Skip to main content

Privacy Policy

Last updated: September 3, 2026

This policy separates the current service from earlier features. DNA Explore currently provides browser-local parsing, raw-entry viewing, and purchase restoration. Health analysis, AI, marketing tracking, newsletter signup, and new purchases are unavailable. See the service update.

This privacy policy applies to DNA Explore (dnaexplore.ai), operated by Hollens Holdings LLC, an Oregon limited liability company. References to “DNA Explore,” “we,” “us,” or “our” in this policy refer to Hollens Holdings LLC.

1. Current service

The current release reads a compatible raw genotype file with JavaScript in your browser. It saves parsed entries in that browser profile's IndexedDB so they remain available after a refresh. The current application code does not upload the selected raw file or full parsed variant set to DNA Explore's servers.

Genetic information is sensitive and may receive special legal protection. Browser-local storage reduces server-side exposure, but it does not make the information anonymous or risk-free. DNA Explore does not separately encrypt its IndexedDB record. Do not use the service on a shared or public device, and use Clear data when you are finished.

2. Current data flow

When you open a compatible file in the current release:

  • Your raw genome file is read by JavaScript running in your browser tab
  • The application parses file rows and displays raw marker identifiers, chromosome labels, positions, and genotypes without health interpretation
  • Your parsed genotype data is held in browser memory and persisted to IndexedDB (a browser-local database) for continuity across navigation and refreshes
  • The current application does not send the raw file, parsed variants, or displayed entries to an AI provider

Normal website requests still disclose ordinary connection data to our hosting provider, including an IP address, user agent, requested URL, and request time. If you use purchase restoration, the email you enter is sent through a DNA Explore serverless function to Stripe to look for a completed purchase. Do not put genetic information in a URL, support email, or restoration form.

3. Earlier AI processing, now paused

AI features are unavailable. Current AI endpoints reject requests before reading a request body or contacting an AI provider, so the current release does not send genetic data to Anthropic.

Earlier versions offered three server-mediated features: Ask My DNA, AI Health Report, and Explain This. When a user requested one of those features, the browser sent selected data to a Netlify-hosted DNA Explore serverless function, which forwarded the request to Anthropic. Depending on the feature, a request could include:

  • SNP identifiers (rsIDs) and your genotype at those specific positions
  • Gene names and variant descriptions from DNA Explore's catalog
  • Derived risk, medication-gene, interaction, or nutrition summaries
  • Your question and earlier messages in the AI conversation

The application code did not intentionally include the selected raw file or full parsed variant set in those AI request bodies. When a purchase token was present, the browser attached it to the same request to DNA Explore's serverless function. That signed token encoded the checkout email so the function could check access. The application code did not include the token or checkout email in the request it then sent to Anthropic. The transmitted genetic subset was still sensitive and may have been identifying without a name or email. DNA Explore's application code did not write the requests or responses to its own database. Hosting, API provider, and subprocessor retention depended on the terms and account settings in effect at the time.

At different times, DNA Explore used two types of report-level AI action. The first copied a prepared prompt to the browser clipboard and displayed links to outside AI services. A later version's per-finding and whole-report actions stored prepared prompts, opened Ask My DNA, and could submit them automatically through DNA Explore to Anthropic without a second send action. The whole-report action could include a consolidated summary of findings the software flagged for attention. If a user submitted a copied prompt to another service, that service handled it under its own terms and privacy policy. Clearing local browser data cannot recall information already submitted to a service provider.

4. No Sale of Genetic Data

DNA Explore does not sell, rent, or license genetic information, and does not disclose it for advertising, insurance, employment screening, or data-broker purposes. We do not provide genetic information to:

  • Pharmaceutical companies or drug developers
  • Insurance companies (health, life, disability, or long-term care)
  • Employers or employment screening services
  • Data brokers or data aggregators
  • Advertising or marketing companies
  • Research institutions

The current application does not send the raw file or parsed variant set to our servers. Section 3 describes selected genetic information that earlier AI features transmitted when requested. We may disclose records held by DNA Explore or its service providers when legally required, but DNA Explore does not maintain an application database of raw genome files or full parsed variant sets.

5. Marketing and analytics

The current release does not initialize the Meta Pixel, send Conversions API events, load a site analytics service, or offer a newsletter or research-alert form. Its browser security policy blocks scripts and browser connections to those outside services.

Earlier versions supported consent-based Meta advertising measurement on marketing and checkout pages. They also included email forms connected to Beehiiv or Netlify Forms. Earlier provider records may remain under the provider's applicable retention and deletion rules.

The current release does not place genetic data in URLs or marketing events. Netlify still receives ordinary connection metadata when it serves the website. Fonts and application assets are served with the site rather than fetched from a third-party font service in the browser.

