Halioc, Inc.

Privacy

What we receive, why, and what we never do.


This policy covers halioc.com, the malpack desktop app, the malpack command-line tool, and your Halioc account. Halioc, Inc. is responsible for the data it describes.

The short version

This website

halioc.com sets no cookies, runs no scripts and uses no analytics. Our hosting provider, Cloudflare, keeps standard operational logs of web requests, which we use only to keep the site available and secure.

The command-line tool

The free malpack command-line tool needs no account and sends no telemetry. It contacts no Halioc server. To check your packages it asks public services (the package registries, OSV.dev, deps.dev and GitHub) about package names and versions, and nothing else.

The desktop app

Scans run locally. To check a package, the app asks the same public services about its name and version. It never sends your source code or file contents. The app downloads threat-intelligence updates and app updates as files, and those downloads are logged like any web request.

Two features are optional, off until you turn them on, and use your own accounts:

  1. Your own AI provider. With your own key for Anthropic or another provider you choose, the app sends that provider a finding's package name, version and ecosystem, its type and category, its severity or confidence, the dependency depth and the finding's text, to explain it or judge whether it is a false positive. Paths in your home folder are removed first. A model running on your own machine receives the same, and nothing leaves the machine.
  2. GitHub. With your own GitHub token, the app reads dependency manifests and workflow files from the repositories you choose, to scan them.

With a subscription

A Solo or Pro subscription needs a Halioc account. We receive and keep:

We do not receive scan results, findings or package lists from Solo or Pro. Team and Enterprise plans report findings to the organization's own console; their terms say so when they are offered.

Signing in with Google

If you sign in with Google, Google shares your email address and an identifier for your Google account with us, and nothing else. We use them only to sign you in and to recognize your Halioc account. We keep them with your account, never sell or share them, and never use them for advertising. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Payments

Paddle.com, our reseller and merchant of record, takes your payment and handles tax, invoices and refunds. Paddle receives your card or other payment details; we never do. We receive your name, email address, country and the status of your subscription.

Cookies

Your Halioc account uses one essential cookie to keep you signed in. We use no advertising or analytics cookies, anywhere.

Who processes data for us

Your account data is stored in the United States, in the eastern US.

How long we keep it

Your rights

You can ask to see, correct, export or delete the personal data we hold about you, or object to how we use it. Write to hello@halioc.com and we will answer within 30 days. If you are in the European Union or the United Kingdom, you may also complain to your data protection authority. If you are in California, we do not sell or share your personal information.

Children

malpack is for people who make software. It is not directed at children under 16, and we do not knowingly collect their data.

Changes

If we change how we handle data, this page says so before the change takes effect, and account holders hear about material changes by email first.

Halioc, Inc., 718 Thompson Lane, #108-274, Nashville, TN 37204, United States. hello@halioc.com

Effective October 8, 2026.

Halioc, Inc./halioc.com/Home

© 2026 Halioc, Inc. All rights reserved.