Privacy

Last updated: 1 August 2026

Helaia is the personal site of one person — Oliver Herbelin. This page explains, in plain words, what happens to your data when you visit. The short version: no accounts, no ads, no selling of anything, and two ways of counting — one bought off the shelf, one written by hand.

1. Analytics — Microsoft Clarity

This site uses Microsoft Clarity to understand how visitors use it: which pages are read, where people click and scroll, on what kind of device. Clarity may record anonymized session replays and build heatmaps. To do this it sets cookies and collects technical data (browser, screen size, approximate region, interactions). This data is processed by Microsoft on my behalf; I use it only to improve the site. It is never used for advertising and never sold. Microsoft’s handling of this data is described in the Microsoft Privacy Statement.

2. The counter I wrote myself

Alongside Clarity, the site counts a few things on its own, with code I wrote and host myself: how many pages are read and which ones, which songs are played, and when someone copies a set of lyrics. It sets no cookie, stores no persistent identifier, and asks for no consent because there is nothing to consent to — nothing that identifies you is kept. To tell one visitor from two on the same day, the server derives a one-way fingerprint from your IP address and browser signature, mixed with a secret that is regenerated every night; the address itself is never written down, and the fingerprint of today cannot be matched to the fingerprint of tomorrow. Those fingerprints are deleted automatically after 45 days. Copying lyrics records only which song it was — never the text, never anything you typed. Requests that look like robots are ignored. The resulting numbers are plain totals with nobody behind them, and they are visible to me alone, on a password-protected page.

3. Hosting and server logs

The site is served by Amazon Web Services (S3 + CloudFront). Like any web server, CloudFront writes standard access logs — time, requested page, IP address, browser — to a private storage bucket that only I can read. I keep them for two reasons: security, and as an independent check on the counter above, since a counter that only ever agrees with itself proves nothing. They are deleted automatically after 90 days, are not linked to any identity, and are never used to build a profile of anyone.

4. Contact forms

The contact page has no server behind it: the “form” simply opens your own mail app with a pre-filled message. Nothing is transmitted or stored by this site. When you email me, your message lives in my mailbox and is used only to answer you.

5. The apps

The applications published by Helaia (QuickestLook, Localizee, Statee) each have their own privacy policy, available from their pages. They are built on the same principle: local first, no telemetry.

6. Your rights

Under the GDPR and similar laws, you can ask what data concerns you, ask for it to be corrected or deleted, or object to its processing. In practice: Clarity is the one place where data about you is handed to a third party, and you can block it entirely with any content blocker or your browser’s tracking protection — the site works exactly the same without it. The counter I wrote can be blocked the same way; and since it keeps nothing that points back to you, there is nothing there to hand over or erase on request. Server logs are the only place an IP address is written down, and they expire on their own after 90 days. For any request: hello@helaia.com.

7. Changes

If the site’s practices change — a new tool, a new need — this page will be updated first, and the date at the top will reflect it.