Privacy Policy
How HelioCad collects, uses, shares and protects personal information, and the choices you have.
Effective August 15, 2026 · Applies to heliocad.com and app.heliocad.com
At a glance
- We collect what you give us (account details; the designs, prompts, photos and files you create or upload; support messages) and what the service records as you use it (usage, sign-in and security logs).
- Analytics on heliocad.com and app.heliocad.com is a first-party page-view beacon: no advertising networks, no cross-site cookies, no third-party analytics service. In the EU, EEA, UK and Switzerland it runs only if you accept; elsewhere it runs by default and you can turn it off. A Global Privacy Control signal turns it off everywhere.
- Your sign-in session lives in your browser's local storage, not in a cookie. The only cookies we set hold your consent choice and a two-letter country code. Full list in the Cookie & Storage Notice.
- By default we may use your AI interactions (prompts, generated code, viewport screenshots, uploaded scans) to improve HelioCad's AI. Turn this off any time under Account → Privacy in the app.
- We share data only with the service providers listed below (payments, email, CDN and bot protection, hosting, AI model providers). We do not sell or share personal information and use no advertising networks.
- You can access, export, correct or delete your data. Use Account → Privacy in the app or email privacy@heliocad.com.
Who we are
HelioCad operates heliocad.com (this website), app.heliocad.com (the CAD application) and engine.heliocad.com (the API behind it) and is the data controller, meaning the business responsible, for the personal information described in this policy.
HelioCad, Michigan, United States. Privacy contact: privacy@heliocad.com. General support: the contact form.
We have not currently appointed a representative in the EU or the UK.
What we collect
We collect only what the service needs. The categories below cover both the website and the application.
| Category | What it includes | Source |
|---|---|---|
| Account | Email address, first and last name, password (stored as a hash by our authentication service), plan and trial status, team membership, and the choices you make about legal terms, cookies and AI training. | You; the service |
| Content you create or upload | CAD projects and files, sketches, parameters and drawings; AI chat prompts and replies, generated code and explanations; viewport screenshots taken during AI turns; photos and phone captures for Photo Draft and Scan-to-CAD; uploaded meshes and image-to-3D inputs and outputs; public view and AR share links; comments; machine, tool, post-processor and laser settings. | You |
| Billing | Plan, subscription status, invoices and payment history, and your Stripe customer reference. Card details are entered on Stripe's hosted checkout and never reach our servers. | You; Stripe |
| Support | Name, email, subject, message, topic and reference number when you contact us; follow-up messages; feedback sent from the app. | You |
| Usage and analytics | Per page view: a pseudonymous visitor hash derived from your IP address, browser string and the current date (it changes every day and the raw values are not stored with the event); a random session ID kept in your browser for 30 minutes; page URL with query strings removed except utm_ campaign tags; referring site without its query string; browser and OS family; device type; screen width; country; and a yes/no flag for whether this browser has visited before. On the sign-up and sign-in pages, the outcome of the bot check (passed, showed a checkbox, or failed) — an outcome name only, with no form contents. For signed-in users: last-seen time, time in the app and session counts, and feature and AI usage counts and credits. | Your browser; the service |
| Sign-in and security records | IP address and browser string in sign-in and session records and server logs; rate-limit counters; Cloudflare Turnstile bot checks on sign-in and sign-up (your IP address is sent to Cloudflare); an audit log of support access to your account. | Your browser; the service |
| Device storage | Cookies, localStorage, sessionStorage and IndexedDB entries, each listed with its purpose and lifetime in the Cookie & Storage Notice. | Your browser |
We do not collect precise location, biometric, health, financial account or government ID information. We do not use social sign-in.
