We measure the pipe, not what goes through it.

Helix exists to tell you how good your connection is. That needs timing and loss data about probe packets we send ourselves. It does not need — and does not collect — anything about what you do online.

The short version

What is collected, and what is not.

Collected

  • Round-trip timings, loss counts and loss-run lengths for probes Helix sends
  • Outage spans and the fault domain concluded for them
  • DNS resolution timings and failures
  • Total bytes in and out per connection, for usage and quotas
  • Speed-test results, including the loaded-latency delta and bufferbloat grade
  • Traceroute and MTR hop addresses when you run a path analysis
  • Your public IP address, network operator and connection type, to identify which line a measurement belongs to
  • Network adapter details and Wi-Fi signal strength, for local diagnosis
  • Which applications used the network, and how much — kept on your machine, and never uploaded
  • Once a day, a list of the names of the services this machine moved the most data to and from. This is on by default and there is a switch to turn it off; the section below says exactly what is in that list

Not collected

  • The content of anything you send or receive
  • Your browsing history — no page addresses, no times, no order, and nothing tied to you. The daily list of service names described below is deliberately none of those things
  • How much data went to any particular service, or when. Volume decides which names make this machine’s list; it never leaves with them
  • Which application talked to which service. Both are measured on your machine and neither is uploaded
  • The addresses, names or hardware identifiers of other devices on your network. Helix reads your machine’s own neighbour table to list what is on the network for you, and none of it is uploaded
  • Any packet Helix did not send itself — there is no traffic capture and no packet inspection
The daily list of service names

A list of names, and the reasons it is only that.

Helix publishes rankings of how well the hosts the internet runs on are actually serving it, measured from probe boxes Helix operates. Deciding which hosts are worth measuring is a separate question, and the machines running the monitor are the only honest way to answer it. So once a day the agent sends a short list of the services it moved the most data to and from.

A list of the addresses a machine connected to is browsing history, and it does not stop being browsing history because it is added up later or because the application name is dropped. That is the problem this design starts from, and every choice below exists to answer it.

What is in the list

  • A registrable domain, such as example-cdn.net, where a reverse lookup answers
  • A network block, such as 104.18.32.0/24, where no name answers
  • The date, to the day

What is not, and cannot be added later

  • Byte counts. Volume ranks the list on your machine and stays there — how much you moved to a given service identifies you far more than the fact you reached it
  • Times of day, or any timestamp finer than the date
  • Application names
  • Individual addresses, full paths, or anything from a URL
  • Anything at all that ties a name to the machine that sent it

Four things that make it safe to publish

The list is built on your machine
The names are generalised before anything is sent, because a rule applied after the fact protects nothing that has already left. The cloud independently refuses anything that arrives un-generalised, since a receiver that trusts its sender to have redacted will store whatever it is sent.
Rare services are dropped entirely
Anything below a volume floor never enters the list. This is the strongest privacy filter here and it is worth saying why: the unusual services — the ones that would actually describe somebody — are almost always the small ones.
Nothing is published below five contributors
A service is only counted once at least five different machines have named it, so nothing you alone reach can appear. Below that floor a service is absent rather than anonymised: an unnamed entry with two contributors is still a disclosure.
Contributors are counted without being kept
To count machines rather than submissions, the cloud keeps a one-way fingerprint of device, service and day, deletes it after two days, and never reads it back. Reversing one would require already knowing the device and the service — it can confirm a guess, and it cannot produce a list.

It is on by default, and off is one click. Open Settings and choose What this machine shares. The panel states what is being sent before it offers the switch, and it says plainly when the machine is contributing because nobody has been asked rather than because somebody agreed.

Where it goes

Three destinations, and you control the second and third.

  1. Your machine, always

    Everything is written to a local database under %PROGRAMDATA%\Helix first. With no account and no network, Helix is fully functional. Uninstalling deliberately leaves that folder alone; delete it yourself if you want it gone.

  2. The Helix cloud, only after you enrol the device

    Sync is off until you paste a device token into the app. From then on, measurement windows upload so you have history across devices. Turn it off and uploading stops immediately — no restart, no delay.

  3. Your ISP, only if you link and share

    A separate, explicit decision on top of having an account. It is per-link and per-connection, and it is off until you turn it on.

Third parties the agent contacts by design. To measure anything, Helix has to send packets somewhere. By default it probes your own router plus three public resolvers run by different operators — Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9). Three operators, so one of them having a bad day is not mistaken for your line having one. Speed tests run against Cloudflare’s speed-test endpoints. Those providers see the connections, as they would from any device on your network.

IP addresses

Treated as personal data, because they are.

Short-lived where it is identifying

Your public IP is a connection attribute with a short life. The long-lived analytical record keeps the network operator and a coarse region, not the address itself — because what the analysis needs is “which ISP, roughly where”, and that is a much weaker identifier.

Redaction before publishing

A diagnosis report contains your IP, your ISP and the hostnames along the path. If you publish one, you are shown what it contains and can mask the last part of your public IP and hide hostnames — and the redaction is applied before the upload, not by hiding fields in the viewer afterwards.

