Privacy Policy

Last updated: April 2026

1. Overview

GeneSupp ("we", "our", "the Service") is a privacy-first nutrigenomics tool that analyzes raw DNA data files to provide educational supplement recommendations. We are committed to protecting your genetic privacy in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy laws.

2. What Data We Collect

We do NOT collect your raw DNA data. Your genetic file is processed entirely within your web browser using client-side JavaScript. The file is never uploaded to our servers, and we have no ability to access, read, or store your genetic information.

If you create an account, we store only: your name, email address, and report metadata (provider name, number of findings, date). We do not store genotypes, alleles, or any raw genetic data on our servers.

3. AI-Generated Explanations

When you request an AI explanation for a finding, we send only the gene name and variant identifier (e.g., "MTHFR" and "rs1801133") to our AI service. No personal identifiers, genotype results, or raw DNA data are included in these requests. The AI generates general educational content about the gene variant — not personalized medical advice.

4. Local Storage

Your analysis results are stored in your browser's local storage for convenience. This data remains on your device and is not accessible to us. You can delete all locally stored data at any time from the Settings page.

5. Payment Information

Payments are processed by Stripe, Inc. We do not store credit card numbers, Apple Pay tokens, or Google Pay tokens. Stripe's privacy policy governs the handling of your payment information.

6. Cookies & Analytics

We use essential cookies for session management if you create an account. We may use privacy-respecting analytics to understand aggregate usage patterns. We do not use advertising cookies or share data with third-party advertisers.

7. Your Rights Under PIPEDA

You have the right to: access any personal information we hold about you; request correction of inaccurate information; withdraw consent for data processing; request deletion of your account and associated data. To exercise these rights, contact us at [email protected].

8. Data Retention

Account data is retained until you request deletion. Local browser data is retained until you clear it or clear your browser storage. We do not retain any genetic data at any time.

9. Contact

For privacy inquiries, contact: [email protected]