Privacy Policy
Effective date: September 29, 2026.
This policy explains what personal data HeliEx collects when you use heliex.net, the swap pages (including swap-beta.heliex.net), support, our emails and our API. It also explains why we collect that data, who we share it with and how long we keep it.
HeliEx is responsible for the personal data described here. For privacy questions or requests, use the support ticket form at About → Support.
In short: you do not need an account or an email address to make a swap. For a swap we record your wallet addresses, amounts, a swap reference and the blockchain transactions, and we clear your IP address from the swap once it is more than 90 days old. Accounts need an email address. HeliEx deals only in GRC and CURE. We do not sell personal data.
This policy is written in English. Any translation is for convenience only, and the English text applies.
1. Swaps without an account
When you ask for a swap estimate or accept a swap, we record:
- Swap details: the coins, amount, receiving address, return address, your minimum, the estimate, the fees and the accepted terms, including their version.
- Swap reference: a short reference in the format HX-XXXX-XXXX-XX that identifies your swap, for example when you contact support. It is not your recovery link.
- Blockchain records: the deposit address we create for your swap, and the transaction IDs, amounts and confirmation counts of deposits, payouts and returns, including deposits sent after your swap has completed and the returns we make for them.
- Recovery link: we store only a one-way hash (SHA-256) of its secret, not the secret itself.
- IP address: your IP address is saved with each estimate and with the record of your acceptance. We use it for security, abuse investigations and limits. Cloudflare passes your IP address to us.
- A keyed hash of your IP address: a code made from your IP address with a secret key (HMAC), which cannot be turned back into the IP address without that key. We use it for per-visitor rate limits and swap limits. It is kept with each accepted swap.
- Short-lived request counters used for rate limiting. They expire after about two minutes and are then removed.
- Beta invites: a hash of your invite code, the label we gave the invite (which may include a name or handle), when the invite expires, and which swaps were started with it.
We do not ask for your name or email address for a swap. If you contact support about a swap, see section 3.
Blockchains are public. Addresses and transactions on the GRC and CURE blockchains are visible to anyone, permanently. HeliEx cannot delete or change them, and other people may be able to link them to you.
2. Exchange accounts
- Sign-up and sign-in: email address, password (stored only as a one-way hash), the dates you signed up and were last active, email verification status and sign-in method.
- Google or Microsoft sign-in (if you use it): we request your email address and basic profile ("openid email profile"; Microsoft also "User.Read"). We store your email address, the provider's name and your account ID with that provider.
- Two-factor authentication (2FA): your 2FA secret (encrypted) and backup codes (hashed).
- Settings: language, time zone, time format, notification and price-alert preferences, withdrawal email confirmation preference and rain eligibility.
- Financial records: coin balances and ledger entries, deposit addresses given to you, deposits and withdrawals (addresses, amounts, fees and transaction IDs), saved withdrawal addresses and their labels, orders, trades, faucet claims, rain rewards and donations.
- API keys: key ID, secret (encrypted), label, permissions, IP allowlist and when the key was last used.
- Browser push notifications (if you turn them on): the push address issued by your browser's push service, and its keys.
- In-site notifications about deposits, orders, the faucet and rain.
3. Support
- The support ticket form at About → Support asks for your email address, a subject and a message. For a swap, it also asks for your swap reference (HX-XXXX-XXXX-XX). We record your IP address with the ticket.
- We reply by email. Replies you send back by email are added to the same ticket.
- Our operators are told about new tickets and replies through our own self-hosted alert system. The alert includes your email address, the subject, the swap reference and the start of your message.
- Never send us your swap recovery link, passwords, 2FA codes or API secrets. HeliEx staff will never ask for your recovery link.
4. Security, abuse prevention and site statistics
- Security log: failed and successful sign-ins (including the email address entered and your IP address), API key changes, and linking an existing account to Google or Microsoft sign-in. Entries are deleted after 180 days.
- Faucet and rain limits: to limit how many accounts on one network can receive rewards, we store a keyed hash (HMAC) of your IP address (for IPv6, of its /64 network) with your account. Each entry stops counting after 24 hours (faucet) or 48 hours (rain).
- Visitor count: when you open a page, we store a one-way hash of your IP address (for IPv6, of its /64 network) with the first and last time we saw it. We use it only to count visitors.
- Server logs: our exchange server writes a log of the pages and API addresses requested, and of the recipient address and subject of each email it sends. It does not record your IP address, but page addresses can include one-time links, such as email verification and withdrawal confirmation links, which expire as described in section 7. This log is replaced when the server restarts. Our server also keeps a size-limited security-testing log of requests (time, account, IP address, method, address and result), in which the oldest entries are overwritten. The swap server does not write web access logs; its logs record swap IDs, timings and error types, not your IP address.
- Operator alerts: our operators receive alerts through our own self-hosted notification server. Account alerts (for example sign-ups, large deposits and withdrawals, filled orders, rain and support tickets) can include your account email address and amounts. Swap alerts contain swap IDs and references, coin amounts, transaction IDs and status, but not your IP address.
5. Why we use your data
- To run swaps and accounts: taking deposits, trading, payouts, returns (including returns of late deposits), withdrawals, the faucet and rain.
- To keep the service secure: sign-in protection, 2FA, CAPTCHAs, rate limits, swap limits, fraud and abuse checks, and investigating incidents.
