Skip to content

Privacy

Your DNA file at Indaga

Most of consumer health-tech depends on keeping your raw data. We won't claim we never touch your data; that isn't true of a hosted app, and pretending otherwise is the bio-babble we're against.

What we learned from 23andMe

When a health-data company fails, your data is the asset.

In 2025, 23andMe filed for bankruptcy. The genetic data of roughly 15 million customers — already exposed once in a 2023 breach — became part of a ~$305M sale, and a coalition of state attorneys general went to court to block the transfer of that data without explicit consent. Privacy regulators advised customers to delete their accounts.

Your raw genetic data is the most permanent, most personal data you will ever generate. It identifies your relatives. It cannot be changed after a leak. It should never sit on a company’s balance sheet — and it should never become a transferable asset.

The model

Where your data lives.

Hosted in the Netherlands, encrypted on disk

Your file and your record live on our server in the Netherlands (EU), on an encrypted disk, and backups are encrypted too. There is no separate key per person, so we don't claim one.

App & Connect — a store of its own

We hold your record in a store of its own. Never sold, never used to train AI.

Connect — the trade-off, stated

Optional, and not part of the paid report: the assistant you connect sees what it reads, under its provider's terms, and most providers process data outside the EU. It never receives your raw DNA file. Want no AI provider to see anything? Don't connect one: your report works without it.

App
A store of its own, on our server in the Netherlands, encrypted on disk
Only inside Indaga. Never sold or used to train AI. Export in the iOS app, or ask us for a copy. To delete, use “Withdraw consent and delete my DNA data” on your dashboard at app.indaga.ai, or email support@indaga.ai; we delete within 30 days.
Connect
The same store, reached by a credential for each assistant, which you can revoke on app.indaga.ai/connect
We return evidence to the assistant you connect, and it sees what it reads, under its provider's terms. Optional, and not part of the paid report. Want no AI provider to see anything? Don't connect one.

In practice

What that means for your rights.

  • Hosted in the Netherlands, encrypted on disk — and no more than that. On the app and Connect your record lives in a store of its own, on our server in the Netherlands (EU). The disk is encrypted and so are the backups. There is no separate key per person, so this sentence does not claim one.
  • Never an asset. Your genome is not sold, not used to train AI, and if the business behind Indaga is ever sold, merged or closed, your DNA data will not pass to anyone else without your explicit consent. Without that consent, we delete it.
  • Export and deletion, with their edges stated. Export your record in the iOS app, or ask us for a copy. To delete, use “Withdraw consent and delete my DNA data” on your dashboard at app.indaga.ai, or email support@indaga.ai; we delete within 30 days, and our encrypted backups roll off within about 8 weeks. The iOS app’s erase removes your health readings and notes, not your genome files.
  • Built with GDPR in mind. Genetic data is treated as special-category, and it is hosted in the Netherlands (EU). The exact security architecture is still being finalised — and the hosted app is already live, so that work is running behind the product rather than ahead of it. We would rather write that down than imply it is settled.

Every concrete claim on this page is reviewed so that it is exactly true. If you ever find a gap between this promise and the product, that is a bug.

Indaga is in active development.

We’re building it privacy-first, cited, and honest about what it can and can’t see.