Helios
Methodology
Draft — pending counsel review

This document has not been reviewed by a lawyer, has not been approved by Ateliersavant, and is not in force. Nothing in it should be relied on as final.

Terms of Service — Helios

These terms are a draft prepared for review by French counsel. They have not been approved by a lawyer and must not be presented to any user as final or binding.

This document is written in English so that counsel can work from it. The governing law is French law, and counsel will decide whether a French-language version must be the authoritative one for consumers domiciled in France. [COUNSEL: confirm whether a French text is legally required for B2C contracts here (Loi Toubon / Art. L.211-1 C. consom. plain-language duty) and, if both languages are published, which prevails.]


1. Who we are, and what these terms cover

Helios is provided by Ateliersavant Europe SAS, a company incorporated in France ("we", "us", "Ateliersavant"). Société par actions simplifiée (SAS), registered office 17 rue du Pre-Breda, B.P. 60, 51200 Épernay Cedex, France. SIRET 91229128300014 (SIREN 912291283). [COUNSEL: RCS registry city and number, share capital, VAT number, and the name of the directeur de la publication are still outstanding — Art. 6 III LCEN requires these on the service itself, not only in these terms, so a footer or legal-notice page has to carry them too.]

These terms form the contract between you and us for your use of the Helios desktop application, the Helios website, and anything we make available as part of them (together, the "Service").

Two other documents form part of this contract and you should read them:

  • legal/medical-disclaimer.md — the medical disclaimer. It is the single source of the medical safety statements; this document does not restate them and, where the two texts could be read differently, the medical disclaimer governs.
  • legal/privacy-policy.md — how we handle personal data, including health data.

If you were invited to the private beta, legal/beta-tester-agreement.md also applies and, on any point where it is stricter than this document, it prevails.

By installing or using the Service you accept these terms. If you do not accept them, do not use the Service.

2. What Helios is

Helios is an informational wellness and decision-support tool. You give it information about yourself — laboratory results, symptoms, medications, history — and it compares that information against published reference ranges and against tighter "optimal" targets used in longevity and functional medicine, then produces findings, research citations, and a list of interventions worth discussing with a clinician.

It exists to help you prepare for and get more out of a conversation with your own doctor. That is the whole of its purpose.

2.1 What Helios is not

Helios is not a medical device. We do not offer it for the diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease. It is not CE-marked, it is not registered with the ANSM, and it has not been assessed by any notified body.

[COUNSEL: this is the single highest-risk statement in this document. Software that provides information used to inform a clinical decision can fall inside Regulation (EU) 2017/745 (MDR) Art. 2(1) as read with Rule 11 of Annex VIII and MDCG 2019-11. Helios outputs named interventions with dosing ranges. Please assess the qualification directly rather than relying on our intent, and tell us whether the output must be reworded, restricted, or whether the product must be classified and conformity-assessed. Everything else in this document is drafted on the assumption that the answer is "not a device"; if it is a device, this document is not the right document.]

Helios is not a prescriber and not a pharmacy. It cannot prescribe, dispense, or supply anything. Every prescription-only medicine, hormone, peptide and therapy it mentions is shown with a dosing range, an evidence tier, and an explicit flag that a licensed clinician is required. Those are illustrative parameters for a clinical conversation, not instructions to you.

Helios is not your doctor and creates no care relationship. Using it does not make us, or anyone working with us, your healthcare provider. Nobody at Ateliersavant reviews your data or your results.

Helios is not an emergency service. If you think you may be having a medical emergency, call your local emergency number (15 or 112 in France). Do not use the Service.

2.2 The clinical review status of what you are shown

You must know this before you use anything Helios tells you:

  • The engine reasons from 90 biomarker reference ranges. 62 of them have not been signed off by a clinician. 28 have.
  • 29 interventions are in the knowledge base. Those not signed off are labelled, in the interface, "Protocol pending clinical review — do not act on this yet."
  • Because most ranges are unsigned, that pending-review warning is the normal state of a Helios recommendation, not an exception.

We are telling you this rather than burying it because a warning that appears on almost everything is easy to stop seeing. docs/CLINICAL_REVIEW.md in our repository is the live record of what has and has not been reviewed.

3. Eligibility and access

The Service is currently invite-only and is not open to public registration.

