Privacy Policy

Effective Date: April 1, 2026

Helio LLC ("Helio," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use Helio Rewards, including heliorewards.com and all related services (the "Service").

Your health data is sensitive. We built our entire platform around that fact. This policy describes not just what we collect, but the specific architecture we designed to keep your identity separate from your health information at every level.

1. Information We Collect

1.1 Information You Provide

1.2 Information Collected Automatically

2. How We Use Your Information

We do not sell your personal information. We do not use your health data for advertising. We do not share your identity with researchers.

3. How We Protect Your Data: Three-Tier Architecture

Your identity and your health data are never stored together. This is the most important thing to understand about how Helio works. We deliberately separate your data into three isolated tiers so that no single breach, no single employee, no single system can connect your name to your health conditions.

Tier 1: Identity Vault

Your personally identifiable information — name, email, phone, date of birth, address, payment details — lives in a secured, encrypted Identity Vault. This vault is completely isolated from all research and health data. Researchers cannot access the Identity Vault. The Identity Vault is used only for account management, communication, and payment processing.

Tier 2: Research Profiles

Your health conditions, demographic ranges, and specimen-relevant characteristics are stored as an anonymized Research Profile. This profile contains no names, email addresses, phone numbers, dates of birth, addresses, or other directly identifying information.

When a researcher is looking for donors with specific health profiles, they see entries like "Female, age 35-40, Type 2 Diabetes, non-smoker, BMI 28-32." They never see your name. They never see your contact information. They never see anything that tells them who you are.

Tier 3: Helio ID (The Bridge)

Your Helio ID is a randomly generated identifier — the only link between your Identity Vault and your Research Profile. It exists in a separate, secured system. This means:

This is not a future plan. This is how the platform is built today.

4. HIPAA and Health Data Protection

Your health data deserves the highest protection available, regardless of whether it is technically classified as Protected Health Information (PHI) under HIPAA. Helio voluntarily adopts HIPAA-aligned safeguards because it is the right thing to do. Our practices include:

5. Who Sees Your Data

5.1 Researchers

Researchers see your anonymized Research Profile only — health conditions, demographic ranges, and specimen-relevant data. They never see your name, email, phone number, date of birth, address, or any information that could identify you personally.

5.2 Collection Facilities

When you schedule a donation, we share your name, contact information, and appointment details with the approved collection facility to coordinate your visit. These facilities are bound by their own HIPAA obligations and by contractual data protection agreements with Helio.

5.3 Third-Party Service Providers

We use a small number of trusted services to run the platform. Each receives only the minimum data needed for their specific function:

None of these providers receive your health profile data.

5.4 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request. We may also disclose information to protect the rights, property, or safety of Helio, our users, or the public.

6. Deleting Your Data

6.1 How to Delete Your Account

You can request deletion of your account at any time by emailing [email protected] with the subject line "Account Deletion Request." Include the email address associated with your account.

6.2 What Happens When You Delete

When we process your deletion request:

6.3 Inactive Accounts

If your account has no activity for 24 consecutive months, we may flag it for review. We will notify you by email before taking any action.

7. Cookies

We use the minimum cookies necessary to operate the Service:

That is it. We do not use advertising cookies, tracking pixels, social media trackers, or third-party analytics. We do not participate in cross-site tracking or behavioral advertising.

8. Children's Privacy

Helio Rewards is for adults 18 and older. We do not knowingly collect information from anyone under 18. If you are a parent or guardian and believe your child has provided information to Helio, contact us at [email protected] and we will delete it promptly.

9. Your Privacy Rights

9.1 California Residents (CCPA/CPRA)

If you live in California, you have additional rights:

9.2 Other States

If you live in Virginia, Colorado, Connecticut, Utah, or another state with consumer privacy laws, you may have similar rights under your state's law.

9.3 Exercising Your Rights

To make a privacy request, email [email protected]. We will verify your identity and respond within 45 days.

10. Data Security

We implement strong technical, administrative, and physical safeguards:

No system is 100% secure. If you discover a security vulnerability, please report it to [email protected].

11. International Users

Helio Rewards is currently available only in the United States. Your data is processed and stored in the United States. If we expand internationally, this policy will be updated to address applicable data protection laws, including GDPR for European users.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated by email at least 30 days before taking effect, with a prominent notice on the Service.

The "Effective Date" at the top of this page shows when the policy was last revised. We encourage you to review this policy periodically.

13. Contact Us

Questions about this Privacy Policy or your data? Reach us at:

Helio LLC
Email: [email protected]
Website: heliorewards.com

For data deletion requests, use the subject line "Account Deletion Request" and include the email address on your account.


Last updated: April 1, 2026