This document has not been reviewed by a lawyer, has not been approved by Ateliersavant, and is not in force. Nothing in it should be relied on as final.
Terms of Service — Helios
These terms are a draft prepared for review by French counsel. They have not been approved by a lawyer and must not be presented to any user as final or binding.
This document is written in English so that counsel can work from it. The governing law is French law, and counsel will decide whether a French-language version must be the authoritative one for consumers domiciled in France. [COUNSEL: confirm whether a French text is legally required for B2C contracts here (Loi Toubon / Art. L.211-1 C. consom. plain-language duty) and, if both languages are published, which prevails.]
1. Who we are, and what these terms cover
Helios is provided by Ateliersavant Europe SAS, a company incorporated in France ("we", "us", "Ateliersavant"). Société par actions simplifiée (SAS), registered office 17 rue du Pre-Breda, B.P. 60, 51200 Épernay Cedex, France. SIRET 91229128300014 (SIREN 912291283). [COUNSEL: RCS registry city and number, share capital, VAT number, and the name of the directeur de la publication are still outstanding — Art. 6 III LCEN requires these on the service itself, not only in these terms, so a footer or legal-notice page has to carry them too.]
These terms form the contract between you and us for your use of the Helios desktop application, the Helios website, and anything we make available as part of them (together, the "Service").
Two other documents form part of this contract and you should read them:
legal/medical-disclaimer.md— the medical disclaimer. It is the single source of the medical safety statements; this document does not restate them and, where the two texts could be read differently, the medical disclaimer governs.legal/privacy-policy.md— how we handle personal data, including health data.
If you were invited to the private beta, legal/beta-tester-agreement.md also applies
and, on any point where it is stricter than this document, it prevails.
By installing or using the Service you accept these terms. If you do not accept them, do not use the Service.
2. What Helios is
Helios is an informational wellness and decision-support tool. You give it information about yourself — laboratory results, symptoms, medications, history — and it compares that information against published reference ranges and against tighter "optimal" targets used in longevity and functional medicine, then produces findings, research citations, and a list of interventions worth discussing with a clinician.
It exists to help you prepare for and get more out of a conversation with your own doctor. That is the whole of its purpose.
2.1 What Helios is not
Helios is not a medical device. We do not offer it for the diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease. It is not CE-marked, it is not registered with the ANSM, and it has not been assessed by any notified body.
[COUNSEL: this is the single highest-risk statement in this document. Software that provides information used to inform a clinical decision can fall inside Regulation (EU) 2017/745 (MDR) Art. 2(1) as read with Rule 11 of Annex VIII and MDCG 2019-11. Helios outputs named interventions with dosing ranges. Please assess the qualification directly rather than relying on our intent, and tell us whether the output must be reworded, restricted, or whether the product must be classified and conformity-assessed. Everything else in this document is drafted on the assumption that the answer is "not a device"; if it is a device, this document is not the right document.]
Helios is not a prescriber and not a pharmacy. It cannot prescribe, dispense, or supply anything. Every prescription-only medicine, hormone, peptide and therapy it mentions is shown with a dosing range, an evidence tier, and an explicit flag that a licensed clinician is required. Those are illustrative parameters for a clinical conversation, not instructions to you.
Helios is not your doctor and creates no care relationship. Using it does not make us, or anyone working with us, your healthcare provider. Nobody at Ateliersavant reviews your data or your results.
Helios is not an emergency service. If you think you may be having a medical emergency, call your local emergency number (15 or 112 in France). Do not use the Service.
2.2 The clinical review status of what you are shown
You must know this before you use anything Helios tells you:
- The engine reasons from 90 biomarker reference ranges. 62 of them have not been signed off by a clinician. 28 have.
- 29 interventions are in the knowledge base. Those not signed off are labelled, in the interface, "Protocol pending clinical review — do not act on this yet."
- Because most ranges are unsigned, that pending-review warning is the normal state of a Helios recommendation, not an exception.
We are telling you this rather than burying it because a warning that appears on
almost everything is easy to stop seeing. docs/CLINICAL_REVIEW.md in our repository
is the live record of what has and has not been reviewed.
3. Eligibility and access
The Service is currently invite-only and is not open to public registration.
You may use it only if you are at least 18 years old and have the legal capacity to enter into a contract. Helios is not designed for, and must not be used to analyse the data of, a child. [COUNSEL: confirm the age threshold. France sets the digital-consent age at 15 under Art. 45 Loi Informatique et Libertés, but Art. 9 health data processed on consent may warrant a higher floor. We have drafted 18.]
