How we protect your genetic privacy

Your DNA is yours.
We make sure it stays that way.

When you trust us with your DNA, we take that seriously. This page explains — in plain English — exactly how we built GeneOS so your personal information can never be stolen, leaked, or connected to your genetic data. No fine print. No technical jargon. Just the truth.

🔑 No names stored with DNA 🔬 Certified Fulgent lab 🛡️ SHA-256 cryptography 🏛️ You hold your key

DNA data breaches are real — and they're getting worse

Every major DNA testing company stores your name, birthday, and personal details right alongside your genetic blueprint. When hackers break in — and they do — they walk away with everything about you. That combination is permanent. You can change a password. You cannot change your genes.

🧬
6.9M
Profiles exposed
23andMe breach, 2023. Names, ancestry data, health predispositions — all stolen. Connected to actual people by name.
🏥
500M+
Health records stolen
US healthcare breaches over the last decade. Medical data combined with names and Social Security numbers is a goldmine for identity thieves.
⚠️
Forever
How long it matters
Your DNA never changes. Unlike a credit card you can cancel, genetic data exposed today is exposed for the rest of your life — and your children's lives.

The old approach — "We promise to lock up your file cabinet really well" — has failed repeatedly. GeneOS was designed from the ground up so that a breach of our systems would give an attacker nothing they could use. Not because we promise to protect it. Because the information was never there in the first place.

A numbered key — not your name

When you order a GeneOS kit, our system creates a unique 32-character code called a cryptographic token. This token becomes your identity inside GeneOS. We link everything — your DNA, your health report, your personalized protocol — to this code. Your name lives only in your own records. We never write it down.

What a GeneOS token looks like — this is what we store
a3f8c2e1d94b7f06 · 2e5a9c3b1d8f4e07
32 characters · generated by your computer · mathematically impossible to reverse into a name
✕ Never stored by GeneOS
  • Your full name
  • Date of birth
  • Social Security number
  • Home address
  • Phone number
  • Insurance information
  • Email address
✓ Linked only to your token
  • Your DNA variants & genotypes
  • Health profile answers
  • Personalized supplement protocol
  • Lab results from certified lab
  • Your full health report
  • Peptide & supplement recommendations
🏦

Think of it like a bank's safety deposit vault

Imagine a bank with 10,000 safety deposit boxes. Each box has a number — not your name. The bank stores what's inside the box (your documents, your valuables). But only you hold the key that matches that number. If a thief broke into the bank and photographed every box number, they'd have a list of numbers — and nothing else. They'd have no idea whose box is whose.

GeneOS works exactly this way. We hold your genetic data in the box. Your token number is the key. We never write your name on the box. You are the only one who knows which box is yours.

From mailbox to results — step by step

Here is exactly what happens from the moment you order a kit to the moment your results arrive. Notice that your name is never needed beyond your front door.

1

You order — we create your private token

You place your order online. At that moment, our system generates your unique 32-character token and prints it as a QR code on your collection kit. Think of it like a numbered evidence bag at a hospital. Your name goes on the shipping label to get it to your door. After that, the shipping label is done its job.

✓ Token generated instantly · your name is never attached to the sample bag
2

The kit arrives — you collect your sample

A standard DNA collection kit arrives at your home. You follow the simple instructions (a cheek swab), seal the bag, and drop it in any mailbox. The only thing on the bag is the QR code — your token number. No name. No address. No identifying information.

✓ Completely anonymous from this point forward
3

The lab processes it — no name required

Our certified partner lab (Fulgent Genomics) receives the kit, scans the QR code, and begins analysis. They link their internal accession number to your token — not to any person. The lab technicians processing your DNA have no idea whose sample it is. This is intentional and by design.

✓ Fulgent Genomics — CLIA-certified, CAP-accredited clinical lab
4

Results connect automatically — to your token, not your name

When your DNA analysis is complete, the lab sends the results back to GeneOS. Our system matches them to your token number and activates your health account. At no point did anyone look up "John Smith." They looked up your 32-character code — and your results appeared.

✓ Fully automated · zero manual identity lookup
5

You access your results — with your key

You receive an email with a link to set your password. Or you can simply scan the QR code on your packing slip and enter your token directly. Either way, only someone who holds that 32-character code can open your file. You are in complete control.

✓ Your token · your access · your data

The security is in the math — not in our promises

We don't ask you to trust our security team. We ask you to trust mathematics. Here's why that's a stronger guarantee than anything any company has ever offered.

🔐

SHA-256 — the gold standard

Your token is generated using SHA-256 cryptography — the same algorithm that protects your online banking, the US government's classified communications, and Bitcoin. It has never been broken. It is considered mathematically unbreakable with current and foreseeable technology.