How we use it, and the legal bases
The legal basis column applies where the GDPR or UK GDPR governs (EU, EEA, UK). Article numbers refer to the GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the service | Account, content, usage: sign you in, store and render your projects, run AI features, exports, sharing links and team workspaces. | Contract (Art. 6(1)(b)) |
| Billing and trials | Account, billing. | Contract; legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Service email | Account, support: password resets, trial notices, receipts, support ticket confirmations and replies, team invitations. We send no marketing email. | Contract; legitimate interests (Art. 6(1)(f)) |
| Analytics | Usage: count visits, see which pages and features matter, find problems. | Consent in the EU, EEA, UK and Switzerland (Art. 6(1)(a)); legitimate interests with an opt-out elsewhere |
| Improve HelioCad's AI | Content: AI interactions as described under AI features and training. | Legitimate interests (Art. 6(1)(f)), with the right to object at any time (the opt-out toggle) |
| Security and abuse prevention | Sign-in and security records: rate limiting, bot protection, fraud and abuse detection, audit of support access. | Legitimate interests; legal obligation |
| Support | Support, account, and (when you ask us to look) your projects and chats. | Contract; legitimate interests |
| Legal compliance and enforcing our terms | Any of the above, as required. | Legal obligation; legitimate interests |
We do not use your data for advertising, do not build advertising profiles, and do not make decisions about you with legal or similarly significant effects by automated means.
AI features and training
When you use an AI feature, your prompt, the project context needed to answer it (such as the current model code, dimensions or a viewport image) and any photos, scans or files you provide are sent to the AI model that answers the request. That is either a model we run on our own GPU servers or a third-party AI model provider acting on our behalf. Providers process the request to produce the response and are described under Sharing.
We may use your AI interactions (prompts, generated code and explanations, retries, viewport screenshots taken during AI turns, and scan meshes) to improve HelioCad's AI: to fine-tune the models we run ourselves, to build evaluation sets, and to curate design knowledge that helps future requests. This is on by default.
You can turn it off any time under Account → Privacy in the app. Capture stops immediately, and records already captured are deleted on request or when you delete your account. Training datasets that have already been exported, design knowledge already derived from your interactions and made available to other users, and models already trained are not recalled.
Screenshots and scans captured for this purpose are stored in private storage tied to your account. Access by our team is limited to what operating the service requires and is logged.
International transfers
We are based in the United States and process data there. If you are in the EU, EEA, UK or Switzerland, your data is transferred to the United States. Our US providers (Stripe, Resend, Cloudflare and Vercel) offer data processing terms that incorporate the EU standard contractual clauses and the UK addendum, and we rely on those.
AI requests answered by a third-party model provider are sent to that provider, which may be in the United States or another country, because the transfer is necessary to deliver the AI response you asked for. If you would rather not have prompts, code or images processed by a third party, you can use HelioCad without its AI features.
How long we keep it
| Data | Kept for |
|---|---|
| Account, projects, files and settings | While your account is active. Deleted when you delete your account or ask us to, except the records listed below. |
| Analytics page-view events | 13 months (400 days). |
| Account activity and time-in-app sessions | 24 months. |
| AI training records (prompts, code, screenshots, meshes) | Until you turn training off and ask us to delete them, or delete your account. |
| Image-to-3D conversion jobs and outputs | 180 days. |
| Phone-capture photos | The capture session expires after 15 minutes; photos are removed within a day after that. |
| Support tickets and messages | About 3 years, as business records. When automated account deletion completes, ticket text and personal details are removed; only a minimal receipt remains. |
| Billing records (invoices, payments) | 7 years, for tax and accounting. |
| Sign-in and security records | Sign-in records per our authentication service defaults; server logs about 90 days. |
| Consent records (cookie choices, AI-training choice, terms acceptance, privacy requests) | Kept as a compliance record. After account deletion the record no longer contains your email or account ID. |
| Backups | Short-lived; overwritten on a rolling basis. |
| Third parties | Stripe, Resend, Cloudflare and Vercel retain data under their own policies. |
Your rights
If you are in the EU, EEA, UK or Switzerland you have the right to access your data, correct it, have it erased, restrict or object to its processing (including processing based on our legitimate interests, such as AI training and rest-of-world analytics), receive a copy in a portable format, and withdraw consent at any time without affecting what was done before. You can also complain to your supervisory authority. We offer the same rights to everyone, wherever you live.
How to use them:
- In the app: Account → Privacy lets you download your data, delete your account, turn AI training off, and change cookie and analytics choices.
- By email: write to privacy@heliocad.com from the address on your account. We verify requests by that email and may ask you to confirm from it.
- On any page: the Privacy choices link in the footer changes your cookie and analytics choice.
We respond within one month, or up to three months for complex requests, in which case we will tell you. Deleting your account removes your profile, projects, files, AI interaction records and stored images; billing records and support tickets are kept as described under retention, with your name and email removed from tickets. If you own a team workspace, transfer or delete it first.