You may use the Service only for your own health information, or for the health information of a person for whom you are the legal representative and for whom you can lawfully give consent. Do not enter another adult's laboratory results.
You are responsible for your account, your device passphrase, and your vault recovery code. We cannot recover your vault if you lose both the passphrase and the recovery code. The data is encrypted on your device with a key we never hold; there is no back door and no reset. That is a deliberate property of the design, and its cost is that a lost passphrase means lost data.
3.1 Price
The beta is supplied free of charge. We do not currently take payment for the Service and no payment mechanism exists in the product. [COUNSEL: because nothing is paid for, the consumer withdrawal right (Art. L.221-18 C. consom.) and the legal conformity guarantees for digital content (Art. L.224-25-12 et seq. C. consom.) apply in modified form or not at all. Please confirm which pre-contractual information duties still bite on a free service, and rewrite this section for the day we do charge. Note also that the liability cap in §10 has no natural size when the price is zero — see the bracket there.]
4. Beta software, supplied as is
The Service is beta software. It is incomplete, it is under active development, and it will contain defects.
To the fullest extent permitted by law, and subject always to §10.2, the Service is provided "as is" and "as available", without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement.
Concretely, and so that "as is" is not an abstraction, here is what we know is unfinished:
| Known limitation | What it means for you |
|---|---|
| 62 of 90 reference ranges are not clinician-signed (§2.2) | Most findings carry a pending-review warning |
| Laboratory PDF extraction is performed by an AI model, not a deterministic parser | Values can be misread; you must confirm every value before it is stored |
| Analysis of scanned (image) PDFs sends page images to a third party without redaction | See §8 and the privacy policy |
| The product has been tested by very few people | Behaviour on unusual lab formats is unknown |
Every value Helios extracts from a document is a proposal until you confirm it. We do not auto-trust extraction. Confirming a wrong value is the most likely way to get a wrong result, and you are the only person in the loop who can catch it.
We do not warrant that the Service will be available, uninterrupted, timely, secure, or error-free, or that any result it produces is accurate or complete.
5. Your obligations
You agree to:
- use the Service lawfully, and only for the personal, non-commercial purpose described in §2;
- give accurate information about yourself, and confirm extracted laboratory values honestly rather than accepting them unread;
- discuss any change to your medication, hormone, supplement or treatment regimen with a licensed clinician before making it;
- keep your credentials, passphrase and recovery code confidential;
- not upload another person's health data without the legal right to do so;
- not use the Service to provide healthcare, diagnosis or treatment advice to anyone else, whether paid or unpaid;
- not attempt to circumvent the safety gate, the consent gate, the clinical-review labelling, or any technical restriction in the Service;
- not reverse-engineer, decompile, scrape, resell, sublicense or redistribute the Service, except where that restriction is void under Art. L.122-6 and L.122-6-1 CPI (interoperability, error correction, study of the program) or other mandatory law;
- not use the Service to build a competing product, or to train a machine-learning model on its outputs;
- not introduce malware, overload our infrastructure, or attempt to access data that is not yours.
If you supply an API key of your own (see §8.1), you are responsible for that key, for its terms with the issuing provider, and for what it costs you.
6. Your data
How we handle personal data — and in particular health data, which is "special
category" data under Art. 9 GDPR — is set out in legal/privacy-policy.md. That
document, not this one, is the authoritative description.
Two points belong here because they are contractual as well as regulatory:
-
Processing your health data requires your explicit consent, and the Service enforces that server-side. If you have not given consent, or you withdraw it, the Service refuses to read or analyse your health data. Withdrawal does not require a reason and costs you nothing.
Landed as of
c352253: theconsentstable (M4) exists in both schemas andrequire_consent(M5,apps/api/app/consent.py) 403s 26 of 47 routes without an active grant. Verified byapps/api/tests/test_consent_gate.py. -
Withdrawing consent does not lock you out of your own data. Export and deletion remain available to you before, during and after withdrawal, because those are precisely the rights you are exercising at that moment.
Landed as of
c352253:GET /export/archiveno longer 404s underHELIOS_AUTH=local(M8b), andDELETE /patients/{id}/DELETE /account(M7,apps/api/app/erasure.py) exist on both platforms. Also landed, this wave: M9's/settingssurface (apps/web/app/settings/*) is now linked from the app chrome —AppRail.tsx'sSETTINGS_ITEMon desktop,SiteHeader.tsx's signed-in/settingslink on hosted — so reaching either mechanism means clicking a link, not typing a URL.
