Privacy Policy
Your privacy is fundamental to how we operate. This policy explains what data we collect, how we use it, and the measures we take to keep it safe.
What data we collect
- Account information: Email address used for authentication and book delivery.
- Genetic data: Raw genome files uploaded from services like 23andMe, AncestryDNA, MyHeritage, or Nebula Genomics.
- Blood work: PDF lab reports you choose to upload (optional).
- Health profile: Information you provide in the intake questionnaire including demographics, health history, lifestyle, and goals.
- Payment information: Processed securely by Stripe. We never store credit card numbers.
How we use your data
- Book generation: Your genetic data, blood work, and health profile are used solely to generate your personalized health book.
- Email notifications: We send you an email when your book is ready for download.
- Service improvement: We may use anonymized, aggregated data to improve our analysis algorithms. Individual data is never shared.
Data retention and deletion
- Raw genetic files: Permanently deleted from our servers after the relevant data has been extracted for book generation.
- Blood work PDFs: Permanently deleted after processing.
- Generated health books: Stored securely in your private dashboard until you choose to delete them or close your account.
- Health profile data: Retained as long as your account is active to allow future book regeneration.
Security measures
- All data is encrypted in transit using TLS/SSL.
- Data at rest is encrypted using AES-256 encryption.
- Access to production systems is restricted and logged.
- We conduct regular security reviews of our infrastructure.
Third-party sharing
We never share, sell, or provide your personal or genetic data to third parties. The only third-party services that process your data are:
- Supabase: Database and file storage (encrypted at rest).
- Stripe: Payment processing only.
- Anthropic (Claude): AI model used for book generation. Your data is sent via API for processing and is not retained by Anthropic.
Your rights
- You can request a copy of all data we hold about you.
- You can request permanent deletion of your account and all associated data.
- You can download your generated health books at any time.
Contact
For privacy-related questions or data requests, email us at privacy@healthbook.com.