You may use it only if you are at least 18 years old and have the legal capacity to enter into a contract. Helios is not designed for, and must not be used to analyse the data of, a child. [COUNSEL: confirm the age threshold. France sets the digital-consent age at 15 under Art. 45 Loi Informatique et Libertés, but Art. 9 health data processed on consent may warrant a higher floor. We have drafted 18.]

You may use the Service only for your own health information, or for the health information of a person for whom you are the legal representative and for whom you can lawfully give consent. Do not enter another adult's laboratory results.

You are responsible for your account, your device passphrase, and your vault recovery code. We cannot recover your vault if you lose both the passphrase and the recovery code. The data is encrypted on your device with a key we never hold; there is no back door and no reset. That is a deliberate property of the design, and its cost is that a lost passphrase means lost data.

3.1 Price

The beta is supplied free of charge. We do not currently take payment for the Service and no payment mechanism exists in the product. [COUNSEL: because nothing is paid for, the consumer withdrawal right (Art. L.221-18 C. consom.) and the legal conformity guarantees for digital content (Art. L.224-25-12 et seq. C. consom.) apply in modified form or not at all. Please confirm which pre-contractual information duties still bite on a free service, and rewrite this section for the day we do charge. Note also that the liability cap in §10 has no natural size when the price is zero — see the bracket there.]

4. Beta software, supplied as is

The Service is beta software. It is incomplete, it is under active development, and it will contain defects.

To the fullest extent permitted by law, and subject always to §10.2, the Service is provided "as is" and "as available", without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement.

Concretely, and so that "as is" is not an abstraction, here is what we know is unfinished:

Known limitationWhat it means for you
62 of 90 reference ranges are not clinician-signed (§2.2)Most findings carry a pending-review warning
Laboratory PDF extraction is performed by an AI model, not a deterministic parserValues can be misread; you must confirm every value before it is stored
Analysis of scanned (image) PDFs sends page images to a third party without redactionSee §8 and the privacy policy
The product has been tested by very few peopleBehaviour on unusual lab formats is unknown

Every value Helios extracts from a document is a proposal until you confirm it. We do not auto-trust extraction. Confirming a wrong value is the most likely way to get a wrong result, and you are the only person in the loop who can catch it.

We do not warrant that the Service will be available, uninterrupted, timely, secure, or error-free, or that any result it produces is accurate or complete.

5. Your obligations

You agree to:

  • use the Service lawfully, and only for the personal, non-commercial purpose described in §2;
  • give accurate information about yourself, and confirm extracted laboratory values honestly rather than accepting them unread;
  • discuss any change to your medication, hormone, supplement or treatment regimen with a licensed clinician before making it;
  • keep your credentials, passphrase and recovery code confidential;
  • not upload another person's health data without the legal right to do so;
  • not use the Service to provide healthcare, diagnosis or treatment advice to anyone else, whether paid or unpaid;
  • not attempt to circumvent the safety gate, the consent gate, the clinical-review labelling, or any technical restriction in the Service;
  • not reverse-engineer, decompile, scrape, resell, sublicense or redistribute the Service, except where that restriction is void under Art. L.122-6 and L.122-6-1 CPI (interoperability, error correction, study of the program) or other mandatory law;
  • not use the Service to build a competing product, or to train a machine-learning model on its outputs;
  • not introduce malware, overload our infrastructure, or attempt to access data that is not yours.

If you supply an API key of your own (see §8.1), you are responsible for that key, for its terms with the issuing provider, and for what it costs you.

6. Your data

How we handle personal data — and in particular health data, which is "special category" data under Art. 9 GDPR — is set out in legal/privacy-policy.md. That document, not this one, is the authoritative description.

Two points belong here because they are contractual as well as regulatory:

  1. Processing your health data requires your explicit consent, and the Service enforces that server-side. If you have not given consent, or you withdraw it, the Service refuses to read or analyse your health data. Withdrawal does not require a reason and costs you nothing.

    Landed as of c352253: the consents table (M4) exists in both schemas and require_consent (M5, apps/api/app/consent.py) 403s 26 of 47 routes without an active grant. Verified by apps/api/tests/test_consent_gate.py.

  2. Withdrawing consent does not lock you out of your own data. Export and deletion remain available to you before, during and after withdrawal, because those are precisely the rights you are exercising at that moment.

    Landed as of c352253: GET /export/archive no longer 404s under HELIOS_AUTH=local (M8b), and DELETE /patients/{id} / DELETE /account (M7, apps/api/app/erasure.py) exist on both platforms. Also landed, this wave: M9's /settings surface (apps/web/app/settings/*) is now linked from the app chrome — AppRail.tsx's SETTINGS_ITEM on desktop, SiteHeader.tsx's signed-in /settings link on hosted — so reaching either mechanism means clicking a link, not typing a URL.