California notice at collection (CCPA/CPRA)
This section is our notice at collection and privacy policy disclosure for California residents under the California Consumer Privacy Act as amended by the CPRA. We extend these rights to everyone; this section uses the law's own categories.
| Category | What we collect | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email address, account ID, IP address, pseudonymous visitor hash. | Provide the service, security, billing, support | Stripe, Resend, Cloudflare, Vercel (service providers) |
| Customer records (Cal. Civ. Code 1798.80(e)) | Name, email, billing status. No card numbers. | Billing, support | Stripe, Resend |
| Commercial information | Plan, subscription, purchases, credits. | Billing | Stripe |
| Internet or network activity | Pages viewed, features used, referring site, device type, sign-in records, server logs. | Analytics, security, improving the service | Cloudflare, Vercel (hosting logs) |
| Geolocation | Country only, derived from your connection. | Choosing the right consent model, analytics | None beyond the CDN that derives it |
| Audio, visual or similar | Photos, phone captures and scans you provide; viewport screenshots the app takes during AI turns. | Provide AI features, improve the AI | AI model providers (when part of an AI request) |
| Sensitive personal information | Account login credentials (email and password) only. | Signing you in and securing your account | None |
| Inferences | An internal engagement level derived from your activity. No advertising profiles. | Running and improving the service | None |
| Not collected | Protected classifications, biometric information, precise geolocation, professional or employment information, education information. |
Sources: you, your browser or device, and Stripe (payment status). Retention: per category as set out under How long we keep it.
We do not sell or share personal information, have not done so in the preceding 12 months, and do not offer financial incentives in exchange for personal information. We do not use or disclose sensitive personal information for purposes beyond signing you in and securing your account, so the right to limit does not apply. We do not knowingly collect information from anyone under 13 and do not sell or share the personal information of any consumer, including consumers under 16.
Your rights: to know and access the categories, sources, purposes and specific pieces of personal information we hold; to delete it; to correct it; to opt out of sale or sharing (not applicable, we do neither); to limit use of sensitive personal information (not applicable); and not to be discriminated against for exercising any right.
How to submit a request: email privacy@heliocad.com, or use Account → Privacy in the app (download my data, delete my account). We verify requests by matching the email address on your account and may ask you to confirm from that address; signed-in requests from the app are treated as verified. An authorized agent may submit a request on your behalf with your signed permission; we may still ask you to confirm your identity directly. We respond within 45 days, and may extend once by a further 45 days with notice.
Opt-out preference signals: we honor Global Privacy Control as a valid opt-out request. When your browser sends it, analytics is switched off automatically and the Privacy choices dialog (footer of every page, and Account → Privacy in the app) shows "Opt-out preference signal honored". Because we do not sell or share personal information, the signal has no further effect.
Shine the Light: we do not disclose personal information to third parties for their own direct marketing purposes.
Do Not Track and Global Privacy Control
We honor both signals. Our servers discard page-view beacons that arrive with a DNT: 1 or Sec-GPC: 1 header, and a Global Privacy Control signal also switches analytics off in your browser, locks the analytics switch, and shows "Opt-out preference signal honored" in Privacy choices. Neither signal changes anything else, because we do not track you across other sites or sell or share personal information.
Children
HelioCad is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child has created an account, email privacy@heliocad.com and we will delete it. We do not sell or share anyone's personal information, including that of consumers under 16.
Security
Traffic is encrypted in transit with TLS. Data is encrypted at rest on infrastructure we operate. Passwords are hashed by our authentication service and payment card details never touch our servers. Access to production systems is limited to the HelioCad team, and when a team member opens your projects or chats to help with a support request or investigate a problem, that access is recorded in an audit log. No system is perfectly secure; if a security incident affects your data we will notify you as the law requires.
Changes to this policy
We will email account holders at least 30 days before a material change takes effect and update the effective date at the top of this page. Earlier versions are available on request.
Contact
Questions, requests or concerns: privacy@heliocad.com, or the contact form. Postal: HelioCad, Michigan, United States.
If you are in the EU, EEA or UK and are not satisfied with our response, you can lodge a complaint with your local data protection authority.