Your information and this workbench
This notice explains what personal information is used to operate Voynich Online and the private research workbench.
Last updated 18 July 2026
Who is responsible
Helix Intelligence operates Voynich Online and is responsible for the personal information described in this notice. The service is hosted in Europe and is intended for manuscript research and related public information.
Information we collect
Why we use it
- To create and administer your account, verify your email and provide the workbench you requested.
- To preserve authorship, provenance and review history for research records.
- To secure the service, prevent abuse, investigate failures and maintain recoverable backups.
- To send essential account messages such as verification and password-reset emails.
- With your consent, to send optional project, access and newsletter updates. You can unsubscribe at any time.
- To answer support, privacy and accessibility requests.
Our principal legal bases are performance of the service agreement, our legitimate interests in operating and securing a research service, and compliance with legal obligations where they apply. We do not use account information for advertising or unrelated marketing.
Cookies and public-site analytics
The signed-in workbench uses only essential cookies: a secure session cookie and a separate anti-forgery cookie. They are required to keep you signed in and protect account actions. Voynich Online does not use advertising or analytics cookies.
We use a self-hosted Matomo service to produce aggregate statistics about visits to public information pages. It runs without cookies and is not loaded on sign-in, account, recovery, waiting-list, API or workbench pages. Query strings and fragments are excluded. Matomo uses the connection address transiently to resolve an approximate location, masks two bytes before storing the address, disables visitor profiles, and deletes raw visit logs after two days. The information is not used for advertising, cross-site tracking or individual profiling.
The sole purpose is to understand how the public site is used and improve it. We rely on our legitimate interests in operating and improving the service and the statistical-purpose exception in the UK rules on storage and access technologies. You can object at any time using the control below.
Public-site analytics are enabled on this browser.
Who processes information
Personal information may be processed by service providers used to run Voynich Online, including Hetzner for hosting, Cloudflare for network and DNS services, and Resend for transactional account email. We disclose only the information needed for each service. We do not sell personal information.
Some suppliers may process information outside the United Kingdom. Where UK data-protection law requires a transfer safeguard, the relevant provider terms and transfer mechanism apply.
How long we keep it
- Active sessions expire after no more than 14 days and after 24 hours without activity.
- Email-verification links expire after 24 hours; password-reset links expire after one hour.
- Account and research records are kept while the account and its research history are needed.
- Waiting-list information is kept until access has been offered, you unsubscribe, or it is no longer needed for the stated purpose.
- Security events, acknowledgement records and backups are retained only as long as reasonably needed for security, audit, dispute resolution, source obligations and legal requirements.
Self-service account deletion is not yet available. You can request deletion or anonymisation by contacting us. Some provenance, acknowledgement or security records may need to be retained where there is a lawful reason.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to or receive a portable copy of your personal information. These rights are not absolute and the applicable right can depend on why the information is used.
There is no solely automated decision-making that produces legal or similarly significant effects. You may also raise a concern with the UK Information Commissioner’s Office.
Security and changes
Passwords are stored as Argon2id hashes, authentication tokens are stored only as hashes, account cookies use secure browser protections, and state-changing account actions use anti-forgery checks. No internet service can promise absolute security.
We will update this notice when the service or its data use changes materially. The latest version and update date will remain on this page.