Privacy
Privacy policy
The short version: your DNA file never reaches us, and we have built the site so that it cannot. Everything else on this page is detail, and none of it contradicts that sentence.
Last updated 22 September 2026.
Your DNA file
It is never uploaded. When you load a file, it is read by your own browser using the browser’s file API, parsed in memory, and discarded when you close the tab. There is no upload endpoint in this application. There is no account, no profile and no database of genetic data, because there is nothing to put in one.
You do not have to take that on trust. Open your browser’s developer tools, switch to the network tab, and load your file. You will see no request carrying it, because none is made.
Nothing derived from your file is transmitted either: not a genotype, not a haplogroup, not a result, not a file name, not a summary. The CSV and PDF exports are written by your browser and never exist on a server.
What we do collect
Page analytics
This site uses Google Analytics (property G-TDBXETCYR0) to count page views, so we know which pages people find useful. It records the pages you visit, roughly where in the world you are, and what kind of device you used. It is subject to Google’s own privacy terms.
The analytics code on this site can only send a fixed list of event names such as “file loaded” or “export pdf”. It is written so that there is no parameter to put anything else in. No genetic data, no genotype, no haplogroup and no file name is ever sent to analytics or to anyone else. If you use a browser or extension that blocks analytics, every part of this site still works.
Payment
Payments are processed by Stripe. We never see or store your card details. Stripe holds the payment record, including the email address you give at checkout, under its own privacy policy.
We deliberately do not keep a database linking licence keys to people. A key carries its own tier and expiry inside itself and is verified cryptographically, so no list of who bought a DNA report exists here to be breached, subpoenaed or sold. The practical consequence is that if you lose your key we have to find your payment in Stripe to help you, which we are happy to do.
Your licence key
Your key is kept in your browser’s local storage. It is sent to our server only to be checked and to fetch the marker panel. It is never sent alongside anything derived from your file, and it cannot be linked to your genetic data because your genetic data never arrives.
Messages you send us
If you use the contact form, we receive your name, email address, chosen topic and message, delivered by SendGrid to a mailbox we read. We keep correspondence for as long as it is useful for support and then delete it. Please do not paste genetic data into that form.
What we never do
- Sell, share or license genetic data, because we do not have any.
- Build a profile of you across sites.
- Pass anything to insurers, employers, law enforcement or data brokers.
- Use your data to train anything.
These are not promises we are asking you to trust so much as descriptions of a system that has no way to do them.
Your rights
If you are in the UK, EU or a jurisdiction with comparable law, you have the right to ask what personal data we hold about you, to have it corrected, and to have it deleted. In practice the only personal data we are likely to hold is correspondence and, in Stripe, a payment record. Write to us through the contact form and we will act on it.
To remove your key from a device, clear site data for this site in your browser, or use a private window.
Children
This site is not intended for anyone under 16, and we do not knowingly collect data from children.
Changes
If this policy changes in a way that affects you, the date at the top will change and the substance of the change will be described here rather than buried.