Legal

Privacy Policy

What we collect, why we collect it, who processes it for us, and how you remove it.

Effective date: September 8, 2026 · Last updated: September 8, 2026

1. Who operates Variant Pilot

Variant Pilot is operated by Harbour Ventures ("Variant Pilot", "we", "us"). You can reach us at samuelpharbour@gmail.com.

This policy explains what information we collect, why we collect it, who processes it on our behalf, and the choices you have.

2. Information we collect

Account information

  • Your email address and a password you choose (sign-in is email and password).
  • A user account identifier generated by our authentication system.
  • Authentication records such as sign-in timestamps and session tokens.
  • We do not ask for your legal name, postal address, phone number or ancestry information.

Genetic information

  • The raw genetic data file you upload from a consumer testing service.
  • Parsed variants derived from that file: rsIDs, chromosome positions and genotypes.
  • Insights generated from your variants, including category and priority information.
  • Matches between your variants and scientific studies, and related research alerts.
  • Variants you add to your watchlist.

Health and wellness information

  • Wellness interests and preferences you select.
  • Answers you give to briefing questions.
  • Educational Mental Wellness content associated with your variants (stress, mood, focus, sleep and brain-nutrition topics).
  • Nutrient and supplement-related educational personalisation derived from your variants.
  • Any health or wellness details you choose to type into the assistant or feedback forms.

Your content

  • Conversations with the optional AI assistant, including your questions and the replies.
  • Feedback messages you submit.
  • Daily Briefings generated for you and your responses to them.

Device and technical information

  • Push notification device tokens and the platform they belong to, if you enable notifications.
  • Product usage events (for example page paths, device type, operating system, browser and app version) and error reports used to fix bugs.
  • Security and delivery logs, including email delivery status and unsubscribe records.

Our own usage and error records do not contain raw DNA data, rsIDs, genotypes, individual trait names, assistant messages, AI responses or your email address.

Purchase and subscription information

  • Your subscription tier and status, renewal or cancellation state, and period end date.
  • Customer and subscription identifiers issued by our payment processor.

Payments are processed by Stripe. Variant Pilot never receives or stores your full card number, CVC or bank details — those are entered directly with Stripe.

3. How we use information

  • Process the genetic file you upload and generate your insights.
  • Match your variants against scientific research and monitor for new studies.
  • Generate your Daily Briefing and research alerts.
  • Provide educational Mental Wellness and nutrient information.
  • Provide optional AI features when you have enabled them.
  • Create and maintain your account and authenticate you.
  • Send notifications and service emails you have chosen to receive.
  • Respond to support requests.
  • Detect, prevent and investigate abuse, fraud and security incidents.
  • Administer subscriptions and billing.
  • Maintain, debug and improve the service.

We do not use your information for advertising.

4. How we handle genetic information

Genetic information is sensitive. It can reveal information about you and, indirectly, about biological relatives. We treat it with particular care.

  • Why we collect it: only to produce the educational insights, research matches and briefings you asked for.
  • How it is processed: your uploaded file is read on our servers, the variants in it are compared against our internal catalog of researched variants, and the resulting variants and insights are stored against your account.
  • Raw file retention: after successful processing your raw file is deleted from storage by default. You can opt in to keep it stored so it can be re-processed later, and you can turn that off or delete the stored file at any time — turning retention off also removes the stored file.
  • Derived results: parsed variants and insights are retained while your account exists so the app can work, and are removed when you delete your account.
  • Visibility: your genetic data is accessible to your own authenticated account. Access controls are enforced per account at the database level. A small number of administrators can access systems for support, security and maintenance.

We never sell your genetic information, and we never share it for advertising. We do not provide your genetic information to advertisers, data brokers, insurers, employers or research partners.

Genetic information is stored and processed by the infrastructure providers listed in section 6, and — only if you explicitly enable AI features — is transmitted to the AI processing service described in section 5.

5. Optional AI features

  • AI features are optional and switched off unless you turn them on.
  • Core Variant Pilot functionality — variants, insights, research matches, citations, alerts, briefings, notifications and account tools — works without AI enabled.
  • Until you explicitly enable AI processing, no genetic or health information is sent to a third-party AI provider for these features.
  • When AI is enabled, information relevant to the feature you use may be transmitted. That can include genetic variants and genotypes, insight and category information, research matches and the questions you type into the assistant.
  • Architecture: requests are sent from our servers to the Lovable AI Gateway, which forwards them to a third-party large language model provider. The models currently used are Google Gemini models. We do not run our own models.
  • Purpose: to generate plain-language summaries, category overviews, dashboard highlights, briefing interpretations and assistant replies.
  • Turning it off: you can disable AI at any time in Settings. Your consent is recorded with a timestamp and version, and withdrawing it stops further transmission.
  • Previously generated content: when you turn AI off, the AI summaries, suggestions, supplement notes, category summaries, dashboard highlights and assistant conversations stored in your Variant Pilot account are deleted. We cannot delete anything retained by the AI provider or gateway.

AI-generated content is labelled in the app, may be incomplete or inaccurate, and is educational only — it is not medical advice, diagnosis or treatment.

[PENDING VERIFICATION] We do not make guarantees about the AI provider's retention, logging or model-training practices. Any statement that the provider does not train on your information will only be published once it is confirmed by the applicable provider agreement.

6. Service providers

Selling data means exchanging personal information for value with a party that uses it for its own purposes. We do not do that. Using service providers means vendors process information strictly to run the service on our instructions. We do that, and it is unavoidable for any hosted application.