You own your health data. We claim no ownership of it and we do not use it to train models.

7. Intellectual property

7.1 Ours

The Service — its software, reasoning engine, reference-range compilation, knowledge base, interface, text and design — is owned by Ateliersavant or its licensors and is protected by copyright and other rights. We grant you a personal, revocable, non-exclusive, non-transferable licence to use the Service for the purpose described in §2, for as long as these terms are in force. No other right is granted. [COUNSEL: check this against the open-source components we redistribute in the desktop bundle; the licence grant above must not purport to cover code we do not own. An attribution/third-party-notices file is a separate deliverable.]

7.2 Yours

Your health data, your documents and your notes remain yours. We take no licence over them beyond what is strictly necessary to operate the Service for you, as described in the privacy policy.

7.3 Feedback

If you send us feedback, bug reports or suggestions, we may use them without restriction and without owing you anything. Beta testers are subject to the fuller feedback licence in legal/beta-tester-agreement.md.

8. Third parties, and the things we do not control

Parts of the Service depend on providers we do not control. We are not liable for their unavailability, degradation, latency, data loss, security incidents, or changes to their own terms, subject always to §10.2.

The providers involved today:

ProviderRoleWhere it applies
Anthropic (US)AI model used to read laboratory documents and to answer chat questionsDesktop: your own key, from your own Keychain (§8.1). Hosted web service: our key, and nothing is asked of you first — see the note below this table
SupabaseDatabase and file storageHosted web service only. Not used for beta health data
VercelWebsite hostingHosted web service only
Google Cloud RunAPI hostingHosted web service only
Europe PMC, ClinicalTrials.govResearch literature and trial lookupsBoth. Receives topic words only — never your data

The Anthropic row differs by platform, and the difference matters enough to state rather than average out. These terms cover both the desktop application and the Helios website (§1). On the desktop, the key is yours: the application reads it from your macOS Keychain and passes it to the engine running on your own machine, so the calls are billed to you and governed by your agreement with Anthropic. On the hosted web service, the same chat and document-reading features run on our key, billed to us. What is described in §8.1 is the desktop arrangement.

Landed as of c352253: the consent record and server-side check exist (M4/M5), M10's LLM_PHI_APPROVED gate (apps/api/app/llm_transfer.py) hard-disables every AI path on hosted with no exception, and M9's key-entry screen exists (apps/web/app/settings/AnthropicKeyPanel.tsx). Also landed, this wave: the llm_transfer consent named in §8.1 can now be granted from /settings (apps/web/app/settings/LlmTransferPanel.tsx, api.grantConsent("llm_transfer", …)). ConsentPanel.tsx still only withdraws consents already on record — granting llm_transfer is this separate panel's job, by design (see that file's own reasoning for why the grant sits at the point of use rather than in first-run setup). Until a tester has both a key and this consent, the gate refuses every desktop AI call with 403 llm_transfer_consent_required, exactly as designed.

[COUNSEL: the full list, with roles, locations and transfer bases, belongs in legal/subprocessors.md and the Art. 30 register. This table exists so the liability carve-out is not abstract, and it must be kept consistent with those documents.]

If a provider stops offering its service, or changes it in a way we cannot absorb, the corresponding Helios feature may stop working. Where that happens we will tell you what stopped and why.

8.1 AI features, and the transfer to the United States

In the desktop application, the AI features (reading laboratory documents, and the chat assistant) work only if you supply your own Anthropic API key, stored in your own macOS Keychain, and only if you grant a specific consent for these transfers. That consent is a standing one — you give it once, it covers only the three transfers described in legal/privacy-policy.md §6 and nothing else, every individual transfer is recorded in your audit log before it happens (and one that cannot be recorded is refused), and you may withdraw it at any time with immediate effect. We describe it as standing rather than as a fresh decision before each call, because that is what it is. It names Anthropic, states that the transfer is to the United States under the terms of your own Anthropic account, and states plainly that we have not confirmed zero-data-retention or no-training terms for that account — because we have not, and a document must not say otherwise until procurement closes that gap (legal/subprocessors.md §1).

