This is a draft Privacy Policy for Haeckel v1. Final policy pending legal review. By using Haeckel, you agree to the practices described here. We will notify users of any material changes before they take effect.
Data we collect
Haeckel collects the genomic data you upload (SNP chip files from 23andMe, AncestryDNA, FTDNA, or VCF/FASTQ from whole-genome sequencing), biomarker measurements you choose to enter, and profile information you provide. Account identity is managed by our authentication partner Clerk and includes your email and any social-login identifiers you choose to connect.
How we process your data
Your genome is processed by our analysis pipeline to produce ancestry, health, trait, pharmacogenomic, nutrigenomic, and evolutionary insights. Depending on the model and compute source you select, AI conversations with Mirror may be processed by Anthropic, OpenAI, Google, or xAI for text generation; OpenAI text-embedding-3-small is used for vector embeddings in search and recommendation. When you start voice transcription, live microphone audio is sent to ElevenLabs for transcription. If ElevenLabs Scribe is unavailable, your browser's built-in speech-recognition service may process that audio instead under the browser vendor's terms. When you enable voice output, text may be sent to ElevenLabs for voice synthesis. Provider processing and retention are governed by the applicable vendor terms and account settings; Haeckel does not promise zero retention for voice data. Managed requests are governed by Haeckel's agreements with those providers. Requests made with My API are governed by the terms of your own provider account, which you should review before sending sensitive data.
Billing and payment processing
If paid billing is enabled and you start a purchase, checkout is hosted by Whop, our third-party payment processor. Whop acts as merchant of record solely for payment processing; it does not supply the Haeckel service. Haeckel/Heru remains the service supplier, subject to final identification of the contracting Heru entity in the draft Terms. Haeckel sends Whop your billing email, the selected plan, a Haeckel account identifier, and a checkout-intent identifier. Whop processes the payment credentials entered in its hosted checkout and sends Haeckel account-scoped checkout, membership, payment, refund, and dispute events. Haeckel stores provider identifiers, the selected plan and billing interval, USD transaction amounts and statuses, billing-period dates, and the associated credit ledger. Haeckel does not ask you to enter full payment-card details on Haeckel. Whop's own privacy terms also apply to its processing.
Storage and encryption
Genomic files are stored in Cloudflare R2 with encryption at rest. Analysis results, embeddings, and account state live in a managed PostgreSQL database (Neon) with encryption at rest and TLS in transit. Backups follow the same protections. Internal access is limited to the personnel required to operate the platform.
Retention
We retain your data for as long as your account remains active. After a full-account deletion request passes the billing-safety checks described below and deletion is completed, your genomic files, analysis results, embeddings, and profile data are removed from production systems within 30 days, and from backups on the next backup rotation. Anonymized aggregate statistics used to evaluate model performance may be retained without any identifier that could be linked back to you. Whop may retain payment and transaction records independently under its own privacy terms and legal obligations.
Billing-data retention — legal decision required
PAID BILLING MUST REMAIN DISABLED. Before approval, counsel and the business owner must specify the legal bases and exact retention periods for Haeckel billing metadata, signed webhook records, accounting evidence, refunds, and disputes, and must confirm Whop's legal role and retention disclosures. This draft intentionally asserts no fixed billing-record retention period.
Your rights
You may export a copy of your analysis results from the Data section of your account at any time, delete individual uploads, or request full-account deletion from Settings. Before full-account deletion starts, Haeckel must confirm that any Whop membership is terminal and that no hosted checkout remains actionable or unresolved. If that confirmation is unavailable, the deletion request is temporarily blocked and your account and data remain intact so you can retry after billing is reconciled. You control whether your profile is discoverable for network recommendations and AI candidate searches via the Privacy section of Settings. We do not sell genomic data. As described above, Managed request content is processed under Haeckel's provider accounts and agreements; My API request content is processed under your own provider account and terms.
Non-clinical disclaimer
Haeckel provides statistical modeling and educational insights only. It is not a medical device. Results are not clinical diagnoses and must not be used as a substitute for the judgment of a qualified healthcare professional. Do not start, stop, or modify medications based on Haeckel output without consulting a clinician.
Contact
Privacy questions can be sent to privacy@herugenomics.com.