Skip to main content
HEMELION
Legal

Privacy Policy

Last updated: August 1, 2026

1. Controller

The controller is Gökhan Vodinali, Gäbelbachstrasse 39, 3027 Bern, Schweiz. Privacy requests may be sent to support@hemelion.com.

2. Data processed

  • Scan content: answers, option labels, decision titles, and response timings submitted during Clarity or MindScan. MindScan includes free-text descriptions of one concrete situation, the first observable response, its reported immediate effect, its reported later effect, and a proposed counter-move. Do not enter names or unnecessary sensitive details.
  • Session data: a random scan identifier and signed, expiring access tokens stored in an essential HttpOnly cookie or report link.
  • Recoverable browser draft: while a scan is unfinished, its answers, decision title or option labels, timing data, scope confirmation, and random scan identifier are also stored in this browser's local storage. This lets the scan survive navigation or a refresh; it is not used for advertising or cross-site tracking.
  • Payment references: Stripe checkout session identifiers, payment status, amount, and currency. Hemelion does not store full card numbers.
  • Private evidence workspace: optional context, trigger-action-outcome notes, counter-move use, observable outcome, usefulness, and whether the original working model was supported, weakened, disconfirmed, or not yet testable. These records remain attached only to the private report.
  • Technical data: request metadata needed for security, rate limiting, error diagnosis, and infrastructure operation, which may include IP address and user-agent information in short-lived platform logs.
  • Product-use events: privacy-minimized events such as page viewed, scan started, preview viewed, checkout started, and anonymous report usefulness feedback, associated with a random first-party session identifier. To understand which countries and channels make the product journey work, a page-view event may also include the two-letter country code supplied by the hosting network, a broad acquisition category, fixed non-identifying source, medium, and campaign labels selected for Hemelion-created links, a known referrer category, and whether the browser was deliberately marked as internal testing traffic. Unknown campaign labels are discarded. Hemelion does not store a city, precise location, full referring URL, search query, or conversation in these events. Scan answers, report links, names, email addresses, IP addresses, and payment identifiers are not stored in these events. If a visit arrives from a supported AI assistant, Hemelion records only the assistant category and landing-page path—not the referring URL, query, or conversation.
  • Aggregate web analytics: on public pages, Vercel Web Analytics may process the event time, filtered page or route, referring page, approximate city, region, and country, device type, operating system, and browser. Vercel reports this information in anonymized aggregate form, does not use analytics cookies, and resets its request-derived visitor hash after 24 hours. Hemelion excludes private paths, including admin, account, sign-in, checkout return, beta outcome, report, follow-up, handoff, perspective, growth, and referral-dashboard pages. It removes URL fragments and all query parameters except fixed, non-identifying source, medium, and campaign labels. Private Hemelion pages also send no referrer when navigating away.
  • Beta applications: name, email address, product interest, the challenge you choose to describe, baseline clarity and confidence ratings, and separate contact and optional case-study interest choices. Selected participants may later submit outcome ratings and written critical feedback through a private link. Applicants should not include sensitive identifying details.
  • Pro and team pilot applications: name, work email, role, organization where applicable, professional context, proposed voluntary use case, expected monthly volume, organization size, budget range, intended start window, paid-program readiness, contact consent, and the application's review status. Applications are reviewed manually and are not a marketing-list signup.
  • Embedded tools: free tools may appear on a third-party website. Inputs are processed in the browser and are not sent to Hemelion; a privacy-minimized embed-loaded event may be counted. An approved publisher may provide a short, non-identifying source label so Hemelion can count which integration produced a visit. Hemelion does not receive the entered text, require third-party cookies, or fingerprint visitors across publisher sites.
  • AI-client and public API tools: A compatible AI client or API caller sends the structured arguments required by the selected function. A native Clarity map may include a decision, two or three option labels, priorities, and user-supplied ratings or indicators. A native MindScan map includes five user-supplied fields about one concrete episode and, for the current method, recurrence history, counterexample status, and a comparison target. Routing, readiness, methodology, and short-lived handoff tools use smaller inputs. The tool schemas do not request the full surrounding conversation, an AI-account identity, private Hemelion scans or reports, payment data, or contact details. Do not include names, health data, or unnecessary sensitive details in tool arguments. A signed handoff contains only product choice, language, integrity, and expiry and expires after 15 minutes.
  • Optional external-AI summary: an unlocked report can display a reduced, versioned working model without raw answers, the full narrative, report URL, account data, payment data, or internal identifiers. It is shown for review and copied only after the report owner ticks a confirmation box. Hemelion does not transmit it to an external assistant or grant future access.

3. Purposes and legal bases

Data is processed to save the scan, create and deliver a purchased report, verify payment, measure whether the product journey works, improve the service, prevent abuse, maintain service security, provide support, and meet legal obligations. Depending on your location, the legal bases may include performance of a contract, legitimate interests in secure service operation and product improvement, and compliance with law.