You own your health data. We claim no ownership of it and we do not use it to train models.
7. Intellectual property
7.1 Ours
The Service — its software, reasoning engine, reference-range compilation, knowledge base, interface, text and design — is owned by Ateliersavant or its licensors and is protected by copyright and other rights. We grant you a personal, revocable, non-exclusive, non-transferable licence to use the Service for the purpose described in §2, for as long as these terms are in force. No other right is granted. [COUNSEL: check this against the open-source components we redistribute in the desktop bundle; the licence grant above must not purport to cover code we do not own. An attribution/third-party-notices file is a separate deliverable.]
7.2 Yours
Your health data, your documents and your notes remain yours. We take no licence over them beyond what is strictly necessary to operate the Service for you, as described in the privacy policy.
7.3 Feedback
If you send us feedback, bug reports or suggestions, we may use them without
restriction and without owing you anything. Beta testers are subject to the fuller
feedback licence in legal/beta-tester-agreement.md.
8. Third parties, and the things we do not control
Parts of the Service depend on providers we do not control. We are not liable for their unavailability, degradation, latency, data loss, security incidents, or changes to their own terms, subject always to §10.2.
The providers involved today:
| Provider | Role | Where it applies |
|---|---|---|
| Anthropic (US) | AI model used to read laboratory documents and to answer chat questions | Desktop: your own key, from your own Keychain (§8.1). Hosted web service: our key, and nothing is asked of you first — see the note below this table |
| Supabase | Database and file storage | Hosted web service only. Not used for beta health data |
| Vercel | Website hosting | Hosted web service only |
| Google Cloud Run | API hosting | Hosted web service only |
| Europe PMC, ClinicalTrials.gov | Research literature and trial lookups | Both. Receives topic words only — never your data |
The Anthropic row differs by platform, and the difference matters enough to state rather than average out. These terms cover both the desktop application and the Helios website (§1). On the desktop, the key is yours: the application reads it from your macOS Keychain and passes it to the engine running on your own machine, so the calls are billed to you and governed by your agreement with Anthropic. On the hosted web service, the same chat and document-reading features run on our key, billed to us. What is described in §8.1 is the desktop arrangement.
Landed as of
c352253: the consent record and server-side check exist (M4/M5), M10'sLLM_PHI_APPROVEDgate (apps/api/app/llm_transfer.py) hard-disables every AI path on hosted with no exception, and M9's key-entry screen exists (apps/web/app/settings/AnthropicKeyPanel.tsx). Also landed, this wave: thellm_transferconsent named in §8.1 can now be granted from/settings(apps/web/app/settings/LlmTransferPanel.tsx,api.grantConsent("llm_transfer", …)).ConsentPanel.tsxstill only withdraws consents already on record — grantingllm_transferis this separate panel's job, by design (see that file's own reasoning for why the grant sits at the point of use rather than in first-run setup). Until a tester has both a key and this consent, the gate refuses every desktop AI call with 403llm_transfer_consent_required, exactly as designed.
[COUNSEL: the full list, with roles, locations and transfer bases, belongs in
legal/subprocessors.md and the Art. 30 register. This table exists so the liability
carve-out is not abstract, and it must be kept consistent with those documents.]
If a provider stops offering its service, or changes it in a way we cannot absorb, the corresponding Helios feature may stop working. Where that happens we will tell you what stopped and why.
8.1 AI features, and the transfer to the United States
In the desktop application, the AI features (reading laboratory documents, and the chat
assistant) work only if you supply your own Anthropic API key, stored in your
own macOS Keychain, and only if you grant a specific consent for these transfers. That
consent is a standing one — you give it once, it covers only the three transfers
described in legal/privacy-policy.md §6 and nothing else, every individual transfer is
recorded in your audit log before it happens (and one that cannot be recorded is
refused), and you may withdraw it at any time with immediate effect. We describe it as
standing rather than as a fresh decision before each call, because that is what it is.
It
names Anthropic, states that the transfer is to the United States under the terms of
your own Anthropic account, and states plainly that we have not confirmed
zero-data-retention or no-training terms for that account — because we have not, and a
document must not say otherwise until procurement closes that gap (legal/subprocessors.md
§1).
