Privacy Policy
Last updated: September 2026
The big promise
We will never sell or license your genetic data to insurance companies, employers, or any third party. Your genome is uniquely identifying, and we treat it accordingly.
Service area — United States only
GeneticCoding.com is available only to residents of the United States. It is not available to residents of the EU, UK, or EEA. If you are located in or are a resident of the EU/UK/EEA, do not create an account, purchase, or upload data — GDPR's special-category protections for genetic data are not satisfied by this service at this time.
Pseudonymization, not anonymization
Genetic data cannot be truly "anonymized" the way a name or email can — your genome is itself an identifier. We do not claim it can be. Instead, we pseudonymize it so that a database breach, an internal support ticket, or a subpoena narrowly scoped to "customer records" does not trivially hand over a person's genome.
Here's how the data model works:
- Identity store: your email, hashed password, billing reference (a Stripe customer ID — no card data stored locally), and account settings. This store has no column that points at genetic content.
- Genome store: keyed by a randomly generated surrogate ID that is derived from none of your personal information. Every uploaded file, parsed variant, and report references this surrogate ID.
- Link store: a tightly access-controlled mapping between your account and your surrogate ID, stored separately from both of the other stores. It is never joined by analytics, logging, or support tooling.
Sub-processors
We rely on the following third-party sub-processors. Each receives only the data described, for the purpose described.
- Base44 — application hosting, database, file storage, and the AI model used to generate report narratives. Receives your pseudonymized genetic variant data and account identifiers as needed to generate and store reports.
- Stripe — payment processing. Receives your email and payment details; does not receive your genetic data or reports.
- Email provider — transactional email delivery (verification, receipts, report-ready, monitoring digests, security alerts). Receives your email address and non-genetic message content only.
Genetic variant and report content is transmitted to the AI model provider as part of report generation. We do not send your raw DNA file to AI models — only the parsed, catalog-referenced variant context required to write the narrative.
We will notify active account holders via email before adding or replacing a sub-processor that will process your genetic data.
Encryption
Raw uploaded DNA files are stored in private, AES-256-encrypted object storage that is never publicly addressable, and never filed under your email or name.
Any genotype call we retain is additionally encrypted at the field level under data keys that are themselves wrapped under a master key which is never stored alongside the data it protects. Data keys rotate on an automated schedule, and retired key versions are tracked and decommissioned once they no longer protect any data.
Data residency
All of your data — raw files, reports, the derived variant index, and account records — is stored and processed exclusively in the United States by U.S.-based infrastructure providers. We do not transfer genetic data across borders.
Data retention
- Raw DNA files are deleted automatically 30 days after report generation by an automated daily job — once the reference is destroyed, a privately stored file can no longer be reached at all — unless you opt in at upload time to keep them for re-processing.
- A derived variant index (rsIDs plus individually encrypted genotype calls, no other file contents) is retained while your account exists and either (a) you have an active Monitoring subscription, or (b) you've opted to keep your raw file. Otherwise it's deleted when the raw-file window expires.
- If you cancel Monitoring, your derived variant index is deleted within 30 days unless you've separately opted to retain the raw file.
- Reports persist until you delete your account.
- We retain a record of your informed consent (what you affirmed, when, and the policy versions in effect) for as long as required to demonstrate compliance, even after account deletion.
No genetic content in logs or analytics
No genetic content, rsIDs, genotypes, or condition names ever appear in application logs, error messages, or analytics events. We log the surrogate genome ID and job status only.
Research use
We do not use your genetic data, variant index, or reports for research, product development, or aggregate statistics, and we do not share them for those purposes. If we ever seek to do so, we will ask for your separate, explicit opt-in consent.
Your privacy rights (US state laws)
Subject to verification, you have the right to:
- Know what personal and genetic data we hold about you.
- Access and receive a copy of your data.
- Delete your account, uploaded file, variant index, and reports.
- Correct inaccurate account information (genetic data itself cannot be "corrected" — it is what your file contains).
- Port a machine-readable copy of your report and account data.
- Opt out of any "sharing" or "sale" of personal information (see below).
To exercise these rights, contact us from the address on your account via the Contact page. We verify requests using your logged-in account and may ask for additional confirmation before disclosing or deleting sensitive data. We respond within 45 days, as required by applicable law.
Do Not Sell or Share My Personal Information
We do not sell your personal or genetic data, and we do not share it for cross-context behavioral advertising. Under laws such as the California Consumer Privacy Act (CCPA/CPRA), "sale" and "share" are defined broadly; neither applies to our practices. You may opt out at any time by contacting us, and you will never lose features by doing so.
Security and breach notification
We protect genetic data with the pseudonymization and encryption model described above, strict access controls, and least-privilege backend functions. No security measure is perfect, and your genome is inherently identifying.
If a breach occurs that compromises your genetic data or account, we will notify affected users without undue delay by email to the address on file, including what we know, what we're doing, and steps you can take. Some state laws require this notice within a specific timeframe; we aim to notify within 30 days of confirming a breach.
Your deletion rights
You can delete your account at any time from your settings. This permanently deletes your account, the uploaded file, the derived variant index, and all generated reports per the retention rules above.
New-device sign-in alerts
Every sign-in from an unrecognized device, browser, or IP triggers an email with device, approximate location (city/region only), and timestamp, plus a one-click "this wasn't me" link that forces a password reset and session invalidation.
We send only transactional emails (verification, login alerts, receipts, report-ready, monitoring digests, trial reminders, password resets, deletion confirmations). No marketing email without separate opt-in.
Children
You must be 18 or older to create an account. We do not knowingly accept genetic data from minors.
Genetic information and insurance
Under the US Genetic Information Nondiscrimination Act (GINA), health insurers and employers may not use your genetic information against you. GINA does not cover life, disability, or long-term-care insurance. Consider this before purchasing or sharing your report.
