back to legal hub

privacy policy

Helios Privacy Policy

Explains what information Helios collects, how it is used, protected, retained, and shared with connected applications.

Version v1.0Updated 9/9/2026

1. About Helios

Helios is a private identity and access management service operated by LoArt & Dev, a private group operating through loart.dev.

Helios is available at https://auth.loart.dev and provides authentication, account management, authorization, and access control for private applications and services made available to authorized members of LoArt & Dev.

Helios is operated for private, internal, and non-commercial use. It is not a public identity service, commercial service, or registered business. Accounts are not available for public registration and access is provided only to individuals who have been authorized to use the service.

This Privacy Policy explains what information Helios may collect, why it is collected, how it is used, how it may be shared with connected applications, and how it is protected.

The current version of this Privacy Policy is publicly available at:

https://loart.dev/legal/helios-privacy-policy

2. Information Helios Collects

Helios collects only information reasonably necessary to provide authentication, account management, security, and access-control functionality.

Depending on the features you use, this may include the following.

Account Information

Helios may store:

  • your name or display name;
  • your email address;
  • your unique Helios user identifier;
  • email verification status;
  • account creation and modification dates;
  • account status; and
  • other basic account settings.

Authentication Information

Helios may process or store information necessary to authenticate you, including:

  • password hashes;
  • multi-factor authentication configuration;
  • time-based one-time password (TOTP) authenticator information;
  • passkey or WebAuthn credentials;
  • recovery-code information; and
  • authentication-related security metadata.

Helios does not intentionally store passwords in plaintext. Passwords are processed using password-hashing mechanisms designed for credential storage.

Where recovery codes or similar authentication secrets are stored, Helios uses or attempts to use appropriate cryptographic protections rather than storing those secrets as readable plaintext.

Session and Device Information

When you use Helios, information may be recorded about your session or device, including:

  • IP address;
  • browser and user-agent information;
  • session identifiers;
  • login times;
  • session creation and expiration times;
  • authentication method;
  • recent activity; and
  • information used to identify or manage active sessions.

This information is used primarily to provide authentication functionality, manage sessions, investigate problems, and protect accounts from unauthorized access.

Security and Audit Information

Helios maintains security and audit records.

These records may include:

  • successful and failed login attempts;
  • account changes;
  • email verification activity;
  • password changes;
  • MFA changes;
  • passkey changes;
  • recovery-code activity;
  • session creation or revocation;
  • administrative actions;
  • role and permission changes;
  • application access changes; and
  • other security-relevant events.

These records are maintained to help detect problems, investigate unauthorized access, troubleshoot the service, and maintain the security and integrity of Helios and connected applications.

3. Roles, Permissions, and Application Access

Helios manages access to private applications and services operated by or made available through LoArt & Dev.

As part of this functionality, Helios may store information describing:

  • applications you are permitted to access;
  • roles assigned to your account;
  • permissions associated with those roles;
  • direct access grants;
  • access inherited through other roles; and
  • administrative privileges.

Application roles are scoped to the applicable application. Administrative access to one connected application does not necessarily provide administrative access to Helios or another connected application.

This information is used to determine and manage your access to Helios and connected services.

4. Information Shared With Connected Applications

Helios acts as an identity provider for certain private applications.

When you sign in to a connected application using Helios, Helios may provide that application with information necessary to identify you and determine your authorized access.

Depending on the application and permissions requested, this may include:

  • your Helios user identifier;
  • your name or display name;
  • your email address;
  • email verification status;
  • roles;
  • permissions; and
  • other identity or authorization claims required by that application.

Helios attempts to provide connected applications only with information appropriate for that application and its authorization requirements.

Connected applications do not automatically receive all information stored by Helios.

Authentication secrets such as password hashes, MFA secrets, recovery codes, private authentication keys, and similar credentials are not intended to be disclosed to connected applications.

5. How Information Is Used

Information collected by Helios may be used to:

  • create and maintain your account;
  • authenticate you;
  • verify your email address;
  • provide multi-factor authentication;
  • manage passkeys and other authentication methods;
  • maintain authenticated sessions;
  • determine which applications you may access;
  • determine your roles and permissions;
  • provide appropriate identity and authorization information to connected applications;
  • detect and prevent unauthorized access;
  • investigate security events;
  • maintain audit records;
  • troubleshoot technical problems;
  • send account and security-related communications; and
  • operate, maintain, and improve the reliability and security of Helios.

Personal information is not collected for advertising or behavioural marketing.

6. Email Communications

Helios may send transactional, account-related, or security-related emails concerning your account.

These may include:

  • email verification messages;
  • password reset messages;
  • password change notifications;
  • login or security notifications;
  • multi-factor authentication changes;
  • passkey changes;
  • recovery-related notifications;
  • account changes; and
  • other important account or security messages.

Helios does not use account email addresses for advertising or commercial marketing.

Transactional messages may originate from dedicated LoArt & Dev email infrastructure. This may include addresses or subdomains specifically used for transactional communications, such as addresses under transactional.loart.dev.

The specific sender address used by Helios may change as LoArt & Dev's email infrastructure evolves. Users should therefore not rely solely on a particular sender address as proof that a message is legitimate.

Helios will not intentionally request your password, MFA secret, recovery codes, or private passkey material by email.

An external email-delivery provider may process your email address, message contents, and related technical metadata as reasonably necessary to deliver these communications.