- To keep accurate records of the coins we hold and to reconcile our wallets.
- To contact you: email verification, password resets, withdrawal confirmations, inactivity notices and support replies.
- To meet legal obligations that apply to HeliEx, and to deal with fraud or abuse.
6. Who we share data with
We use the following services:
- Cloudflare: network, security and delivery for heliex.net and swap-beta.heliex.net. All traffic to our sites passes through Cloudflare, including your IP address.
- Cloudflare Turnstile: Cloudflare's security check, used on sign-up, on sign-in after repeated failed attempts, on password reset, on faucet claims and on the support form. The swap page can also use it when that check is turned on. Cloudflare receives information from your browser when the check runs.
- Google and Microsoft: only if you choose to sign in with them.
- Twilio SendGrid: sends our emails, and receives the email replies you send to support.
- Browser push services (Google, Mozilla, Apple or Microsoft, depending on your browser): only if you turn on push notifications.
- Public blockchains: payouts, returns and withdrawals are published on the GRC or CURE network.
- Authorities: when the law requires it, or to deal with fraud or abuse.
Our operator alert system is self-hosted and run by HeliEx; it is not a third-party service.
Our pages link to block explorers (gridcoinstats.eu and chainz.cryptoid.info) and to coin websites. These are third-party sites with their own privacy policies. Our servers fetch public price data from other services without sending any of your data.
Where data is processed: the services listed above, such as Cloudflare, may process data outside the place where you live.
7. How long we keep data
Unless a shorter period is listed below, we keep records as long as needed to operate the service, keep accurate records of swaps and balances, resolve disputes and meet legal obligations. Today this applies, for example, to swap records (addresses, amounts, swap references and transactions), the keyed IP hash saved with accepted swaps, account ledger and transaction records, support tickets (including their IP address and swap reference), visitor-count hashes and database backups.
- IP addresses saved with swaps: cleared once they are more than 90 days old, during our routine clean-up.
- Swap recovery links: stop working 90 days after the estimate was made.
- Estimates you do not accept: expire after 60 seconds and are deleted, with their addresses and IP address, during our routine clean-up.
- Rate-limit counters: expire after about two minutes.
- Security log: 180 days.
- Password reset, email verification and withdrawal confirmation links: expire after 30, 60 and 30 minutes.
- Unverified accounts: accounts with password sign-in whose email address is not verified within 7 days are deleted. If the account has received coins or has other transaction records, we anonymize it instead, as for inactive accounts below, and keep those records and any balance.
- Inactive accounts: locked after 12 months without activity, and we send an email notice. 60 days after the notice, we anonymize the profile: we replace your email address, disable your password and delete your account deposit addresses and password reset tokens. Other records linked to the account, such as ledger, order, deposit and withdrawal records, support tickets and saved settings, are kept.
- Server logs: the exchange request log is replaced when the server restarts; the security-testing log is limited in size and overwrites its oldest entries.
8. Cookies and browser storage
HeliEx sets only the cookies it needs to run the site. We do not use advertising cookies. Cloudflare may set its own cookies needed for security.
__Host-session: keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, and lasts up to 24 hours.
__Host-twofa: a temporary cookie used during a 2FA sign-in. Lasts 5 minutes.
__Host-oauth_browser: links a Google or Microsoft sign-in to your browser. Lasts 10 minutes.
__Host-heliex_beta_invite: on the swap beta only, set when you open an invite link. It stores your invite code, is HttpOnly, Secure and SameSite=Strict, and lasts 30 days.
- Browser storage (localStorage) on the exchange: sign-in status, your account email address (for display), theme, language, time zone and time format, display preferences, notification settings and markers, and withdrawal defaults. This stays on your device and is not sent to us automatically.
- Swap page: the recovery secret is kept in the page address after "#", which browsers do not send to servers as part of the address. Opening the swap page itself sets no cookies. Some test modes may use temporary browser storage (sessionStorage).
9. Security
- Passwords and 2FA backup codes are stored as one-way hashes. 2FA secrets and API secrets are encrypted.
- Swap recovery secrets and beta invite codes are stored only as hashes.
- Sign-in cookies are Secure and HttpOnly. Our sites use HTTPS, a content security policy and a no-referrer policy.
- No system is perfectly secure. If we learn of a security incident that affects your personal data, we will take steps to deal with it and tell you where we are required to.
10. Your choices and requests
- You can ask to see, correct or delete personal data we hold about you, or ask a question about how we use it, through the support ticket form at About → Support.
- There is no self-service data export or account deletion today, so requests are handled by hand.
- For a swap without an account, give your swap reference. We may ask you to prove the swap is yours, for example by giving the deposit address and the deposit transaction ID. Do not send your recovery link. HeliEx staff will never ask for it.
- We may need to keep some records even after you ask us to delete them, for example ledger records and records we must keep by law. Blockchain data cannot be deleted by anyone.
11. Children
HeliEx is not directed at children, and we do not knowingly collect information about children.
12. Changes to this policy
We may update this policy. We will post the updated policy on this page and change the effective date above.
13. Contact
Contact HeliEx through the support ticket form at About → Support. For a swap, give your swap reference. Never send your recovery link, passwords, 2FA codes or API secrets.