Trust & privacy

What happens to your genetic data, step by step

Your raw DNA file goes from your browser straight into one storage bucket in the United States, encrypted in transit and at rest. It is converted, annotated and read to write your report, then it stays there so you can download that report again. You can delete all of it yourself, from Settings, at any time.

This page is a map, not a policy. The Privacy Policy in the app governs how your information is handled and wins wherever the two differ. The Trust & Privacy page answers the six questions people ask before uploading anything.

The short version

  • Collected. The raw DNA file you already own, from AncestryDNA or 23andMe. The medications and supplements you type in. An optional lab report PDF. An optional free-text note about your health background. Your contact details, profile answers, and email address.
  • Stored. Google Cloud, us-central1 region, United States, inside MarkerView's own account, under a signed Business Associate Agreement, encrypted in transit and at rest.
  • Used for. Converting your file, annotating it against curated variant databases, cross-referencing your medications, and writing your report. Nothing else.
  • Deleted. The moment you ask, from Settings. Automatically 21 days after an upload nobody paid for. And a storage rule removes any raw upload that reaches 1,095 days, whatever else happened.

MarkerView is informational. It does not diagnose, no physician reviews your individual report, and a consumer DNA file is screening-grade genotyping rather than sequencing, which is why rare alarming calls are never headlined.

The lifecycle, one step at a time

  1. 1. Upload

    Your browser sends the DNA file straight to one storage bucket over an encrypted connection, using a short-lived link issued for that upload alone. It never passes through the pages you are reading now. An optional lab report PDF goes to the same bucket, in its own folder. Which files are accepted is on supported files.

  2. 2. Processing

    The pipeline works on copies: the upload as received, a staged copy, and a working copy in your job folder. All three are named in the deletion cascade, because deleting only the first would leave two complete genomes behind.

    Your file is converted to a standard variant format, annotated with open-source tools against curated variant databases, and matched against pharmacogenomic guidelines. Your medication list goes to our own lookup service, which asks public US government drug references for the drug name and nothing else. Your lab PDF, findings, medications, age and gender are read by a large language model running inside our own Google Cloud project; under our agreement with Google that content is not used to train its models, and no person there reviews it. The science is on methodology.

  3. 3. Report delivery

    The finished PDF is emailed to the address on your order, usually within a couple of hours, and is also in your dashboard, where the download link is created when you click it and expires shortly after. You can see the document on the sample report page.

  4. 4. After delivery

    If you bought a report, your DNA file, lab documents and report are kept so you can download it again and a re-run can read the same file. The pipeline's working files go after 60 days; the report does not. If you never bought one, nothing is kept: the file, lab documents and analysis go 21 days after the order started, and your medication list and health background text go with them.

    A twelve-month window for signed-in customers who have not paid, with warning emails first, is described in the Privacy Policy but is not switched on. Until it is, the 21-day schedule applies whether or not you signed in.

  5. 5. Deletion

    Sign in, open Settings, choose Delete account. No request form, no waiting period. Every copy of your file, your records, your report and your sign-in identity leave the active systems, and you get an email saying what went and what could not. Details are on the account-deletion page.

    A few things take longer, and a few are out of reach: backups, logs, Stripe's payment record, and a report already emailed to you, which sits in your mailbox and in ours. The table below is the whole list.

How long each thing is kept

Every number below is set in MarkerView's own code or infrastructure.

WhatWhere it livesHow longWhy
Raw DNA file, report boughtCloud Storage, us-central1Until you delete it. A storage rule removes any raw upload at 1,095 days.So a re-run can read the same file.
Raw DNA file, never boughtCloud Storage, us-central121 days after the order started.An unclaimed genome should not sit there.
Lab report PDFSame bucket, separate folderWith the order it belongs to.Source document for your lab values.
Medications, supplements and health background, report boughtCloud SQLUntil you ask us to delete it.So your profile is there if you come back.
The same, never boughtCloud SQLDeleted with the unpaid upload, every time.No health narrative for a non-customer.
Pipeline working filesCloud Storage job folder60 days.Intermediates a paid re-run can replay.
Your finished reportCloud Storage and Cloud SQLUntil you delete it.So you can download it again.
Objects you deletedCloud Storage soft delete7 days, then gone.A provider window we cannot shorten.
Database backupsCloud SQLRolling 14 days, with 7-day point-in-time recovery.Disaster recovery, unreadable meanwhile.
Application logsCloud Logging30 days.May contain your email address.
Security audit logsCloud Logging, locked400 days.Locked retention, no per-entry delete.
Order recordCloud SQLKept: date, amount, the fact of deletion.Financial and legal record-keeping.
Payment recordStripeStripe's own retention obligations.We never hold your card number.

The 1,095-day rule is a backstop, not the policy: it exists so nothing can sit in storage forever if the normal deletion job fails. Nothing is old enough to have reached it.

Who else touches your data

The complete list, matching Section 7 of the Privacy Policy.

ProviderWhat it doesWhat it receives
Google Cloud (United States)Hosting, file storage, the database, the logs, the AI processing.Everything. Your DNA file, lab documents, report and account record live here, under a signed BAA.
Google Workspace (Gmail)Delivers your report email.Your email address and the report PDF. A copy stays in our sending mailbox.
Google Identity PlatformSign-in and email verification.Your email address.
StripePayment on markerview.com.Your email, the amount, and your card details directly from you. Never your DNA file or medications.
CloudflareRoutes and protects markerview.com traffic.Your IP address and request details. Not your files.
Google PlayPurchases made in the Android app.The purchase, under Google's own terms.
US government drug referencesConfirm what a medication is.The drug name only, sent from our servers. No identifier, and not your IP address.

One more is ours, not a third party's. The medication typeahead sends what you have typed to a MarkerView lookup service, which gets that partial drug name and your IP address, not your name or files. It keeps the questions it is asked, stored under the question with no link to any customer, so there is no way to find yours in order to delete it. We would rather name that than leave it out.

What MarkerView does not do

  • We never sell data that identifies you. Not your DNA data, not your lab results, not any other personal information. If we ever share or sell data for research it will be de-identified first, and we will say so plainly first. The blanket version is a promise a company can quietly break later, so we word it exactly.
  • We do not give your information to insurers, employers or family members, and we do not report to insurers. Using MarkerView creates no insurance record.
  • No advertising cookies, and no third-party advertising trackers on the service.
  • Your content trains nobody's models. Under our Google Cloud agreement the model provider does not train on what it processes for us.
  • No physician reviews your individual report. MarkerView does not diagnose. Anything serious is framed for one action: a conversation with your own doctor about confirmatory testing.

Your controls

  • Download everything we hold about you. Settings, then save the export: one file with your account record, orders, the answers you gave, your lab and report file details, and your consents.
  • Delete everything. Settings, then Delete account. It happens immediately. If you cannot sign in, email us from the address you used at purchase.
  • Ask a person. customerservice@markerview.com reaches a human, including about anything on this page you think is wrong.

Where the law protects you, and where it stops

The Genetic Information Nondiscrimination Act of 2008 makes it illegal for health insurers to use your genetic information in eligibility, coverage, underwriting or premium decisions, and illegal for employers to use it in hiring, firing, pay, promotion or job assignment. It does not cover life insurance, disability insurance or long-term-care insurance, though some states add protections there.

Read the map first. Then decide.

You already own the file. The only thing left to choose is whether you want it read.

References

AncestryDNA and 23andMe are trademarks of their respective owners. MarkerView is not affiliated with, endorsed by, or sponsored by either company; it reads the raw data file those services let you download.