Trust
Privacy policy.
Effective
This policy is written to be read. Genetic data is the most personal data there is, so every section below states, in plain language, what we collect, why, where it lives, and how to make it leave. Where we make a promise, we mean it as a commitment you can hold us to — several of these promises are also restated as contractual obligations in our terms of service.
The short version: we collect only what is needed to run the service. We do not use third-party trackers. Your genome stays on our systems unless you choose to send it elsewhere. Deletion is immediate and real. Export is always free.
Data we collect
We collect three categories of data, and only these:
- Account data. Your email address and a password hash (or the identifier from your chosen sign-in method), plus the settings you choose in the app. If you optionally tell us your country and, for the United States, your state — used only to tailor legal information such as our GINA explainer — you pick them from dropdowns. We deliberately provide no field for a street address and do not collect one.
- Uploaded genome files. The raw files you upload: microarray exports (23andMe, AncestryDNA, MyHeritage, FamilyTreeDNA) and VCF/gVCF files. BAM, CRAM and FASTQ files are not accepted. These uploads go directly from your browser to private storage, where server checks verify them before preparation.
- Derived data. Variants parsed from your files, the reports, ancestry estimates, and polygenic scores computed from them, and — if you use the chat feature — your chat history. Derived data is treated with the same protections as the files it came from.
What we deliberately do not collect
- No street addresses. Location, where relevant at all, is a country/state dropdown — nothing finer.
- No third-party trackers of any kind. No Meta (Facebook) pixel, Google tags or analytics, Microsoft ad pixel, session replay, or ad-tech beacons. An automated network audit enforces this rule in CI. A build fails if it requests a tracking domain.
- No behavioral advertising profiles. We have no advertising business and build no such profiles.
Where your data is processed
The hosted service uses two infrastructure providers as data processors. Supabase handles the database and file storage, including your genome files and derived variants.Vercel hosts the app. Each provider works only on our instructions under a data processing agreement. Neither may use your data for its own purposes.
If you prefer that no company — including us — hold your genome, Inherit is designed to be self-hosted. The complete platform is open-source under AGPL-3.0, and the self-hosting guide at /docs/self-hosting lets you run it on infrastructure you control, in which case this policy’s hosted-service sections simply do not apply to you.
Zero third-party analytics
We use no third-party analytics services. The only logs we keep are first-party server logs for security and debugging. We also count aggregate activity without tracking individual users. No analytics vendor, ad network, or data broker gets data from Inherit. We do not share even “anonymized” or “aggregated” genetic statistics.
When data can leave our infrastructure
Your genome data is never sent to a third party, with one exception that you control: the AI chat feature. If you choose an external AI provider, Inherit sends only the report or variant excerpts needed to answer your question. This happens only after you give separate consent for that named provider. For example, consent for Anthropic covers only Anthropic. Until you consent, chat cannot send anything. You can also use a local model, so nothing leaves your machine.
- Consent is granular: one grant per named provider, never a blanket “AI partners” checkbox.
- You can review and revoke each grant at any time in Settings. Revocation stops all future transmission at once.
- Our related legal commitments are set out at /legal/research-consent. They include our promise not to run a research-sharing program.
Apart from that choice, we disclose data only if valid legal process compels us. Our strict policy at /legal/law-enforcement governs each response. It requires notice to you unless the law bars notice, the narrowest possible response, and a public transparency report.
Retention
We keep your data for as long as your account exists, and no longer. There is no shadow retention:
- Account data, genome files, and derived data are retained while your account is active, because they are the service.
- Server logs are retained for 30 days for security and debugging, then deleted. Logs never contain genome file contents or variant data.
- Encrypted database backups are retained for at most 30 days on a rolling basis and exist solely for disaster recovery. Backups are never used to restore data you have deleted.
Deletion that actually deletes
When you delete a file or your account, deletion is immediate and unrecoverable:
- Database rows are deleted as soon as you confirm. This covers your account, variants, reports, chat history, and consents. We do not mark them hidden or queue them for later.
