Privacy by architecture


Privacy Policy

DAO governance principlesImmutable contractOn-device genomics

Explore raw DNA on-device. When a connected feature moves data, Genodex explains the path. If you choose to publish, public means public.



Privacy Policy

Genodex · Draft for legal review


Draft for legal review — not approved for production publication. Last updated: August 11, 2026.

This Privacy Policy explains how Genodex ("Genodex," "we," "us," or "our") handles information through the Genodex website, mobile application, and related services (together, the "Services"). It describes the Services as they operate today. It does not promise future features or guarantee that any system is risk-free.

Plain-language overview

  • A compatible raw DNA file can be parsed and used to calculate supported educational GWAS-based results on your device. This is the default path for personal exploration.

  • Genodex does not require you to publish a genome in order to calculate those supported results locally.

  • If you deliberately publish a genome, the genomic archive and associated public record are uploaded to Genodex infrastructure and made available as a public contribution under Creative Commons Zero (CC0).

  • Public genomic data is not anonymous. It may identify you, reveal information about biological relatives, and be linked with other information now or in the future.

  • Optional AI reports and Genome Chat send selected calculated results, supporting scientific facts, relevant genome metadata, and the text you submit to OpenAI. AI explains existing calculations; it does not calculate the scientific score.

  • Genodex uses service providers named below to operate accounts, hosting, AI features, purchases, analytics, crash reporting, and notifications.

  • The current in-app control labeled "Delete Account" removes local genome data and signs you out. It does not by itself delete your Firebase Authentication account or all server-side data. Contact joe@genodex.org for a formal access, correction, export, or deletion request.

1. Scope and roles

This Policy applies to information handled by Genodex through the Services. It does not govern an external project, publication, app store, operating system, or website linked from the Services. Those parties apply their own terms and privacy practices.

For personal information that Genodex determines how and why to process, Genodex acts as the relevant operator or controller to the extent required by applicable law. A qualified legal adviser must confirm the appropriate legal role and jurisdiction-specific disclosures before this draft is published as an effective policy.

2. The two genomic paths

Private, on-device exploration

When you import a compatible raw DNA file, the app can parse variants and calculate supported phenotype estimates on your device. Raw file contents, local variant indexes, locally calculated scores, and locally stored results are not uploaded merely because you import the file or run those calculations.

Information can still leave the device when you choose a connected feature. Examples include signing in, publishing a genome, requesting an AI report, using Genome Chat, sending a support request, enabling notifications, or using purchase features. Device backups and operating-system services are controlled separately by you and their providers.

Explicit public contribution

When you complete the publish-genome flow, Genodex uploads a genomic archive and creates or updates a server-side genome record marked public. Public records may include a public name or identifier, genome metadata, project or organization relationships, phenotype results, variants or result context, and timestamps or technical identifiers used to operate the catalog.

Publishing is distinct from local analysis. Do not publish data unless you have the right to do so and understand that the contribution is intended to be public.

3. Information we handle

Depending on the features you use, Genodex and its providers may handle:

  • Account and profile information: account identifier, email address, authentication provider, profile fields, preferences, language, account timestamps, and consent or acknowledgement records.

  • Local genomic information: the raw DNA file, indexed variants, local genome metadata, and calculated results retained on your device.

  • Public genomic contributions: the uploaded genomic archive, public genome record, public metadata and results, source or project relationships, and information needed to index and display the contribution.

  • AI feature information: selected calculated results, phenotype and model facts, linked studies and variants, uncertainty or coverage values, relevant genome metadata such as genome identifier and available demographic context, the prompt or message you submit, recent conversation context, and the generated response. Genodex is not designed to send the entire raw DNA archive to OpenAI for these features.

  • Community and content information: comments, annotations, messages, discussions, reports, or other material you choose to submit where those features are available.

  • Purchase information: product identifiers, entitlement and subscription status, transaction references, and related purchase metadata. Genodex does not receive your full payment-card number from Apple or Google.

  • Device and operational information: device and app information, push-notification token, IP address and request metadata received by hosted services, security events, analytics events, diagnostics, crash reports, and performance information.

  • Support communications: your email address, message, attachments you provide, and information needed to respond.

4. How information is used

We use information to:

  • provide authentication, account, catalog, community, and support functions;

  • calculate and display supported results on the device;

  • publish and distribute a genome only after the explicit publishing action;

  • generate AI explanations and support Genome Chat when requested;

  • verify purchases and manage access to subscription features;

  • deliver notifications you enable;

  • maintain security, prevent abuse, diagnose failures, and understand service performance;

  • comply with applicable legal obligations and enforce the Terms of Use; and

  • correct, update, and maintain public evidence and provenance.

We do not sell raw genomic files. Public contributions are, however, deliberately made available for broad reuse under CC0; that public release is not a private sale and should not be understood as confidential processing.

5. Public genomes and CC0

The publish-genome flow asks you to dedicate the uploaded contribution under Creative Commons Zero 1.0 Universal. CC0 is intended to waive copyright and related rights covered by the dedication to the extent legally possible and permit broad reuse, including commercial reuse.

CC0 is not an anonymity tool, a security control, or a waiver of every privacy, publicity, personality, genetic-data, family, or third-party right. You remain responsible for confirming that you are authorized to publish the data. Do not publish another person’s genome or a minor’s genome unless you have a lawful and fully informed basis to do so.

