Last updated: August 18, 2026
This Privacy Policy explains how GoHelix (“we,” “us”) collects, uses, and discloses information when you use our scraping API, dashboard, and website (the “Service”).
Account data: name, email, company name, billing address, and payment details (processed by our third-party payment processor — we do not store full card numbers).
Usage data: API request logs, including request timestamps, target URLs submitted, response status, IP address, user agent, and API key used. This is used for billing, rate-limiting, abuse detection, and debugging.
Scraped content: By default, we process the content of the pages you request in order to return it to you. In the current implementation, that content is not stored after it is returned — your request is proxied to the underlying scraping infrastructure and the response is passed straight back to you, without GoHelix retaining a persistent copy of the page content itself.
Technical data: cookies and similar technologies on our website/dashboard for authentication and analytics (see Section 6).
Communications: support tickets, emails, and other correspondence you send us.
We use collected information to: provide and maintain the Service; process payments and manage subscriptions; monitor for abuse, fraud, and violations of our Terms of Service; enforce rate limits and quotas; provide customer support; send service-related notices (e.g., billing, downtime, policy changes); and improve and debug the Service. We do not sell your personal data.
Where GDPR applies, we process personal data on the basis of: performance of a contract (providing the Service you signed up for), legitimate interests (fraud prevention, service improvement, security), and legal obligation (tax and accounting records).
We share information with service providers who help us operate the Service, including: cloud hosting providers, payment processors, the infrastructure/proxy providers used to route scraping requests, and analytics/error-monitoring tools. These providers are bound by confidentiality and data protection obligations. We do not share your account data with third parties for their own marketing purposes.
Account data is retained for as long as your account is active and for a reasonable period after closure for legal, tax, and dispute-resolution purposes.
In the current implementation, request metadata used for rate-limiting (IP address, timestamp, endpoint called) is held only in memory for a rolling 24-hour window and is not written to a persistent database — it clears automatically on its own and whenever the service restarts. We do not currently retain scraped page content at all (see Section 1). If GoHelix introduces persistent request logging or content caching in the future (e.g., for billing history or performance), this section will be updated to reflect the actual retention period in place at that time.
Our website and dashboard use cookies for authentication (keeping you logged in), essential functionality, and aggregate analytics. You can control cookies through your browser settings; disabling essential cookies may affect dashboard functionality.
Depending on your location, you may have the right to access, correct, delete, or export your personal data, object to or restrict certain processing, and withdraw consent where processing is based on consent. To exercise these rights, contact us at privacy@gohelix.xyz. California residents have rights under the CCPA/CPRA, including the right to know what personal information is collected and to request deletion; we do not sell personal information as defined under CCPA.
Your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
We implement commercially reasonable technical and organizational measures (e.g., encryption in transit, access controls) to protect information. No system is completely secure, and we cannot guarantee absolute security of data transmitted to or from the Service.
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If we become aware that we have collected such information, we will delete it.
Content you scrape through the Service may itself contain personal data of third parties (e.g., individuals mentioned on a target website). We act only as a data processor/conduit for such content passed through the API at your request — you, as the party determining the purpose of extraction, are the data controller responsible for ensuring your collection, storage, and use of that data complies with applicable privacy law.
We may update this Privacy Policy from time to time. Material changes will be notified via the dashboard or email, with the “Last Updated” date revised accordingly.
For privacy questions or to exercise your rights, contact us at privacy@gohelix.xyz.