The Keychain half of that is real — the desktop application stores your key there and hands it to the engine on your machine, and it is the only key the desktop can use. Landed as of c352253: the consent record, require_consent, LLM_PHI_APPROVED gating, and the /settings screen for entering the key. Also landed, this wave: /settings → the llm_transfer panel (apps/web/app/settings/LlmTransferPanel.tsx) now grants the consent this paragraph describes (api.grantConsent("llm_transfer", …)), so a transfer to Anthropic can happen from the desktop app once a tester has both a key and this consent — refused with 403 llm_transfer_consent_required until then, exactly as designed.

When you grant it, health information leaves your device: for chat, that is your age, sex, medication names, biomarker values and the findings and recommendations shown to you; for document reading, it is the text of the report, with lines that look like identifiers removed but with the laboratory values deliberately kept, because the values are the thing being read. For scanned documents, whole page images are sent and no redaction is possible — if your scan shows your printed name or a hospital number, that is transmitted too.

We describe this bluntly because it is the one place where the "your data stays on your device" property of the desktop app does not hold. If you do not want that transfer, do not grant the consent and do not use the AI features; the rest of the Service works without them.

Calls made with your key are billed to you by Anthropic and are governed by your agreement with them, not by these terms.

9. Availability, changes, and no commitment to keep shipping

We may change, suspend or discontinue any part of the Service, including the whole of it, at any time. This is beta software with no service-level commitment: there is no uptime guarantee, no support guarantee, and no guarantee that the product will ever leave beta.

If we discontinue the Service we will give you reasonable notice and a window in which to export your data, unless we are prevented from doing so by law or by a safety or security emergency.

Landed as of c352253: GET /export/archive no longer 404s under HELIOS_AUTH=local (M8b) and answers in the desktop application. The /settings → Export my data screen it backs is now reachable from the app chrome as well — the desktop rail carries a Settings entry and the hosted header a signed-in link — so this commitment is exercisable from inside the product, not only by calling the route.

[COUNSEL: specify the notice period, and whether a free beta requires one at all under Art. L.224-25-x C. consom.]

Because your beta data lives in an encrypted vault on your own device, discontinuation does not by itself delete it. The vault is a folder on your own disk (~/Library/Application Support/Helios by default) and copying it while the application is closed preserves everything, though what you get is the encrypted form, readable only by Helios and only with your passphrase. Discontinuation does mean the software that reads it stops being maintained.

10. Liability

10.1 The cap

Subject to §10.2 and §10.3, our total aggregate liability to you arising out of or in connection with the Service, whether in contract, tort, or otherwise, is limited to [COUNSEL: SIZE CAP].

[COUNSEL: SIZE CAP — the usual anchor, a multiple of amounts paid in the preceding twelve months, produces zero here because the beta is free. Please set a defensible fixed euro figure instead, and consider whether a cap of any size survives Art. 1170 C. civ. (a clause depriving the essential obligation of its substance is deemed unwritten) and Art. L.212-1 C. consom. (unfair terms in consumer contracts, and the clauses noires list at R.212-1) in a contract about health information. Our instruction to you is: if a cap in this context is not enforceable against a consumer, say so and we will remove it rather than keep an unenforceable clause that looks like protection.]

10.2 What can never be capped or excluded

Nothing in these terms limits or excludes our liability for:

  1. Fraud and wilful misconduct (dol) — including fraudulent misrepresentation. Under Art. 1231-3 of the Civil Code, a debtor guilty of dol is liable for damages that were not foreseeable at the time of contracting, and no clause may reduce that.
  2. Gross negligence (faute lourde) — French case law treats faute lourde as equivalent to dol for this purpose, and a limitation clause is set aside where the breach is of that gravity, or where it defeats the essential obligation of the contract.
  3. Death or personal injury (dommage corporel) — Art. 1245-14 of the Civil Code makes any clause excluding or limiting liability for harm caused by a defective product to the person unwritten, and the same principle applies to bodily harm generally.

These three exceptions are not negotiable and are not stylistic. A limitation clause that omitted them would not merely be unfair — it would be unenforceable, and its presence would be evidence against us. They are stated here for that reason.

10.3 Your mandatory rights

Nothing in these terms affects your non-waivable rights as a consumer under French or EU law, including the legal guarantee of conformity for digital content and services, your rights under the GDPR, and your right to bring proceedings under §13.