↩️

One-way — can't run it backwards

If someone found your token code (a3f8c2e1…), they cannot reverse-engineer it to find your name or any personal detail. It's like having the ash from a burned document and trying to reconstruct what was written. Mathematically impossible.

🏛️

You control the connection

The only record connecting your name to your token lives in your own hands — the packing slip, your kit confirmation email, or your clinic's records if you went through a medical practice. GeneOS deliberately never holds that connection. We cannot leak what we do not have.

🔍

Even a full breach exposes nothing

If every server GeneOS owns was stolen tomorrow, the attacker would have a database of 32-character hex strings with DNA analysis attached. No names. No birthdays. No Social Security numbers. Nothing a criminal could sell, use for identity theft, or connect to any living person.

How GeneOS compares to traditional DNA testing

Here is an honest comparison of what happens to your data under each model.

Question 23andMe / AncestryDNA GeneOS
Is your name stored with your DNA? Yes — your name, email, and profile are directly linked to your genetic data. No — never. Only a 32-character token is linked to your DNA.
What happens if their servers are hacked? Hackers get your name, ancestry, health predispositions — all tied to your identity. Hackers get a list of random-looking codes. Nothing that can be tied to any person.
Who can access your data? The company, their partners, potentially law enforcement with a subpoena, and any future buyer if the company is sold. Only you, with your token key. We literally cannot look up your file by name because we never stored your name.
Can they sell your data? Yes. 23andMe sold genetic data to GSK for $300M. Your data is their product. No. There is nothing to sell. Unlinked genetic data with no name attached has no commercial value to data brokers.
What encryption standard is used? Standard database encryption — protects in transit, but the data inside is still labeled with your name. SHA-256 token generation — your name is architecturally separated from your DNA, not just encrypted.
What do you get with your data? Ancestry percentages and broad health risk categories. No personalized protocols. No clinical depth. 18,000+ variants analyzed. Personalized 12-week protocol. Peptide and supplement stack. Lifetime access. AI-powered health account.

Frequently asked questions

These are the questions people actually ask us — answered plainly and completely.

Your token is stored in your confirmation email and printed on your kit's packing slip. If you've set up your GeneOS account with an email and password (which we recommend), you can always log in that way — your token is also visible inside your account once you're signed in. Think of the token like a spare key to a safety deposit box: keep it somewhere safe, but you also have your own login as a backup.
We would comply with any valid legal order — but here's the key point: we genuinely cannot link a token to your name because we never stored that connection. A subpoena asking us "who does token a3f8c2e1 belong to?" would produce no useful answer from us, because we don't know. Your clinic or doctor — if you went through one — would hold that mapping in their own private records, just as they hold any other patient information.
No — and this is more than a promise. Anonymized genetic data with no name attached has very little commercial value to the kind of data brokers who buy this information. The reason 23andMe was able to sell their users' data to pharmaceutical companies is because it was name-linked, high-resolution, and consent-tracked. Our data architecture removes the very thing that makes genetic data worth buying. We have no financial incentive to sell what can't be sold.
Fair question. You can verify it yourself. When you go through the kit process, you'll notice that at no point does GeneOS ask for your Social Security number, insurance, date of birth, or any identifying information beyond a shipping address (so we can mail you the kit). Once the kit is in the mail, your name plays no further role in the process. You can confirm this by looking at what information your account actually holds — only your token, your health data, and your email for login purposes.
A token alone is not enough to access your full account if you've set a password — you'd need the token AND your password. Think of the token like your account number at a bank: someone needs your number AND your PIN. If you went through a clinic using GeneOS, they manage the tokens in their own secure system the same way they manage any other patient records — with all the legal protections that medical records carry.
HIPAA is a minimum legal standard — it tells healthcare entities "you must try to protect this data." Compliance with HIPAA doesn't mean a breach can't happen; it means you took reasonable steps. What GeneOS does goes beyond HIPAA: instead of protecting a file that has your name on it, we never put your name on the file at all. You can't violate HIPAA privacy rules around data that was never personally identifiable to begin with. Our model eliminates the risk rather than managing it.
The token system protects everyone equally — adults and minors alike. A parent or guardian would hold the token for a minor and control account access. Because no name, school, or identifying information is ever stored alongside the genetic data, there is no way for someone to connect a minor's DNA profile to their identity through GeneOS's systems.

Ready to know your exact biology — privately?

One kit. One payment of $1,200. Lifetime access to your genetic health account. No subscription. No name stored with your DNA. No compromises on privacy.