Why genetic data is different from every other kind of data
If a password leaks, you change it. If a credit card number leaks, you cancel the card. If your genetic data leaks, there's no reissue. It's permanently tied to you and, unlike almost any other data category, it implicates people who never consented at all — your parents, siblings, children, and more distant relatives all share fragments of the same code. A decision you make about testing can reveal information about them too.
That's why the privacy practices of a genetic testing service deserve more scrutiny than a typical app's terms of service, and why the questions worth asking are a little different from a standard privacy checklist.
Deletion and sample destruction are two separate things
This is the single most commonly missed distinction. Deleting your account and deleting your data is one action; requesting destruction of the physical saliva or blood sample sitting in a lab's biobank is often a completely separate request, sometimes buried in a different section of the policy or requiring a different form. A service can honor one without the other unless you specifically ask for both.
Opt-in versus opt-out is the whole ballgame
Two policies can sound almost identical in a press release and mean opposite things in practice. "Opt-in" research sharing means nothing happens with your data until you actively check a box agreeing to it. "Opt-out" means sharing is the default the moment you sign up, and it's on you to find the setting and turn it off — if you even know to look. The same distinction applies to law enforcement data-sharing programs some services participate in: read carefully whether that requires your specific, separate consent or is covered by broad terms-of-service language you agreed to just to use the product at all.
What a solid privacy policy actually states
- Encryption of your data both at rest (while stored) and in transit (while being transmitted) — stated explicitly, not implied
- A defined data retention period, not an open-ended "we keep it as long as needed"
- A working, documented path to download your raw genetic data as a file, independent of keeping an account open
- A clear, actionable process for account and data deletion with a stated response timeframe
Reading the policy is still on you
No checklist replaces actually opening the specific service's current privacy policy — company ownership changes, and terms have shifted after signup for consumer genetic testing companies before. Treat any past confirmation as a snapshot, not a permanent guarantee, and re-check periodically if you keep an account open long-term.
A framework beats scattered searching
Reading a multi-thousand-word privacy policy cold and trying to remember which of seven things you were looking for is how important details get missed. Working through a fixed checklist — one item at a time, with a note on exactly where in a typical policy to look — makes the review faster and far less likely to skip something that matters.
What to do if a service falls short
Finding a gap doesn't necessarily mean walking away — some services are transparent about limitations, and some gaps matter more than others depending on what you care about. A service that lacks a raw-data download option is a bigger deal for someone who wants to move their results elsewhere than for someone who never plans to. What matters is that the gap is a conscious decision on your part, made after actually reading the policy, rather than something you find out about after your sample is already in a lab.
If you decide to proceed despite an unchecked item, it's worth writing down which ones you accepted and why, especially if the retention policy is vague or research sharing defaults to opt-out. That note becomes useful later if the company changes hands or updates its terms — you'll have a clear record of what you originally agreed to compare against, rather than relying on memory of a decision made months or years earlier.
Frequently Asked Questions
No — it gives you a general-purpose 7-point framework to apply to any service's current privacy policy yourself, since practices vary by company and change over time. It deliberately avoids naming or rating specific companies so the guidance stays accurate regardless of which service you're evaluating.
Yes — the Genetic & DNA Testing Service Privacy Checklist covers data deletion, sample destruction, opt-in sharing, encryption, and retention policy in one weighted checklist. It's a one-time $5.99 purchase — no subscription, no account required.
Deleting your data removes your digital genetic profile and results from the company's systems. Destroying your physical sample is a separate request for the saliva or blood sample itself, which some services retain in a biobank by default even after your account is closed — the checklist treats these as two distinct items for exactly this reason.
Yes — it works equally well as a pre-signup evaluation or a periodic review of a service you're already using, since privacy terms and ownership can change after you've signed up.
No. It runs entirely in your browser using localStorage, with zero network requests, analytics, or tracking — nothing about which boxes you check ever leaves your device.