokens expire within that period. Expired records are blocked immediately and removed through scheduled and routine cleanup. Payment providers may retain transaction records for their own legal and compliance periods.

Founding-cohort applications are retained for up to 180 days and then removed through scheduled cleanup. Associated outcome feedback follows the same maximum period. Applying does not add the applicant to a marketing list, and case-study interest or optional quote permission is not consent to publish a name, report, or identifying detail.

6. Cookies and tracking

Hemelion uses an essential HttpOnly cookie to associate the current browser with a scan and a separate random first-party session identifier to calculate aggregate funnel metrics. Neither is used for advertising or cross-site tracking. Product-use events are retained for up to 90 days. The application does not intentionally load third-party advertising cookies or cross-site behavioral analytics scripts.

7. International processing

Infrastructure providers may process data in countries outside your residence. Where required, transfers are protected through recognized safeguards such as adequacy decisions or contractual protections provided by the relevant processor.

8. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may lodge a complaint with a competent supervisory authority. Include the secure report link or Stripe receipt ID so the record can be located without an account email.

9. Security and contact

Hemelion uses encrypted transport, server-only integration keys, signed access tokens, Stripe signature verification, and restricted database access. No internet service can guarantee absolute security.

Questions or deletion requests may be sent to g.vodinali@gmail.com.