- We delete the raw genome files from storage in the same operation. We do not merely unlink them.
- There is no grace period and no resurrection. We will not restore deleted data from backups, and rolling backups age out within 30 days, after which no copy exists anywhere on our infrastructure.
Deletion is available self-serve in Settings — no support ticket, no retention phone call, no dark patterns.
Free export, forever
You can export everything at any time and in open formats. This includes your original files, derived variants, reports, and chat history. Export is free forever. We will never charge a data-transfer, egress, or “download your own genome” fee. Our terms of service make this a contractual promise, not a courtesy we can withdraw.
Children's data
Inherit is for adults: you must be 18 or older to create an account, and you may only upload genome files that are your own. Inherit is not directed to children and we do not knowingly collect or process data from anyone under 18.
COPPA is the United States Children’s Online Privacy Protection Act. Its definition of “personal information” at 16 CFR § 312.2 expressly includes genetic data. We do not knowingly process any minor’s genetic or other personal information. If we learn that we hold data about a person under 18, we will delete it promptly after notice. This applies whether the minor opened the account or another person uploaded the file. We use the immediate, unrecoverable deletion described above. Report suspected minors’ data to privacy@inherit.bio.
Change of control
Genomics companies can be acquired, and their databases may change hands. The following rules apply if Inherit is acquired, merged, or transferred. They also apply in bankruptcy or receivership:
- 60 days’ advance notice. We will notify you by email at least 60 days before any transfer of your data to a successor entity takes effect.
- A guaranteed export-and-delete window. Throughout that notice period, free export and immediate deletion remain fully available. If you delete before the transfer, the successor receives nothing about you.
- Policy continuity or fresh consent. Any successor is bound by this policy for data collected under it. Weakening these commitments requires your new, affirmative consent — silence is not consent.
- A structural escape hatch. Because Inherit is AGPL-3.0 open source, the platform itself cannot be taken away from you: you can export your data and self-host the same software, permanently, regardless of what happens to the company.
Inherit and Plus Bio: created by, legally separate
Plus Bio created Inherit as an open-source project for the public good. Inherit operates as a legally separate entity. Creation does not mean access. The separation keeps your genetic data from becoming an asset of Plus Bio or any other commercial business. The following rules are binding:
- Inherit and Plus Bio’s commercial services use separate domains and accounts. They do not share a single sign-on system.
- No personal, health, or genetic data moves between Inherit and any Plus Bio service. This rule applies in both directions. It covers uploads, derived data, account details, and usage events.
- Plus Bio’s commercial operations have no access to Inherit data under this policy. Inherit is legally separate. A change of control at Plus Bio cannot transfer your data.
Your rights (GDPR, CCPA, and everywhere else)
We extend the same rights to every user, everywhere, without requiring you to prove which law applies to you:
- Access and portability — see and export everything we hold about you (GDPR Articles 15 and 20; CCPA right to know). Self-serve, free, forever.
- Rectification — correct inaccurate account data (GDPR Article 16).
- Erasure — immediately delete any file or your entire account. This covers GDPR Article 17 and the CCPA right to delete.
- Restriction and objection — restrict or object to processing under GDPR Articles 18 and 21. We do not use marketing profiles or automated decisions with legal effect. There is little to object to, but the right still applies.
- Withdraw consent — revoke any LLM-provider consent at any time in Settings (GDPR Article 7(3)).
- No sale, no sharing — we do not sell or share personal information under the CCPA/CPRA definitions. There is nothing to opt out of because we meet the right by default.
- No discrimination — exercising any right never degrades your service.
- Complaint — you may complain to your local supervisory authority. GDPR Article 77 protects this right. You may also complain to your state attorney general.
Most rights are self-serve in the app. For anything that is not, email privacy@inherit.bio and we will respond within 30 days.
Changes and contact
We will post any new version here with a new effective date. We will email account holders before a material change takes effect. A change cannot weaken protections for data already collected unless you affirmatively consent.
Privacy questions and data-rights requests: privacy@inherit.bio. Security reports: security@inherit.bio.