1. Introduction
FuelYourDNA ("we", "our", "us") is committed to protecting your privacy and personal data, especially your genetic data which is considered sensitive data under GDPR and other privacy regulations.
This Privacy Policy explains how we collect, use, store, and protect your information when you use our personalized genetic nutrition service.
Our Core Promise: Your genetic data is yours. We will NEVER sell your data to third parties. Your DNA files are deleted after analysis. You can delete all your data at any time.
2. Data We Collect
2.1 Account Information
- Name and email address
- Password (encrypted with bcrypt)
- Account preferences and settings
2.2 Genetic Data
- Uploaded DNA files (from 23andMe, AncestryDNA, MyHeritage, FTDNA, LivingDNA)
- Analyzed genetic variants (SNPs) relevant to nutrition
- Generated nutritional analysis results
- Personalized recommendations
Important: Your raw DNA files are processed for analysis and then permanently deleted from our servers. We only retain the analyzed genetic markers relevant to nutrition.
2.3 Payment Information
- Payment transactions are processed by Stripe
- We never store your credit card numbers
- We only receive transaction confirmations
2.4 Usage Data
- Log data (IP address, browser type, pages visited)
- Cookies for essential functionality
3. How We Use Your Data
- Provide our service: Analyze your genetic data and generate personalized nutrition recommendations
- Account management: Manage your account and communicate with you
- Service improvement: Improve our algorithms and user experience (using anonymized, aggregated data only)
- Legal compliance: Comply with legal obligations
4. Data Security
We implement industry-leading security measures to protect your sensitive genetic data:
AES-256 Encryption
All data encrypted at rest
TLS 1.3
Encrypted data in transit
Secure Authentication
JWT tokens + bcrypt hashing
Access Control
Restricted to authorized personnel
EU Hosting
GDPR-compliant data centers
Data Deletion
Raw files deleted after processing
5. Data Sharing — We DO NOT Sell Your Data
We will NEVER sell, rent, or trade your personal or genetic data to third parties.
Your data may only be shared with:
- Payment processor (Stripe): To process transactions securely
- Hosting provider: To store data securely (GDPR-compliant)
- Legal authorities: Only if required by law
We will NEVER:
- Sell your genetic data to insurance companies
- Share your data with employers
- Use your data for research without explicit consent
- Share identifiable data with any third party
6. Your Rights (GDPR)
Under GDPR and other privacy regulations, you have the right to:
- Access: Request a copy of all your personal data
- Rectification: Correct any inaccurate data
- Erasure: Delete all your data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to certain processing activities
- Restriction: Restrict how we process your data
- Withdraw consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@fuelyourdna.com
7. Data Retention
- Raw DNA files: Deleted immediately after analysis (within 24 hours)
- Analyzed genetic markers: Retained while your account is active
- Account data: Retained while account is active + 30 days after deletion
- Usage logs: Maximum 12 months
- Payment records: As required by law (typically 7 years)
8. Children's Privacy
Our service is not intended for individuals under 18 years of age. We do not knowingly collect data from minors. If you believe we have collected data from a minor, please contact us immediately.
9. International Transfers
Your data is primarily stored in the European Union. Any transfer outside the EU complies with GDPR requirements, including Standard Contractual Clauses where applicable.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through our service. The "Last updated" date at the top indicates the most recent revision.
11. Contact Us
12. Supervisory Authority
If you are not satisfied with our response, you have the right to lodge a complaint with the French data protection authority:
CNIL — Commission Nationale de l'Informatique et des Libertés
3 Place de Fontenoy, TSA 80715
75334 Paris Cedex 07, France
Website: www.cnil.fr