6. IndexedDB & localStorage

To preserve your data across page refreshes, DNA Explore stores parsed genome entries in this browser profile's IndexedDB. Earlier versions stored AI chat history in localStorage. The browser may also store your theme, purchase token, and earlier consent choices. This browser-local data:

  • Remains available to this site in the same browser until cleared
  • Is not stored in a DNA Explore server-side database
  • Genome data, earlier chat history, and earlier AI or tracking choices can be cleared using the “Clear data” button on the dashboard
  • The payment token and theme remain after Clear data so purchase restoration and display settings are not lost
  • Can also be removed by clearing your browser's site data

7. Data Deletion & Your Control

You have immediate control over the raw file and full parsed variant set stored in your browser:

  • Dashboard “Clear data” button: Removes the parsed genome from IndexedDB and clears earlier chat history, AI consent, general report consent, and tracking consent. It does not remove your payment token or theme.
  • Browser site data: Clearing site data for this domain removes all stored information

DNA Explore does not maintain a server-side database of raw genome files or full parsed variant sets. Earlier AI request data or form submissions may remain with the relevant provider under the terms and settings that applied at the time. Payment records are held by Stripe. Contact us to request help with records we control, subject to provider, legal, fraud-prevention, and accounting requirements.

Consent records: Earlier dashboard, AI, and tracking choices were stored as browser-local flags. The application did not maintain a server-side consent database, timestamp, or versioned consent receipt.

8. Payment Processing & Stripe

New purchases are unavailable. Earlier purchases were processed on Stripe's hosted checkout page. Stripe collected the purchaser's email address and payment details. DNA Explore's application did not receive or store full card details.

For purchase confirmation and restoration, Stripe makes the following information available to DNA Explore's server-side code and merchant account:

  • Your email address (used to create a signed access token so you can restore access if you return later)
  • A payment intent ID (an internal transaction reference)
  • Payment status (paid / unpaid)

DNA Explore stores a signed access token in your browser and does not copy customer emails into an application customer database. Stripe retains the purchase email and transaction record. If you use Restore purchase, the email you enter is sent through a DNA Explore serverless function to Stripe's API to look for a completed purchase. The application code does not persist the lookup request.

As the merchant of record, the operator of DNA Explore can view transaction details — including your email address — in the Stripe merchant dashboard. This is standard for any online purchase and may be needed for customer support, refunds, fraud prevention, accounting, or legal compliance. DNA Explore has not sent the drafted customer safety or feedback message. Any future communication will be handled separately from the current website service.

Stripe's handling of your payment data is governed by Stripe's Privacy Policy.

9. Service providers

The current service uses:

  • Netlify: Hosts the website and processes ordinary web-request metadata such as IP address, user agent, requested URL, and request time. The current application does not intentionally include genetic data in those requests.
  • Stripe: Holds earlier payment records and receives the email entered for purchase restoration. See Section 8.

Earlier versions also used Anthropic for requested AI processing, supported Meta advertising measurement, and offered email forms connected to Beehiiv or Netlify Forms. Sections 3 and 5 describe those historical uses. The current application does not use third-party authentication, a customer support widget, or an application database of raw genome files or full parsed variant sets.

10. Data Breach Notification

DNA Explore does not maintain an application database of raw genome files or full parsed variant sets. Other records may be held by DNA Explore's service providers. If we learn of an incident that may affect information handled through DNA Explore, we will assess it and provide notices required by applicable law.

11. Children's Privacy

DNA Explore is intended only for adults using their own genetic data. Do not open a minor's file or another person's file. DNA Explore has no user account or age-verification system. If a file was opened in error, use Clear data and clear this site's browser data. Contact us if you believe a child's contact or payment information was submitted to a service provider through DNA Explore.

12. Your Choices and Privacy Requests

Privacy rights vary by location. DNA Explore provides the following controls and request paths:

  • Local genome and chat copy: Use Clear Data or clear this site's browser data.
  • AI and tracking: These features are unavailable in the current release.
  • Email and form records: Contact us to request access, correction, deletion, or an opt-out for records we control.
  • Payment records: Contact us for assistance; Stripe and DNA Explore may retain transaction records when required for legal, fraud-prevention, tax, or accounting purposes.
  • Sale of personal information: DNA Explore does not sell personal information.

We will respond to verified privacy requests as required by applicable law.

13. Sensitive genetic information

Genetic information may receive heightened protection under applicable privacy laws. DNA Explore minimizes server-side handling by keeping the raw file and full parsed variant set in the browser. Earlier server-mediated AI features transmitted selected genetic and derived information only when requested, as described in Section 3. Those features are now unavailable.

14. International Users

DNA Explore is operated from the United States, and its hosting and payment providers may process ordinary website or payment-restoration data in the United States or other locations covered by their terms. The current release does not offer AI processing or intentionally send genetic data to an AI provider. Any future feature that transmits genetic data will require a new notice and any consent required before use.

15. Changes to This Policy

We may update this privacy policy from time to time. The “Last updated” date identifies the current version. When a change materially expands genetic-data collection, use, or disclosure, we will provide notice and obtain consent when required by applicable law or before enabling the changed feature. Formatting, clarification, and contact updates may be made by updating this page.

16. Contact

If you have questions about this privacy policy or our data practices, please reach out at legal@dnaexplore.ai.