The Keychain half of that is real — the desktop application stores your key there and hands it to the engine on your machine, and it is the only key the desktop can use. Landed as of
c352253: the consent record,require_consent,LLM_PHI_APPROVEDgating, and the/settingsscreen for entering the key. Also landed, this wave:/settings→ thellm_transferpanel (apps/web/app/settings/LlmTransferPanel.tsx) now grants the consent this paragraph describes (api.grantConsent("llm_transfer", …)), so a transfer to Anthropic can happen from the desktop app once a tester has both a key and this consent — refused with 403llm_transfer_consent_requireduntil then, exactly as designed.
When you grant it, health information leaves your device: for chat, that is your age, sex, medication names, biomarker values and the findings and recommendations shown to you; for document reading, it is the text of the report, with lines that look like identifiers removed but with the laboratory values deliberately kept, because the values are the thing being read. For scanned documents, whole page images are sent and no redaction is possible — if your scan shows your printed name or a hospital number, that is transmitted too.
We describe this bluntly because it is the one place where the "your data stays on your device" property of the desktop app does not hold. If you do not want that transfer, do not grant the consent and do not use the AI features; the rest of the Service works without them.
Calls made with your key are billed to you by Anthropic and are governed by your agreement with them, not by these terms.
9. Availability, changes, and no commitment to keep shipping
We may change, suspend or discontinue any part of the Service, including the whole of it, at any time. This is beta software with no service-level commitment: there is no uptime guarantee, no support guarantee, and no guarantee that the product will ever leave beta.
If we discontinue the Service we will give you reasonable notice and a window in which to export your data, unless we are prevented from doing so by law or by a safety or security emergency.
Landed as of
c352253:GET /export/archiveno longer 404s underHELIOS_AUTH=local(M8b) and answers in the desktop application. The/settings → Export my datascreen it backs is now reachable from the app chrome as well — the desktop rail carries a Settings entry and the hosted header a signed-in link — so this commitment is exercisable from inside the product, not only by calling the route.
[COUNSEL: specify the notice period, and whether a free beta requires one at all under Art. L.224-25-x C. consom.]
Because your beta data lives in an encrypted vault on your own device, discontinuation
does not by itself delete it. The vault is a folder on your own disk
(~/Library/Application Support/Helios by default) and copying it while the
application is closed preserves everything, though what you get is the encrypted form,
readable only by Helios and only with your passphrase. Discontinuation does mean the
software that reads it stops being maintained.
10. Liability
10.1 The cap
Subject to §10.2 and §10.3, our total aggregate liability to you arising out of or in connection with the Service, whether in contract, tort, or otherwise, is limited to [COUNSEL: SIZE CAP].
[COUNSEL: SIZE CAP — the usual anchor, a multiple of amounts paid in the preceding twelve months, produces zero here because the beta is free. Please set a defensible fixed euro figure instead, and consider whether a cap of any size survives Art. 1170 C. civ. (a clause depriving the essential obligation of its substance is deemed unwritten) and Art. L.212-1 C. consom. (unfair terms in consumer contracts, and the clauses noires list at R.212-1) in a contract about health information. Our instruction to you is: if a cap in this context is not enforceable against a consumer, say so and we will remove it rather than keep an unenforceable clause that looks like protection.]
10.2 What can never be capped or excluded
Nothing in these terms limits or excludes our liability for:
- Fraud and wilful misconduct (dol) — including fraudulent misrepresentation. Under Art. 1231-3 of the Civil Code, a debtor guilty of dol is liable for damages that were not foreseeable at the time of contracting, and no clause may reduce that.
- Gross negligence (faute lourde) — French case law treats faute lourde as equivalent to dol for this purpose, and a limitation clause is set aside where the breach is of that gravity, or where it defeats the essential obligation of the contract.
- Death or personal injury (dommage corporel) — Art. 1245-14 of the Civil Code makes any clause excluding or limiting liability for harm caused by a defective product to the person unwritten, and the same principle applies to bodily harm generally.
These three exceptions are not negotiable and are not stylistic. A limitation clause that omitted them would not merely be unfair — it would be unenforceable, and its presence would be evidence against us. They are stated here for that reason.
10.3 Your mandatory rights
Nothing in these terms affects your non-waivable rights as a consumer under French or EU law, including the legal guarantee of conformity for digital content and services, your rights under the GDPR, and your right to bring proceedings under §13.
