Skip to content
GenoLensGenoLens

Privacy Policy

Last updated: July 2026

For Research Use Only. GenoLens is not a medical device and is not intended for use in diagnostic procedures. No patient data should be entered into or processed by this service.

1. What We Collect

GenoLens collects the minimum data necessary to provide our service:

  • Account information: Email address and authentication credentials when you create an account (optional).
  • Query history: Gene symbols, variant IDs, HPO terms, and disease names you look up — stored only if you are signed in and have history enabled.
  • Favorites: Items you explicitly save to your favorites list.
  • Preferences: Display settings and configuration choices.
  • Usage analytics: Anonymized, aggregated usage patterns (e.g., feature usage counts) to improve the product. No personally identifiable information is included.
  • Crash and error reports:When the browser extension hits an unexpected error, a diagnostic report (error message, stack trace, extension version) is sent to our error monitoring provider so we can fix it. Reports are scrubbed of personal data before sending and are never collected from the page you are reading — only from the extension's own background process. You can turn this off entirely in the extension's Options page.
  • AI report inputs (Pro): If you generate an AI Variant Interpretation or Cancer Tier report, the assembled evidence for that gene or variant — all of it drawn from the public databases listed below — is sent to our AI provider to produce the report. Your identity is not included.

What we do NOT collect: We do not monitor your browsing history, read page content beyond your explicit text selections, or store any patient or clinical data.

2. How We Use Your Data

  • To provide genomic annotation lookups in response to your queries.
  • To maintain your query history and favorites (if signed in).
  • To sync your preferences across devices.
  • To improve service performance and reliability.
  • To communicate important service updates (with your consent).

3. Data Storage & Infrastructure

Your data is stored using the following services:

  • Supabase (PostgreSQL): User accounts, query history, favorites, and preferences. Protected by Row Level Security (RLS) — only you can access your own data.
  • Upstash Redis: Anonymized API response caching to improve performance. Cache keys are hashed and cannot be traced back to individual users.
  • Local browser storage: For users without accounts, preferences are stored locally in chrome.storage.local and never leave your device.
  • Lemon Squeezy:Subscription payments and billing (merchant of record). See “Payments & Subscriptions” below.

Sub-processors

These are every third party that may process data on our behalf, and what each one receives:

ProviderPurposeData received
SupabaseAccounts, database, edge functionsEmail, query history, favorites, preferences
VercelWebsite hostingRequest metadata (IP, user agent) in operational logs
UpstashAPI response cacheGene/variant/disease identifiers only — no user identifiers
Lemon SqueezyPayments (merchant of record)Email, billing details you enter with them
ResendTransactional email (contact form, trial alerts)Your email address and message content
SentryExtension error monitoring (opt-out)Scrubbed error reports and extension version
Google (Gemini API)AI reports for Pro subscribersPublic-database evidence for the queried entity

Payments & Subscriptions

GenoLens Pro subscriptions are processed by Lemon Squeezy LLC, who act as the merchant of record. When you start a checkout, we share your account email with Lemon Squeezy so they can create and manage your subscription. Their handling of your data is governed by their own privacy policy.

We never see or store your payment card details. Card data is collected and processed entirely by Lemon Squeezy and their payment partners. On our side we store only your subscription status and billing period (to unlock Pro features) and the Lemon Squeezy customer and subscription identifiers — never card numbers.

We keep a short-lived audit log of subscription webhook events for operational and accounting purposes. Any personal data in that log (such as the email on the invoice) is automatically purged within 14 days, and is scrubbed immediately if you delete your account.

4. Third-Party APIs

When you perform a lookup, GenoLens queries public genomic databases on your behalf: HGNC, ClinVar and PubMed (NCBI), gnomAD, PanelApp (Genomics England), UniProt, PharmGKB, CPIC, ClinGen, Ensembl VEP, VariantValidator, MyVariant.info, Open Targets, CIViC, Cancer Hotspots, AlphaFold (EMBL-EBI), LitVar2, Europe PMC, HPO (Jackson Laboratory), MONDO, DDG2P, Orphanet, and ClinicalTrials.gov. These queries contain only the gene/variant/term you selected — no personal information is transmitted to these services, and they never learn who you are.

5. Data Retention

  • Query history: Retained until you delete it or close your account.
  • API cache: Automatically expires after 24 hours.
  • Account data: Retained while your account is active. Deleted within 30 days of account closure.

6. Your Rights

In accordance with GDPR and applicable data protection laws, you have the right to:

  • Access: Request a copy of all data we hold about you.
  • Rectification: Correct inaccurate personal data.
  • Erasure: Request deletion of your account and all associated data.
  • Portability: Export your query history and favorites.
  • Restriction: Limit how we process your data.
  • Objection: Object to data processing for specific purposes.

What you can do yourself, right now: your dashboard lets you delete individual query-history entries, clear your entire history, and remove favorites at any time. Those deletions are immediate.

Account deletion and data export are handled by us on request — there is no self-service button for them yet. Email privacy@genolens.app from your account address and we will action it within 30 days, as will we for any of the other rights listed above. Deleting your account removes your profile, query history, favorites, trial watches, and scrubs personal data from our subscription webhook log; cancel your Pro subscription first if one is active.

7. Security

All data is transmitted over HTTPS. Database access is protected by Row Level Security policies. API keys are never exposed in client-side code. We follow industry best practices for secure application development.

8. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of material changes via email. Continued use of the service after changes constitutes acceptance of the updated policy.

9. Contact

For privacy-related inquiries, contact us at privacy@genolens.app.