Skip to main content
Helicase

Privacy Policy

What information Helicase handles, why, and what it never does.
Last updated October 9, 2026

In short

  • Helicase has no ads, no analytics and no tracking cookies, and it never sells personal information.
  • Accounts are optional. If you create one, we keep only what it needs, it is private by default, and you can download or delete it at any time.
  • Your display settings are saved only in your own browser.
  • Searches of the research literature are passed on without your IP address.
  • Searching Helicase itself happens in your browser.

Who is responsible

This website and this policy are the responsibility of Easton Tobias. For privacy questions or requests, write to thepeddlecompany@gmail.com or use the contact page.

When you visit a page

Like every website, the server that delivers Helicase receives technical details with each request: your IP address, the address of the page, your browser’s description of itself (the user agent) and the time. Helicase is hosted by Vercel Inc., which keeps request logs under its own policies and retention periods. Helicase’s own code does not store these details, except as described in the next section.

Security and abuse prevention

To protect the research search and sign-in from abuse, our server turns your IP address into a keyed one-way code (a hash) and counts requests per code. Counts for the research search are kept in memory for no more than about two hours; counts for signing in are kept in our database, under the hashed code only, and deleted within about a day. Raw IP addresses are never stored or written to our logs. When something looks like abuse, such as too many requests, we log the event with that code, the time and the page, but never what you searched for or typed.

If you create an account

Accounts are optional. Everything else on Helicase works without one. If you create one, we keep:

  • Your email address, to sign you in and to send you account emails: the confirmation link, password resets and security notices. We do not send marketing email.
  • Your password, only as a salted one-way hash (scrypt). Nobody, including us, can read it.
  • Optional details you choose to add: a display name, a username, a daily goal and the fields that interest you (used to suggest learning paths). We never ask for your real name, address, phone number or date of birth.
  • Your picture. Unless you upload one, it is a pattern drawn from a random number. If you upload a picture, we convert it to a small square image and remove its hidden details, such as location and camera information, before storing it.
  • Your confirmations: the date you confirmed you are 13 or older and the date you accepted the Terms of Use, and your time zone, so that streaks follow your calendar.
  • Your learning activity: which steps you opened and completed, your quiz answers and scores, the XP, level and achievements they earned, and the days on which you studied, so we can count study runs in your time zone.
  • Your library: the items you save, the research papers you bookmark (title, authors, journal, year and link) and your private notes.
  • Sign-in records: one record per signed-in device, holding a random session token, when it started and your browser’s description, so you can see and end your sessions. IP addresses are not kept with them.
  • Two-step verification, if you turn it on: the secret for your authenticator app and your backup codes, both stored encrypted.

Your account data is private. The database itself lets each account see only its own rows, and the part of the site that serves pages cannot read email addresses or passwords at all.

We use your learning activity only to show you your own progress and to suggest what to try next. Suggestions come from simple rules applied to your progress and the interests you chose; they are not used to make any decision about you, and we never share or sell this information.

Expired sign-in records and links are deleted automatically. If you create an account but never confirm your email address, the account is deleted after seven days.

Public profiles

Your profile is private unless you choose to make it public in your profile settings. A public profile is a page at an address made from your username. It shows your display name, username, picture and the month you joined, and only the extras you tick: your level and XP, your achievements, your interests. It never shows your email address, your sign-in or security details, your notes, your quiz answers or what you have saved.

Public profile pages ask search engines not to list them, though we cannot make every search engine comply. Making your profile private again takes the page down straight away, but we cannot recall copies that other people may already have made.

Downloading or deleting your data

Signed in, you can download everything stored for your account as one file from Account, Your data. Password hashes, sign-in tokens and two-step verification secrets are left out, because a copy of them could be used to take over your account.

On the same page you can delete your account. That removes your email address, password, profile, picture, progress, notes and everything else stored for the account straight away; it cannot be undone. Emails you have sent us are kept separately; ask us if you want those deleted too.

The research explorer

When you search published papers, our server sends your search terms and filters to Europe PMC, run by the European Bioinformatics Institute, and, if Europe PMC is unavailable, to PubMed at the US National Center for Biotechnology Information. Your IP address and browser details are not passed on to them.

To answer repeated searches quickly, results are kept in our server’s memory for up to 15 minutes, and a content delivery network may reuse identical searches for up to about an hour. Our code does not log search terms. Please do not type personal information into the search box.

The site search runs in your browser: the search index is downloaded once, and what you type is not sent to our server as you type. If you open or share the address of a search page that includes a search, that address reaches the server like any other page request.

Display settings and quiz answers

Your theme, reading level and motion choices are saved in your browser’s local storage, and only after you change one. They never leave your device. When you submit a quiz, the questions, your answers and the feedback are also kept there, signed in or not, so they are still there if you reload the page; choosing Try again removes them. Anyone using the same browser can see them. The Cookie & Storage Policy lists exactly what is stored.

If you email us

If you write to us, we receive your email address and whatever you write. We use them only to reply and to act on what you reported, such as a correction, and we keep them only as long as that requires.

What Helicase does not do

  • No tracking or advertising cookies, no analytics and no tracking pixels. The only cookies are the ones that keep you signed in, and they are set only when you sign in.
  • No advertising, and no selling or sharing of personal information for advertising.
  • No third-party scripts, embeds or fonts: every file comes from this website, and fonts are served from it too.
  • Nothing you type on Helicase is sent to an AI service.

Children

Helicase is made for learners of all ages, and the site can be used without an account. Accounts are for people aged 13 and over, and we do not knowingly create accounts for, or collect personal information from, children under 13. If you believe a child under 13 has an account or has emailed us personal information, contact us and we will delete it.

Your rights

Depending on where you live, you may have the right to ask what personal information we hold about you, to get a copy of it, to correct it or to have it deleted. If you have an account, you can do most of this yourself: edit your profile, download your data or delete your account in your account settings. For anything else, including emails you sent us, contact us and we will respond as the law where you live requires. You may also have the right to complain to your local data protection authority.

If you live in California

Helicase is run from California, and California law governs this policy. California residents may have the right to know what personal information we hold about them, to correct it, to delete it, and to be free of discrimination for asking. We do not sell or share personal information, and we do not track you across other websites, so a “Do Not Track” setting in your browser has nothing to change. Use your account settings or the contact page to make a request, and we will respond as California law requires.

Where information is processed

Our hosting provider and the literature databases named above may process requests in countries other than yours. Europe PMC is based in the United Kingdom and PubMed in the United States.

Keeping information safe

Helicase is served over encrypted connections with strict security headers, limits how fast its search can be used, and keeps secrets on the server. No website can promise perfect security, but we keep what we hold to a minimum so that there is little to protect.

Changes to this policy

When Helicase’s practices change, this page will be updated before the change takes effect, with a new date at the top.