For questions about a message or assistance with your account, contact:

support@loart.dev

7. Cookies and Local Browser Storage

Helios may use cookies or similar browser storage where necessary to provide authentication, security, and account functionality.

These technologies may be used to:

  • maintain authenticated sessions;
  • protect authentication flows;
  • maintain security state;
  • prevent certain attacks;
  • remember necessary account or interface settings; and
  • support OpenID Connect or OAuth authentication flows.

Helios does not intentionally use advertising cookies or third-party behavioural advertising trackers.

8. Third-Party Services

Helios may rely on limited third-party infrastructure, software, or service providers where reasonably necessary to operate particular features, such as email delivery.

Information is provided to these services only where reasonably necessary to provide the relevant functionality.

Third-party services may process information according to their own privacy policies and terms.

Helios and LoArt & Dev do not sell personal information to third parties.

9. Sale or Commercial Use of Personal Information

Helios and LoArt & Dev do not sell, rent, trade, or commercially monetize personal information collected through Helios.

Helios is operated as a private, non-commercial service.

10. Security

Because Helios is responsible for authentication and access control, security is treated as an important part of the service.

Reasonable technical safeguards are used where appropriate, which may include:

  • password hashing;
  • encrypted network connections;
  • secure session cookies;
  • multi-factor authentication;
  • passkeys and WebAuthn;
  • cryptographically generated security tokens;
  • restricted administrative access;
  • role- and permission-based authorization;
  • audit logging;
  • session management;
  • rate limiting; and
  • other protections against unauthorized access.

No computer system can be guaranteed to be completely secure. Neither Helios nor LoArt & Dev can guarantee that unauthorized access, software vulnerabilities, data loss, or other security incidents will never occur.

Users are expected to help protect their accounts by safeguarding credentials, authentication devices, passkeys, recovery information, and active sessions, and by reporting suspected unauthorized access.

Security concerns or suspected account compromise should be reported to:

support@loart.dev

11. Data Retention

Helios retains information for as long as reasonably necessary to operate the service, maintain security, troubleshoot problems, or maintain appropriate audit records.

Different categories of information may be retained for different periods.

Active account information may be retained while an account exists. Certain security or audit records may remain after an account has been disabled or deleted where reasonably necessary for security, integrity, troubleshooting, or investigation.

Expired sessions, temporary authentication tokens, and similar information may be deleted automatically.

Helios aims not to retain personal information indefinitely where there is no reasonable operational, administrative, or security reason to keep it.

12. Access, Correction, and Deletion

Authorized Helios users may request:

  • access to information associated with their account;
  • correction of inaccurate account information;
  • deletion of information where reasonably possible; or
  • deletion or disabling of their Helios account.

Requests should be directed to:

support@loart.dev

Some information may need to be retained after a request where reasonably necessary to preserve security or audit records, investigate misuse, maintain system integrity, or comply with applicable legal obligations.

Deleting a Helios account may prevent access to applications that depend on Helios for authentication.

13. Administrative Access

Authorized Helios administrators may have access to account information when necessary to:

  • manage accounts;
  • manage application access;
  • assign or revoke roles and permissions;
  • troubleshoot technical problems;
  • respond to user requests;
  • investigate security events; or
  • maintain Helios and its connected services.

Administrative actions may themselves be recorded in Helios audit logs.

Administrative access is not intended to be used to inspect personal information without a legitimate operational, administrative, or security reason.

14. Connected Applications

Helios provides authentication and authorization services to other private applications.

Those applications may independently collect information about your activity within their services.

This Privacy Policy applies specifically to Helios at https://auth.loart.dev.

Information independently collected by another LoArt & Dev application or connected service may be subject to its own privacy policy or privacy practices.

15. Children

Helios is not offered to the general public and is not designed as a public service directed toward children.

Accounts are created or authorized only for individuals permitted to participate in the private LoArt & Dev group and use its services.

16. Disclosure Required by Law or for Security

Helios and LoArt & Dev do not voluntarily sell or commercially disclose user information.

Information may nevertheless be disclosed where required by applicable law or valid legal process, or where reasonably necessary to address a serious security, safety, fraud, or abuse issue.

17. Changes to This Privacy Policy

This Privacy Policy may be updated as Helios and LoArt & Dev services change.

Material changes that significantly affect how personal information is collected, used, or disclosed should be communicated to affected users where reasonably practical.

The date at the top of this document indicates when this Privacy Policy was most recently updated.

The canonical current version is available at:

https://loart.dev/legal/helios-privacy-policy

18. Future Changes to Helios

This Privacy Policy describes Helios as it currently operates: a private, limited-access, non-commercial service operated by LoArt & Dev.

If Helios later becomes publicly available, accepts public registrations, becomes commercial, is operated through a registered business, or materially changes how personal information is processed, this Privacy Policy should be reviewed and updated before those changes take effect.

19. Related Policies

Use of Helios is also subject to the applicable:

  • Helios Terms of Service;
  • Helios Security Policy; and
  • LoArt & Dev Acceptable Use Policy.

Current legal documents are publicly available at:

https://loart.dev/legal/

20. LoArt & Dev and Contact Information

The primary LoArt & Dev website is:

https://loart.dev

Helios is available at:

https://auth.loart.dev

Public legal documents are available at:

https://loart.dev/legal/

For privacy requests, account assistance, security concerns, or other questions concerning Helios, contact:

support@loart.dev

Transactional email addresses used by Helios are intended for automated service communications and should not be relied upon as support addresses. For assistance, use support@loart.dev.