Privacy
What we receive, why, and what we never do.
This policy covers halioc.com, the malpack desktop app, the malpack command-line tool, and your Halioc account. Halioc, Inc. is responsible for the data it describes.
The short version
- Scans run on your machine. We never receive your source code, the contents of your files, or the list of packages you have installed.
- A subscription needs an account. We keep what running it requires: who you are, your plan and your devices.
- We do not sell or share your data for advertising, and we do not use it to train AI models.
- The user is the customer, never the product.
This website
halioc.com sets no cookies, runs no scripts and uses no analytics. Our hosting provider, Cloudflare, keeps standard operational logs of web requests, which we use only to keep the site available and secure.
The command-line tool
The free malpack command-line tool needs no account and sends no telemetry. It contacts no Halioc server. To check your packages it asks public services (the package registries, OSV.dev, deps.dev and GitHub) about package names and versions, and nothing else.
The desktop app
Scans run locally. To check a package, the app asks the same public services about its name and version. It never sends your source code or file contents. The app downloads threat-intelligence updates and app updates as files, and those downloads are logged like any web request.
Two features are optional, off until you turn them on, and use your own accounts:
- Your own AI provider. With your own key for Anthropic or another provider you choose, the app sends that provider a finding's package name, version and ecosystem, its type and category, its severity or confidence, the dependency depth and the finding's text, to explain it or judge whether it is a false positive. Paths in your home folder are removed first. A model running on your own machine receives the same, and nothing leaves the machine.
- GitHub. With your own GitHub token, the app reads dependency manifests and workflow files from the repositories you choose, to scan them.
With a subscription
A Solo or Pro subscription needs a Halioc account. We receive and keep:
- Your account: your email address, your name if you give it, and how you sign in (an emailed link, GitHub or Google).
- Your plan: which plan you hold, its term and its status, from our reseller.
- Your devices: a name and identifier for each machine you activate, its operating system and the app version, so the plan's machine limit works and you can see and remove devices.
- License renewals: the app renews its license with our service periodically. Each renewal carries the device identifier and app version.
- Managed AI requests: when the app uses the AI included in your plan, the finding details described above pass through our service to our AI providers. We count them against your allowance and check them for misuse, keeping only the counts, never their content. Our providers never train on them and may keep them for up to 30 days.
- Your messages to us, when you write to support.
We do not receive scan results, findings or package lists from Solo or Pro. Team and Enterprise plans report findings to the organization's own console; their terms say so when they are offered.
Signing in with Google
If you sign in with Google, Google shares your email address and an identifier for your Google account with us, and nothing else. We use them only to sign you in and to recognize your Halioc account. We keep them with your account, never sell or share them, and never use them for advertising. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Payments
Paddle.com, our reseller and merchant of record, takes your payment and handles tax, invoices and refunds. Paddle receives your card or other payment details; we never do. We receive your name, email address, country and the status of your subscription.
Cookies
Your Halioc account uses one essential cookie to keep you signed in. We use no advertising or analytics cookies, anywhere.
Who processes data for us
- Cloudflare: our network, website hosting, email delivery and file storage.
- Our hosting provider for the account service and its database. Named here before accounts open.
- Paddle: payments, tax and invoices.
- Google Workspace: our email, when you write to us.
- Our AI providers for managed AI. Named here before managed AI is offered.
Your account data is stored in the United States, in the eastern US.
How long we keep it
- Your account for as long as you have it. Delete it from your account page, or ask us, and we erase it within 30 days, except what the law makes us keep.
- Records of purchases for as long as tax law requires, which can be several years.
- Operational logs for up to 30 days.
- Backups roll off within 90 days.
- Records of what our staff did on an account (an audit log of lookups and changes) for one year. If you delete your account, your personal details are removed from those records, and the records themselves are deleted at the end of the year.
Your rights
You can ask to see, correct, export or delete the personal data we hold about you, or object to how we use it. Write to hello@halioc.com and we will answer within 30 days. If you are in the European Union or the United Kingdom, you may also complain to your data protection authority. If you are in California, we do not sell or share your personal information.
Children
malpack is for people who make software. It is not directed at children under 16, and we do not knowingly collect their data.
Changes
If we change how we handle data, this page says so before the change takes effect, and account holders hear about material changes by email first.
Halioc, Inc., 718 Thompson Lane, #108-274, Nashville, TN 37204, United States. hello@halioc.com
Effective October 8, 2026.