← Back to the file

Privacy Policy

What we collect, and what we don't.

Last updated: April 14, 2026

Who we are

GenomePrivate operates the public quiz at genomeprivate.com. It is a marketing asset for PrivDNA, a privacy-sovereign whole genome sequencing service. This privacy policy describes what the quiz site collects, what it doesn't, and what rights you have.

PrivDNA is the data controller for both sites. This policy applies only to genomeprivate.com. PrivDNA's own service — which handles your genome and your email if you join the waitlist — is covered by its privacy policy.

What we collect

Your quiz answers

Nothing. The six answers live only in the browser tab you're reading this in, as React state. They are never sent to a server, never written to a cookie, never written to localStorage. They disappear when you close the tab.

Anonymous analytics

We use Rybbit, a self-hosted, open-source, cookieless analytics platform. It records:

  • Page views
  • Referrer and UTM parameters (where you came from)
  • Browser, device type, operating system, and screen size
  • Language preference
  • City-level geographic location (derived transiently from your IP)
  • Session duration and engagement metrics
  • Custom funnel events — quiz_start, quiz_progress (with a step number 1–6), quiz_complete, quiz_cta_click. No quiz answers, persona outcomes, or any other user-identifying data are included in these events.

Rybbit does not use cookies, does not fingerprint browsers, and does not assign persistent identifiers. Every visitor is anonymous by default — there is no way to link analytics data back to a specific individual. IP addresses are used transiently for geolocation and are not stored.

Cloudflare

Our site is served through Cloudflare, which processes requests at the network edge. Cloudflare may temporarily log IP addresses and request metadata for security and performance purposes (DDoS protection, bot detection) under their own privacy policy. We do not have access to individual IP addresses in Cloudflare logs.

What we do not collect

  • No cookies (zero — not even analytics cookies)
  • No email addresses
  • No account system (there's nothing to sign up for)
  • No advertising or tracking pixels
  • No browser fingerprinting
  • No third-party scripts beyond our self-hosted Rybbit tracker
  • No IP address storage
  • No cross-site tracking
  • No quiz answer telemetry
  • No persona-outcome telemetry

How we use the data we do collect

The anonymous analytics above are used for one purpose only:

  • Understand aggregate behavior — how many people complete the quiz, where traffic comes from, how the site performs — so we can improve the content

We do not sell, rent, license, or share analytics data with any third party. We do not use it for advertising. We do not build profiles.

Data sharing

We do not share analytics data with anyone. Rybbit is self-hosted on infrastructure we control; no third-party data processor sees your activity. The only external service in the request path is Cloudflare, whose role and privacy policy are described above.

Retention and deletion

Because Rybbit records no personal data and no persistent identifiers, there is nothing tied to you to retain or delete. Aggregate pageview and event counts are retained indefinitely for trend analysis. If you would like us to exclude your traffic going forward, we recommend enabling the Global Privacy Control signal in your browser, which Rybbit honors.

Security

  • All data in transit is encrypted via TLS 1.3 (enforced by Cloudflare)
  • HSTS with 12-month max-age, includeSubDomains enabled
  • No exposed ports — the site is reachable only via Cloudflare Tunnel
  • The site source is open source (MIT) — you can audit exactly how your data is handled

Security vulnerability reports: see our security.txt.

Your rights

Regardless of where you are located, you have the right to:

  • Know — what data we process about you (answer: none that identifies you personally)
  • Object — opt out of analytics entirely via your browser's Global Privacy Control signal, a tracker-blocking extension, or private browsing mode
  • Lodge a complaint — with your local data protection authority if you believe your rights have been violated

To exercise any of these rights or ask a question, email contact@genomeprivate.com.

For European visitors (GDPR)

If you are in the European Economic Area or United Kingdom, the General Data Protection Regulation applies.

  • Legal basis: analytics are processed under the legitimate interests basis (Article 6(1)(f) GDPR) — specifically, the site operator's interest in understanding aggregate traffic to improve the site — balanced against the minimal privacy impact of fully anonymous, cookieless measurement.
  • Data controller: PrivDNA, New York, NY, United States. contact@genomeprivate.com.
  • International transfers: analytics data is processed on infrastructure located in the United States. The Rybbit instance is self-hosted; there is no third-party data processor outside the US.
  • Automated decision-making: we do not use your data for automated decision-making or profiling. Quiz persona classification happens entirely in your browser and is not shared with us.
  • Supervisory authority: you have the right to lodge a complaint with your local data protection authority.

For California residents (CCPA / CPRA)

If you are a California resident, the CCPA (as amended by the CPRA) applies.

  • Categories of personal information collected: none. The analytics data we receive does not meet the CCPA definition of personal information because it cannot reasonably be linked to any specific individual.
  • Sale or sharing of data: we do not sell or share any data as defined under the CCPA/CPRA.
  • Right to opt out: not applicable — we do not sell or share personal information. If you still wish to signal opt-out, we honor the Global Privacy Control browser signal.
  • Non-discrimination: we will not discriminate against you for exercising any of your CCPA rights.

Children

The site is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. Given that the site collects no personal data from anyone, this restriction is precautionary rather than operationally distinct.

Changes to this policy

If we make material changes, we will update the "Last updated" date at the top of this page and commit the change to the open-source repository where the page source lives. You can see the full revision history there.

Contact

For privacy-related questions or requests, email contact@genomeprivate.com. Security disclosure: see our security.txt.

Your genome. Your hands. No copies.