10.4 What we are asking you to accept
Subject to §10.1 to §10.3, we are not liable for:
- any health outcome arising from a decision you made on the basis of Helios output without a clinician's involvement;
- a wrong result caused by a laboratory value that was extracted incorrectly and that you confirmed;
- loss of data caused by the loss of your passphrase and recovery code (§3);
- the acts, omissions or outages of the third parties listed in §8;
- indirect or consequential loss, loss of profit, loss of opportunity or loss of data, to the extent the law permits that exclusion between us.
The medical disclaimer in legal/medical-disclaimer.md explains, in plain terms, why
the first item on that list is the one that matters.
11. Suspension and termination
You may stop using the Service at any time. You can delete your account and your data from within the application; deletion is permanent.
Landed as of
c352253:DELETE /patients/{patient_id}andDELETE /account(M7,apps/api/app/erasure.py) delete the rows and the blobs —scans.delete_objectis now called from the erasure path, andassert_no_orphansre-checks the database before committing. Also landed, this wave: M9's interface for this (/settings → Delete my account and data) is now linked from the app chrome (AppRail.tsxon desktop,SiteHeader.tsxon hosted), so "from within the application" above is true in the sense of clicking a link, not only in the sense that the API it calls works.
We may suspend or terminate your access, with notice where practicable and immediately where not, if you materially breach these terms, if we reasonably believe your use presents a safety or security risk, or if we discontinue the Service under §9.
On termination the licence in §7.1 ends. Sections 2, 6, 7.2, 7.3, 10, 13 and 14 survive.
Termination does not delete the encrypted vault on your own device. If you want that
gone, delete the vault folder itself (~/Library/Application Support/Helios by
default): removing it removes the encrypted database, the header file holding the
wrapped keys, and the encrypted document blobs together, and without the header the
data cannot be read again by anyone, including us. The privacy policy explains what
deletion covers.
12. Changes to these terms
We may update these terms. If a change is material we will notify you in the application and, where the change concerns how we process your health data, we will ask for your consent again rather than assume it. Continued use after a non-material change means acceptance. [COUNSEL: notice period and the mechanics of re-consent for a consumer contract — confirm that silence cannot be treated as acceptance for material changes.]
Each version of these terms carries a version number in the front matter above. The application records which version you accepted, when, and a hash of the text you were shown, so that "which terms did I agree to" always has an answer.
Landed as of
c352253:record_acknowledgement(M4,apps/api/app/consent.py) records the document, version and a SHA-256 of the text shown, and M12's desktop first-run flow (apps/web/app/legal/first-run/FirstRunLegalFlow.tsx) writes it fortermsandhealth_data_processing.legal/beta-tester-agreement.md§12 carries the same update; the two documents are deliberately identical on this point.
13. Governing law, complaints, and jurisdiction
These terms are governed by French law.
Before going to court, you may contact us at the address in §14 and we will try to resolve the matter. As a consumer you are also entitled to free recourse to a consumer mediator under Art. L.612-1 of the Consumer Code. [COUNSEL: we must appoint a médiateur de la consommation and name them, with their postal and web address, here and on the site — the obligation applies to any professional dealing with consumers, including one supplying a free service. Confirm and name.] You may also use the European ODR platform. [COUNSEL: verify the ODR platform is still operative; the Commission has been winding it down. Do not link a dead platform in a consumer contract.]
Disputes fall to the French courts. [COUNSEL: a clause fixing exclusive jurisdiction against a consumer is void — Art. L.212-1 C. consom. and, for cross-border cases, Art. 17-19 of Regulation (EU) 1215/2012 give the consumer the courts of their own domicile. Draft this so that it does not purport to take that away.]
14. Contact
Ateliersavant Europe SAS 17 rue du Pre-Breda, B.P. 60 51200 Épernay Cedex, France SIRET 91229128300014 Email: privacy@ateliersavant.com
Engineering note, to be removed before publication: the
privacy@ateliersavant.com alias did not exist at the time of this draft; it was
created 2026-08-03 and now receives mail. That blocker on publication is closed —
counsel sign-off (front-matter status, above) is the one that remains.
15. Document control
| Field | Value |
|---|---|
| Version | 0.1.3-draft |
| Status | DRAFT-PENDING-COUNSEL |
| Drafted | 2026-07-27 |
| Effective | TBD-PENDING-COUNSEL |
| Supersedes | nothing — this is the first terms of service Helios has had |
| Reviewed by counsel | No |
Related documents: legal/medical-disclaimer.md, legal/privacy-policy.md,
legal/beta-tester-agreement.md, legal/subprocessors.md.