Published reports

A published report lives at an unguessable link, is rate-limited, is marked not to be indexed by search engines, and can be revoked at any time. You can set it to expire.

Path hop countries are registry data

Each hop in a path analysis is annotated with the network that owns it and the country that network is registered in. That is not geolocation and it is not where the equipment is. We label it as registry country so nobody reads it as a location.

ISP sharing

Two gates, and both fail closed.

Sharing with an ISP is not one switch with a permission attached. It is two independent questions asked on every single read, and either one saying no means nothing is returned.

Gate one: consent

Did you turn sharing on for this link, and have you not withdrawn it? This is a live condition in the query itself, not a flag checked once and cached. There is nothing to expire and no job to wait for.

Gate two: scope

Which of your connections may this particular ISP see? For an ISP that operates its own network, that is the connections on their network. For a reseller or a carrier-grade-NAT operator without one, it is only the connection you explicitly pinned to them — and if you pinned nothing, they get nothing.

What they see

Latency, packet loss, outages and speed tests for the shared line, as counts and distributions over a window they choose, plus tickets you raised with them. They see your service ID because you gave it to them; they do not see your other connections, and there is no browsing or traffic data to see because none exists.

Their staff are limited too

Inside an ISP organisation, access is by capability rather than seniority. Their billing and CRM staff have no permission to read connection quality at all, because your consent was given for support purposes and a design that let a billing clerk browse your history would be a failed design.

Revocation

Off means off, on the next query.

What happens immediately

Turn sharing off in the dashboard and the very next request your ISP makes returns nothing for you. You disappear from their subscriber list entirely — not greyed out, not marked as revoked. An ISP has no business knowing that somebody used to share with it.

Every consent and every revocation is recorded as an immutable event, so what you agreed to and when is answerable.

Copies outside Helix

Telemetry is read from Helix per service and time-bounded. It is deliberately never bulk-exported into a database the ISP operates, because the moment a copy lives there, revocation stops being something the code enforces and becomes something a contract promises.

Where an ISP has legitimately retained something — a report you attached to a ticket, for instance — deletion is a contractual obligation on them, not a technical guarantee we can make on this page.

Retention

Raw measurements are kept 45 days. For everyone.

One policy, not three

The storage-limitation policy for raw telemetry is a uniform 45 days on every tier, free included, applied by an automatic sweep. The 3-, 30- and 45-day tiers are access entitlements: how far back the service will serve you. They are not deletion schedules and we never describe them as such — not to users and not to regulators.

The uniform window is not chosen separately from those tiers — it is the largest of them, read from the same table in code. It cannot drift below what a plan promises, because a test refuses to build a version where it has.

That is also why upgrading is instant rather than starting a new collection.

Summaries and account deletion

Downsampled summaries persist while your account is active and are deleted with the account. Delete the account and the local database on your machine is still yours — it is not reached by anything the cloud does, and you remove it by deleting the folder.

Data requests: [email protected]

This website

The site you are reading is not the product.

Everything above describes the Helix Internet Monitor software. This section is about helixaicloud.com itself, which is a different thing with different visitors, and it would be a strange omission on a page like this one.

Two third parties run on these pages

Secure Privacy provides the consent banner, and Google Analytics measures which pages people read. Both are loaded from their own servers, so both see your IP address and your browser’s user agent, as any embedded script does.

The consent manager loads first, deliberately. It decides whether the analytics tag is allowed to run, which only works if it is running before the tag rather than beside it.

What that is used for

Aggregate readership: which pages are found, which are read to the end, which are never reached. It is how a documentation page that nobody can find gets discovered and fixed.

It is not connected to your Helix account. Signing in happens on a different host, and nothing here is joined to a subscriber record.

Downloads are counted

When you download the installer, the request passes through a Helix-operated endpoint that records the time, the version, a coarse location derived from the address, and the address itself. That serves two purposes and only two: knowing how many people are running which version, and rate-limiting abuse of the download.

It is kept for 45 days, the same uniform window as everything else in this product, and then deleted. Why 45 days →

Your choice actually applies

Decline in the consent banner and the analytics tag does not run. You can change your mind from the banner’s control at any time.

The download counter and its rate limit are not analytics and are not covered by that choice: they are the operational record of a file transfer you asked for, in the same way a web server logs a request. We would rather say that plainly than bury it.

Being straight about it

What we are not claiming.

This page describes what the software does. It is not a legal notice and it does not assert a certification, because none has been earned.

  • No compliance certification is claimed. Independent audit is on the roadmap ahead of general availability of the ISP platform; it has not happened.
  • Refresh tokens do not yet have reuse detection. A stolen session token stays valid for up to 30 days. That is acceptable for a controlled pilot and it is not acceptable for general availability, which is why it is written here.
  • The installer is not code-signed, so you cannot currently verify the publisher of the binaries by their signature. Compare the published checksum instead.
  • EU data residency is designed for and not yet offered. Ask us where your data sits before you assume.

Questions before you install?

The download page is equally blunt about what happens on your machine, and the docs walk through every step where you are asked to consent to something.