Whole Gene Health
How It WorksWhat You GetComparePricingFAQ
The ScienceArticles
Partners
Back to Home

Data Handling Policy

Last Updated: June 26, 2025

Our Commitment to Your Genetic Privacy

Your genetic data is among the most personal information you can share. We treat it with the utmost respect and security. This policy explains exactly what happens to your data at every step.

1. Overview: Your Data Journey

1

Upload

You upload your raw DNA file through our secure, encrypted connection

2

Process

Professional genetic analysis services extract relevant variant information

3

Deliver

Your personalized report is sent to your email

4

Delete

Your raw DNA file is permanently deleted within 7 days of delivery

2. What We Collect

Genetic Data

  • Raw DNA data file (typically .txt or .zip format from 23andMe or AncestryDNA)
  • Specific genetic variants (SNPs) relevant to our analysis

Personal Information

  • Email address (required for report delivery)
  • Name (optional)
  • Payment information (processed by Stripe, not stored by us)

Technical Data

  • IP address and browser information (for security)
  • Transaction records (for customer service and refunds)

3. Data Retention Schedule

Data TypeRetention PeriodReason
Raw DNA FileDeleted within 7 daysAfter report delivery and quality confirmation
Generated Report (PDF)90 daysCustomer support and re-delivery
Processed Genetic Data90 daysFor questions about specific variants
Data Sent to AI Report Generator (Anthropic)Deleted within 30 daysHeld by our AI processor to generate your report; not used for model training
Email AddressUntil you request deletionCustomer service and updates
Transaction Records7 yearsLegal and tax requirements

Note: The 7-day deletion window applies to your raw DNA file, which is stored only on our own servers and is never sent to any AI processor. To generate your report, we send your extracted genetic variant analysis and health profile—not your raw DNA file, and not your name—to our AI processor (Anthropic's Claude API). That processor retains what we send it for up to 30 days for safety and security purposes, after which it is not retained. It is never used to train AI models. See Section 6 for full details on this AI processor.

4. Security Measures

Encryption in Transit

All data transfers use TLS 1.3 encryption. Your DNA file is encrypted the moment it leaves your device.

Encryption at Rest

While stored (briefly), your data is encrypted using AES-256 encryption.

Access Controls

Only essential automated systems access your genetic data. No human views your raw genetic file.

Secure Deletion

We use cryptographic erasure to ensure your genetic data cannot be recovered after deletion.

5. What We Do NOT Do

✗

We do NOT sell your genetic data to anyone—ever

✗

We do NOT share your data with insurance companies

✗

We do NOT share your data with employers

✗

We do NOT use your data for research without explicit consent

✗

We do NOT keep your raw genetic file long-term

✗

We do NOT share your data with third-party marketers

✗

We do NOT create genetic databases for sale

6. Third-Party Services

Your raw DNA file is processed through professional genetic analysis services that specialize in extracting and interpreting genetic variant information. These services:

  • Have strict data retention and deletion policies
  • Do not sell or share genetic data with third parties
  • Do not use data for research without explicit consent
  • Maintain their own comprehensive privacy policies

See our Privacy Policy for complete details on third-party data processors.

Payment & Infrastructure Services

  • Stripe: Handles payment securely. We never see or store your full credit card number. View Stripe's Privacy Policy
  • Email Service Provider: Used to deliver your report. They do not have access to your genetic data, only your email address.
  • Cloud Infrastructure: Our servers use industry-standard cloud infrastructure with SOC 2 compliance. All data processing occurs in secure, access-controlled environments.
  • AI Report Generation (Anthropic Claude API): Your extracted genetic variant analysis and health profile (weight, age, sex, medications, health conditions) are sent to Anthropic's Claude API to generate your report. Your raw DNA file is never sent—it stays on our own servers. Your name is also never sent: it is replaced with a neutral placeholder before the request goes out and reinserted only when your report is rendered. Anthropic retains this data for 30 days for safety and security purposes and then does not retain it further. We have model-improvement feedback disabled and have not joined any Anthropic data-sharing program, so this data is not used to train AI models. Anthropic's infrastructure is SOC 2 compliant.

7. Your Rights and Controls

Request Data Deletion

Contact us at privacy@wholegene.health to request deletion of any personal information we hold. We will comply within 30 days.

Access Your Data

You can request a copy of all personal information we have about you.

Correction

If any information we have is incorrect, contact us and we'll correct it.

Withdraw Consent

You can withdraw consent for future data processing at any time (note: this won't affect your already-delivered report).

8. Legal Disclosure

We may disclose your information only if required by law:

  • Valid court order or subpoena
  • Legal requirements in our jurisdiction
  • Protection of our legal rights

However, since we delete your raw genetic data within 7 days of report delivery, we typically won't have it available even if legally requested. We will notify you of any legal requests unless prohibited by law.

9. Data Breach Procedures

In the unlikely event of a data breach:

  • We will notify affected users within 72 hours
  • We will notify relevant authorities as required by law
  • We will provide clear information about what data was affected
  • We will take immediate steps to secure systems and prevent further breaches

Note: Because we delete raw genetic data quickly, the risk window for the most sensitive information is minimized.

10. International Transfers

Your data may be processed in the United States. If you are located outside the US, your data will be transferred to the US for processing. We ensure appropriate safeguards are in place, including standard contractual clauses where required.

11. Changes to This Policy

We may update this Data Handling Policy to reflect changes in our practices or legal requirements. We will:

  • Post the updated policy on our website
  • Update the “Last Updated” date
  • Notify existing customers of material changes via email

12. Contact Us

For questions about how we handle your data, or to exercise your data rights:

Data Protection Contact:
Email: privacy@wholegene.health

We aim to respond to all inquiries within 48 hours during business days.

13. Genetic Information Nondiscrimination Act (GINA)

In the United States, the Genetic Information Nondiscrimination Act (GINA) provides some protections against genetic discrimination in health insurance and employment. However, GINA does not cover life insurance, disability insurance, or long-term care insurance. We encourage you to understand your rights under GINA and related state laws.

Whole Gene Health

Comprehensive genetic analysis with actionable supplement protocols.

Product

How It WorksWhat You GetCompare ServicesPricing

Support

FAQContact UsSample Report

Learn

The ScienceDNA & SupplementsWhy Personalized?For Practitioners

Partners

Become a PartnerPartner Login

Legal

Privacy PolicyTerms of ServiceMedical DisclaimerData Handling Policy

© 2025 Whole Gene Health, LLC. All rights reserved.

Medical Disclaimer: This service provides educational information only. We make no medical claims and do not diagnose, treat, cure, or prevent any disease. Not medical advice. These statements have not been evaluated by the FDA. Results vary by individual. Consult a qualified healthcare provider before starting any supplement regimen. Your raw DNA file is securely deleted within 7 days of report delivery.