  • Cloud hosting, database and file storage: Lovable Cloud (built on Supabase) and Cloudflare, which host the application and store your account, genetic and insight data.
  • Authentication: the Supabase authentication service used by Lovable Cloud.
  • Optional AI processing: Lovable AI Gateway, forwarding to Google Gemini models — only when you enable AI.
  • Email delivery: the Lovable email service, used for account emails, research alerts and briefings.
  • Push notifications: Apple Push Notification service (APNs), if you enable notifications on an Apple device.
  • Payments: Stripe, which handles checkout, card data, subscriptions and the billing portal.
  • Website analytics: Google Analytics (via the Google tag) on the public website, which receives standard web analytics data such as page views, approximate location derived from IP address, and device/browser information. Genetic, health and insight data are never sent to it.
  • First-party product analytics and error monitoring: stored in our own database, not shared with an external analytics vendor.
  • Scientific research sources: we retrieve study metadata from public sources such as PubMed and the GWAS Catalog. We send queries about variants of scientific interest; we do not send your identity or your personal genetic file to them.
  • Customer support: handled by email at the address above.

Service providers receive only the information needed to perform their function and are subject to their agreements with us.

We do not sell your personal or genetic information. We do not share your genetic information with advertisers or data brokers.

7. Advertising and tracking

Variant Pilot does not use advertising networks, advertising SDKs, the iOS advertising identifier (IDFA), cross-app or cross-site tracking for advertising, targeted advertising, data brokers or advertising profiles. The iOS app contains no advertising or tracking SDKs.

The public website loads Google Analytics for aggregate traffic measurement. It is not used for advertising audiences, and genetic or health information is never sent to it.

8. Data retention

  • Raw DNA file: deleted after processing by default; kept only if you opt in, and removed when you opt out or delete it.
  • Account information, parsed variants, insights, research matches, briefings, briefing answers, interests, watchlist, AI-generated content, assistant conversations, notification preferences and device tokens: retained while your account exists and removed when you delete your account.
  • Product analytics and sessions: purged automatically on a configurable schedule (currently 90 days for signed-out events and 180 days for signed-in events and sessions). If you delete your account, your analytics and error records are stripped of identifiers rather than deleted, so they remain only in aggregate, non-identifying form.
  • Email delivery logs, unsubscribe and suppression records: retained to honour your email choices and prevent unwanted mail.
  • Payment and subscription records held by Stripe: retained by Stripe under its own policies and applicable accounting/tax law, even after your Variant Pilot account is deleted.
  • Backups: our hosting provider takes routine backups; deleted data can persist in those backups for a limited period until they age out.

[TO BE ESTABLISHED] Formal maximum retention periods for backups, email logs and security logs have not yet been defined. We will publish specific periods once they are set.

9. Deleting your account and data

You can permanently delete your account from Privacy & data controls in the app. When you do, we remove from our live systems: your stored raw DNA file, your genetic file records, parsed variants and insights, dashboard highlights, research matches, study alerts, watchlist entries, briefings and briefing answers, interest areas, research view state, assistant conversations and messages, AI-generated summaries, category summaries, notifications and notification preferences, push subscriptions and device tokens, consent records (including AI consent), feedback, access-code redemptions, subscription records held by us, and your login record.

Your product-analytics and error records are stripped of your identifiers rather than deleted, so they survive only as anonymous aggregate counts.

If you have an active paid subscription, the app asks you to cancel it (immediately or at period end) as part of deletion so that you are not billed again.

Some information can legitimately remain for a limited time:

  • Routine infrastructure backups, until they age out.
  • Email suppression records, so we do not email an address that opted out.
  • Payment and transaction records held by Stripe for accounting and legal obligations.
  • Security records needed to investigate abuse.

We do not promise instantaneous removal from backups.

10. Your controls

  • Turn raw-file retention on or off, and delete a stored raw file, in Settings.
  • Enable or disable optional AI processing in Settings, and delete AI-generated content.
  • Manage email, research alert and push notification preferences in Settings.
  • Unsubscribe from marketing email using the link in any such email.
  • Delete your account from Privacy & data controls.
  • Request a copy of your account data, or ask a question about your information, by emailing samuelpharbour@gmail.com from your account address.
  • Withdraw AI consent at any time; withdrawing required consent means deleting your account.

11. Security

We use reasonable technical and organisational safeguards, including encrypted connections (HTTPS/TLS), encryption at rest provided by our hosting platform, per-account database access rules, authenticated access to your data, and scoped server-side credentials.

No electronic system can be guaranteed completely secure. We do not claim that the service is end-to-end encrypted, anonymous, HIPAA-regulated or impossible to breach.

12. Children

Variant Pilot is intended for adults. It is not directed to children, and we do not knowingly collect information from anyone under the minimum age stated in our Terms of Service. [FOR APPROVAL] Minimum age is currently stated as 18.

13. International users

Variant Pilot is operated from and hosted in facilities that may be located outside your country. If you use the service from elsewhere, your information may be transferred to, stored in, and processed in other countries where we or our service providers operate, which may have different data protection laws. We apply this policy wherever your information is processed.

[FOR LEGAL REVIEW] Jurisdiction-specific rights (for example under the GDPR or US state privacy laws) and the corresponding legal bases and transfer mechanisms have not been formally assessed and are not claimed here.

14. Changes to this policy

We may update this policy. The effective date above will change, and for material changes we will provide notice in the app or by email and, where appropriate, ask you to review or re-confirm your consent.

15. Contact

Privacy questions: samuelpharbour@gmail.com.

[RECOMMENDED] A dedicated privacy address such as privacy@variantpilot.com does not exist yet; it should be created and substituted here.