This is a draft Privacy Policy for Haeckel v1. Final policy pending legal review. By using Haeckel, you agree to the practices described here. We will notify users of any material changes before they take effect.
Data we collect
Haeckel collects the genomic data you upload (SNP chip files from 23andMe, AncestryDNA, FTDNA, or VCF/FASTQ from whole-genome sequencing), biomarker measurements you choose to enter, and profile information you provide. Account identity is managed by our authentication partner Clerk and includes your email and any social-login identifiers you choose to connect.
How we process your data
Your genome is processed by our analysis pipeline to produce ancestry, health, trait, pharmacogenomic, nutrigenomic, and evolutionary insights. AI conversations with Mirror are processed by Anthropic Claude models for text generation, by OpenAI text-embedding-3-small strictly for vector embeddings used in search and recommendation, and optionally by ElevenLabs for voice synthesis when you enable voice mode. None of these providers are authorized to use your data for model training.
Storage and encryption
Genomic files are stored in Cloudflare R2 with encryption at rest. Analysis results, embeddings, and account state live in a managed PostgreSQL database (Neon) with encryption at rest and TLS in transit. Backups follow the same protections. Internal access is limited to the personnel required to operate the platform.
Retention
We retain your data for as long as your account remains active. When you delete your account, your genomic files, analysis results, embeddings, and profile data are removed from production systems within 30 days, and from backups on the next backup rotation. Anonymized aggregate statistics used to evaluate model performance may be retained without any identifier that could be linked back to you.
Your rights
You may export a complete copy of your analysis results from the Data section of your account at any time. You may delete individual uploads or your entire account from Settings. You control whether your profile is discoverable for network recommendations and AI candidate searches via the Privacy section of Settings. We do not sell or share your genomic data with third parties.
Non-clinical disclaimer
Haeckel provides statistical modeling and educational insights only. It is not a medical device. Results are not clinical diagnoses and must not be used as a substitute for the judgment of a qualified healthcare professional. Do not start, stop, or modify medications based on Haeckel output without consulting a clinician.
Contact
Privacy questions can be sent to privacy@herugenomics.com.