A public genomic contribution can be copied, indexed, combined with other datasets, redistributed, and retained by third parties. Removing a Genodex-hosted copy cannot retract copies already obtained by others or reverse rights already dedicated under CC0. Because genomic data is persistent and can implicate biological relatives, the privacy consequences may extend beyond you and may change as re-identification techniques develop.

6. AI explanations

AI reports and Genome Chat are optional connected features. When used, Genodex prepares a limited context from existing calculated results and connected scientific records, and transmits that context together with your request to OpenAI. Genome Chat may also send recent conversation context. OpenAI generates explanatory text; the Genodex calculation engine, not OpenAI, produces the underlying scientific score.

The current OpenAI Responses API integration is configured with response storage enabled. This means OpenAI may retain response application state and related input/output data under its API data controls, retention settings, and legal obligations. OpenAI states that API data is not used to train its models by default unless the customer opts in, but its current policies and any configured exceptions should be reviewed before using the feature.

Do not include names, contact details, medical records, or other information you do not want transmitted in an AI prompt. AI output may be inaccurate and is educational only.

7. Providers and disclosures

Genodex currently relies on:

  • Google Firebase and Google Cloud for authentication, Firestore databases, file storage, callable and hosted services, analytics, crash reporting, and cloud messaging;

  • OpenAI for optional AI reports and Genome Chat;

  • RevenueCat for subscription and entitlement management;

  • Apple App Store and Google Play for app distribution, purchases, and store-managed subscriptions; and

  • infrastructure, security, and professional advisers where reasonably necessary to operate the Services or comply with law.

These providers process information under their own terms and data-processing arrangements. Information may be processed in countries other than the one where you live. Applicable safeguards and rights vary by jurisdiction.

We may also disclose information when reasonably necessary to respond to valid legal process, protect users or the Services, investigate abuse, or complete an organizational transaction subject to appropriate protections. Public genomic contributions and other intentionally public content are available to anyone.

8. Legal grounds

Where law requires a legal basis, the basis depends on the feature and jurisdiction and may include performance of a user-requested service, consent or explicit consent, legitimate interests in operating and securing the Services, and compliance with legal obligations. Publishing sensitive genomic information may require explicit consent or another specific legal condition. CC0 does not replace data-protection consent or another legal basis.

This draft does not determine which law applies to a particular user. Counsel must confirm the final legal-basis language for the regions where Genodex is offered.

9. Retention

  • Local genomic data remains on the device until you remove it, clear application data, or uninstall the app, subject to device backups you control separately.

  • Account, profile, community, operational, and security information is retained for as long as reasonably needed for the feature, security, dispute handling, and legal obligations.

  • Public genomic contributions may remain available indefinitely because they are published for open reuse. Third-party copies are outside Genodex’s control.

  • AI inputs and outputs are retained according to Genodex’s records and the configured OpenAI API storage and retention settings.

  • Purchase records are retained by RevenueCat and the relevant app store according to their policies and as needed to manage entitlements.

  • Backups, logs, and support records may remain for a limited operational or legal period after active data is removed.

Specific retention periods have not been represented here where the current implementation does not establish a reliable fixed period. Counsel and operations must confirm a production retention schedule.

10. Your choices and rights

You can choose not to publish a genome and not to use AI, community, notification, or purchase features. You can remove local genomes through the app and control notifications through the app or device settings where available.

Depending on where you live, you may have rights to request access, confirmation, correction, portability, deletion, restriction, objection, withdrawal of consent, or review by a privacy authority. These rights are not absolute and may require identity verification.

For a formal request concerning information held by Genodex, email joe@genodex.org from the address associated with your account and describe the request. The in-app control currently labeled "Delete Account" removes local genome data and signs you out; it does not by itself delete the Firebase Authentication account or all information stored on Genodex servers.

For public genomic contributions, a request may result in removal from Genodex-controlled hosting where legally required or operationally feasible, but it cannot revoke CC0, recover downstream copies, or guarantee disappearance from search engines, caches, mirrors, or third-party datasets.

11. Children

The Services are not directed to children. Do not create an account or submit genomic data if you are below the age required to consent in your jurisdiction. Do not submit a child’s or another person’s genomic data without a lawful basis and appropriate authority. Genodex may remove content or restrict an account when it learns that data was submitted without appropriate authorization.

12. Security

Genodex uses technical and organizational measures intended to protect non-public information, including provider access controls and encryption in transit. No system, device, public archive, or transmission method is completely secure. Once genomic data is published, confidentiality is incompatible with the intended public distribution.

13. Changes and contact

We may revise this Policy as the Services, providers, or laws change. A production policy should state its effective date and provide appropriate notice of material changes. Continued use alone may not constitute valid consent where law requires a separate action.

Questions, privacy requests, or complaints may be sent to joe@genodex.org.

Counsel review required: Before publication, qualified counsel must confirm the operator identity and contact disclosures, territorial scope, legal bases, sensitive-data conditions, international-transfer safeguards, retention schedule, children’s rules, consumer-health and genetic-privacy requirements, rights-response process, CC0 consent language, and provider agreements.