Helix.ID
Sign In

Cookie Notice

Last updated 17 September 2026 · Version 1.0

View as Markdown

This notice lists every cookie and every other item Helix stores on your device, what each one does, how long it lasts, and why it does not need your consent. It goes with our Privacy Notice at https://helix.id/privacy, which explains everything else about how we handle personal information.

We would rather list the items than describe them in categories, so you can check what we say against what your browser shows you.

The short version

On our corporate site, helix.id, we store nothing. No cookies, no browser storage.

In our product, the customer dashboard and the verification widget, we store a small number of items. All but one are strictly necessary: without them you could not sign in, the site could not protect you against forged requests, and the verification flow could not remember which step you are on. The one exception remembers whether you chose the light or dark theme.

We do not use analytics cookies anywhere. Our analytics runs in a cookie-free configuration that stores nothing on your device, and session identifiers are removed before anything reaches it.

We do not use cookies for advertising, and we do not allow anyone else to.

Corporate site: helix.id

We store nothing on your device when you visit helix.id.

Until 15 September 2026 the site carried a consent banner supplied by Termly, which stored two items of its own. The banner has been removed and those items are no longer set. If you visited before that date, you may still have them in your browser; clearing site data for helix.id removes them.

Product: cookies

NameWhat it doesHow long it lastsWhy it is necessary
access_tokenKeeps a dashboard user signed in1 hourSign-in
id_tokenCarries the signed-in user's identity details, name and email, to the dashboard1 hourSign-in
refresh_tokenRenews the dashboard session so you are not signed out every hour30 daysSign-in
csrf_tokenProtects against cross-site request forgery. Readable by the page by design, so it can be sent back on each request30 daysSecurity
helix_jwtKeeps an end user signed in after passkey or voice verification, including inside a partner's embedded widget30 minutesSign-in
helix_sessionIdentifies the verification attempt in progress and links it to our abuse and bot checks. Removed before anything reaches our analytics1 hourSecurity

Where a business uses voice matching

Some businesses configure our technology so that you are matched against a voice you set up earlier. In that case an encrypted voice reference is created and held on your own device. It is never sent to Helix. It is storage on your device, so we mention it here, though it exists only because you set up that feature. Clearing that site's data or removing the passkey you created removes it, and once the key is gone what remains cannot be unlocked by anyone, including us. Our End-User Processing Notice at https://helix.id/privacy/voice-check explains the voice check itself.

Analytics

We use PostHog to understand how our site and product are used. It runs in cookieless mode on both. It sets no cookies, stores nothing on your device, receives no IP address, and receives no session identifier, because we remove identifiers before events are sent. Session recording is off. What it receives is aggregate usage: which pages and features are used, how often, and whether they work.

Advertising

We do not use cookies or any other storage for advertising. We do not permit third parties to place tracking technologies on our site or in our product to target advertising at you, and we do not share information with advertising networks.

How to clear these items

Your browser settings let you view and delete cookies and site storage for helix.id and for any partner site where you used our verification widget. If you clear the necessary items you will be signed out and, where a business uses voice matching, you will need to set up your voice reference again. Clearing the theme preference returns the dashboard to its default appearance.

Changes to this notice

This notice changes whenever the items we store change. Changes are approved before they are published, and we keep every previous version and its approval record. The version and date at the top tell you which one you are reading.

Contact

Questions about this notice: privacy@helix.id. Our Privacy Notice at https://helix.id/privacy explains who we are, how to contact our UK and EU representative, and what rights you have.