Public MCP and REST tool arguments are processed only to validate the request, calculate and return the requested deterministic result, apply security and rate limits, or create a short-lived handoff. They are not used to create a profile, train Hemelion models, advertise, or unlock a paid service. Copying a reduced report summary remains a local browser action initiated by the report owner.

4. Service providers

Hemelion uses specialized processors only as needed to operate the service:

  • Vercel for hosting, delivery, and operational logs, and for cookie-free aggregate Web Analytics on public pages.
  • Supabase for server-side storage of scan attempts and reports.
  • Stripe for checkout, payment verification, receipts, fraud prevention, and payment support.
  • OpenAI, only when website-report enhancement is enabled, to process relevant scan content for narrative generation. If unavailable, Hemelion uses a deterministic fallback. Public native MCP and REST maps are not sent by Hemelion to OpenAI.

When you call Hemelion through ChatGPT, Claude, Gemini, or another third-party AI client, that provider handles the surrounding conversation under its own terms and privacy policy. Hemelion receives only the structured tool request sent to its endpoint. Native Clarity and MindScan mappings are calculated by Hemelion without forwarding those arguments to an external model provider.

Hemelion does not sell scan data or use it for third-party advertising.

5. Retention

An unpurchased scan attempt is retained for up to 90 days from the start of the scan. If a report is unlocked, that scan, its report, context observations, and 7/14/30-day follow-ups are retained for up to 90 days from the unlock. The private report link works only while the underlying record remains within that period. Expired records are blocked immediately and removed through scheduled and routine cleanup. Payment providers may retain transaction records for their own legal and compliance periods.

Before a record is removed, it is counted into a monthly aggregate: calendar month, product, report provider, checkpoint, and the number of scans and follow-up verdicts in each. That aggregate carries no scan identifier, no report content, no free text, and no timestamp finer than the month, so it cannot be traced back to a person or a scan. It exists so a published research figure stays checkable after the underlying records are gone — which is also why nothing more detailed is kept.

An unfinished browser draft is no longer restored after seven days and is deleted on the next relevant Hemelion scan or checkout visit. It may be removed earlier when the matching report is opened after access has been granted, or when the browser rejects or clears local storage. The scan's Clear draft action also deletes the matching unpurchased server record; it refuses to delete a scan linked to checkout, access, or a report. Opening a different report does not remove another scan in progress. Browser storage and the server-side 90-day record are otherwise separate.

Founding-cohort applications are retained for up to 180 days and then removed through scheduled cleanup. Associated outcome feedback follows the same maximum period. Applying does not add the applicant to a marketing list, and case-study interest or optional quote permission is not consent to publish a name, report, or identifying detail.

Pro and team pilot applications are retained for up to 180 days unless an active commercial engagement or legal obligation requires a documented longer period. Declined or inactive applications are removed through scheduled cleanup.

Public MCP and REST tool arguments and results are not stored in Hemelion's product database. They are processed transiently to return the result. A one-way request-key hash may be retained temporarily for rate limiting, and hosting providers may retain limited security and operational logs under their own controls. The chosen AI-client provider controls its copy of the surrounding conversation and tool call under its own privacy policy.

6. Cookies and tracking

Hemelion uses an essential HttpOnly cookie to associate the current browser with a scan and a separate random first-party session identifier to calculate aggregate funnel and acquisition metrics. Neither is used for advertising or cross-site tracking. Product-use events are retained for up to 90 days. A Hemelion operator or tester may deliberately set a first-party local-storage marker that classifies that browser's subsequent page views as internal traffic; the marker contains no identity and is deliberately sticky for that browser's analytics session. Public pages also load Vercel Web Analytics, which uses no analytics cookies and an anonymous visitor hash that resets after 24 hours. Hemelion uses it only for aggregate traffic measurement, not advertising or tracking across websites. The application does not intentionally load third-party advertising cookies or cross-site behavioral analytics scripts.

Hemelion also uses first-party local storage for the seven-day recoverable scan draft described above. Unlike the HttpOnly access cookie, this storage contains the unfinished inputs needed to restore the form and remains on that device until the matching report opens, it is removed on a relevant visit after seven days, or browser data is cleared.

7. International processing

Infrastructure providers may process data in countries outside your residence. Where required, transfers are protected through recognized safeguards such as adequacy decisions or contractual protections provided by the relevant processor.

8. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may lodge a complaint with a competent supervisory authority. Include the secure report link or Stripe receipt ID so the record can be located without an account email.

9. Security and contact

Hemelion uses encrypted transport, server-only integration keys, signed access tokens, Stripe signature verification, and restricted database access. No internet service can guarantee absolute security.

Questions or deletion requests may be sent to support@hemelion.com.