10.4 What we are asking you to accept

Subject to §10.1 to §10.3, we are not liable for:

  • any health outcome arising from a decision you made on the basis of Helios output without a clinician's involvement;
  • a wrong result caused by a laboratory value that was extracted incorrectly and that you confirmed;
  • loss of data caused by the loss of your passphrase and recovery code (§3);
  • the acts, omissions or outages of the third parties listed in §8;
  • indirect or consequential loss, loss of profit, loss of opportunity or loss of data, to the extent the law permits that exclusion between us.

The medical disclaimer in legal/medical-disclaimer.md explains, in plain terms, why the first item on that list is the one that matters.

11. Suspension and termination

You may stop using the Service at any time. You can delete your account and your data from within the application; deletion is permanent.

Landed as of c352253: DELETE /patients/{patient_id} and DELETE /account (M7, apps/api/app/erasure.py) delete the rows and the blobs — scans.delete_object is now called from the erasure path, and assert_no_orphans re-checks the database before committing. Also landed, this wave: M9's interface for this (/settings → Delete my account and data) is now linked from the app chrome (AppRail.tsx on desktop, SiteHeader.tsx on hosted), so "from within the application" above is true in the sense of clicking a link, not only in the sense that the API it calls works.

We may suspend or terminate your access, with notice where practicable and immediately where not, if you materially breach these terms, if we reasonably believe your use presents a safety or security risk, or if we discontinue the Service under §9.

On termination the licence in §7.1 ends. Sections 2, 6, 7.2, 7.3, 10, 13 and 14 survive.

Termination does not delete the encrypted vault on your own device. If you want that gone, delete the vault folder itself (~/Library/Application Support/Helios by default): removing it removes the encrypted database, the header file holding the wrapped keys, and the encrypted document blobs together, and without the header the data cannot be read again by anyone, including us. The privacy policy explains what deletion covers.

12. Changes to these terms

We may update these terms. If a change is material we will notify you in the application and, where the change concerns how we process your health data, we will ask for your consent again rather than assume it. Continued use after a non-material change means acceptance. [COUNSEL: notice period and the mechanics of re-consent for a consumer contract — confirm that silence cannot be treated as acceptance for material changes.]

Each version of these terms carries a version number in the front matter above. The application records which version you accepted, when, and a hash of the text you were shown, so that "which terms did I agree to" always has an answer.

Landed as of c352253: record_acknowledgement (M4, apps/api/app/consent.py) records the document, version and a SHA-256 of the text shown, and M12's desktop first-run flow (apps/web/app/legal/first-run/FirstRunLegalFlow.tsx) writes it for terms and health_data_processing. legal/beta-tester-agreement.md §12 carries the same update; the two documents are deliberately identical on this point.

13. Governing law, complaints, and jurisdiction

These terms are governed by French law.

Before going to court, you may contact us at the address in §14 and we will try to resolve the matter. As a consumer you are also entitled to free recourse to a consumer mediator under Art. L.612-1 of the Consumer Code. [COUNSEL: we must appoint a médiateur de la consommation and name them, with their postal and web address, here and on the site — the obligation applies to any professional dealing with consumers, including one supplying a free service. Confirm and name.] You may also use the European ODR platform. [COUNSEL: verify the ODR platform is still operative; the Commission has been winding it down. Do not link a dead platform in a consumer contract.]

Disputes fall to the French courts. [COUNSEL: a clause fixing exclusive jurisdiction against a consumer is void — Art. L.212-1 C. consom. and, for cross-border cases, Art. 17-19 of Regulation (EU) 1215/2012 give the consumer the courts of their own domicile. Draft this so that it does not purport to take that away.]

14. Contact

Ateliersavant Europe SAS 17 rue du Pre-Breda, B.P. 60 51200 Épernay Cedex, France SIRET 91229128300014 Email: privacy@ateliersavant.com

Engineering note, to be removed before publication: the privacy@ateliersavant.com alias did not exist at the time of this draft; it was created 2026-08-03 and now receives mail. That blocker on publication is closed — counsel sign-off (front-matter status, above) is the one that remains.

15. Document control

FieldValue
Version0.1.3-draft
StatusDRAFT-PENDING-COUNSEL
Drafted2026-07-27
EffectiveTBD-PENDING-COUNSEL
Supersedesnothing — this is the first terms of service Helios has had
Reviewed by counselNo

Related documents: legal/medical-disclaimer.md, legal/privacy-policy.md, legal/beta-tester-agreement.md, legal/subprocessors.md.

Version 0.1.3-draft · Effective TBD-PENDING-COUNSEL

Ateliersavant Europe SAS · privacy@ateliersavant.com