Hacker News new | ask | show | jobs
by flipp3r 2768 days ago
I don't understand why you have your privacy policy as it is right now, at all.

Privacy is important to us. We want to do it right. (...) At no time is your DNA data shared - or sold - to any external party, period. (...) If a genome is uploaded, but the user does not continue and generate a report, the uploaded genome is automatically deleted immediately. As soon as a report has been generated (no more than 10 minutes) the uploaded genome is deleted.

Wow! A company that isn't out to steal your data! Great!

When using Meports you are uploading your genome to our central website for analysis. (...) By uploading your genome you grant us a temporary, limited, revocable, royalty-free, world-wide license to process and use your genome for the purpose of providing you with the service.

"Vision: We believe in using data and software in order to maximize everybody's quality of life. "

(Actually - you even have a different company "vision" on gene.meports.com. Which one is it?)

So what does this mean then? Are you using the word "analysis" to trick people into thinking you don't store data derived from the genome on your servers, but you're not storing the literal file someone is uploading? While, at the same time, reassuring clients you'll never store or sell their data?

1 comments

Not sure I understand your concern: It’s standard boilerplate for the case where private data is required to run an analysis, but is not otherwise used.

Not saying that it should necessarily be trusted but the wording isn’t problematic. What is problematic is the complete lack of legal security.

Definitely not boilerplate. The privacy policy is quite light, doesn't define terms like "external parties", doesn't even have the company's name or origin.
Yeah I mean Im a one man shop, have no lawyer. The privacy policy is this: we don't store your genome or any identifying information beyond the report which is automatically deleted (or deleted at your request) within 48 hours.

Is there anything else you want to know?

I was talking specifically in the context of OP’s comment. I otherwise agree with you. But the wording that OP seems to complain about simply means that, in order to perform the requested analysis, the company needs to temporarily store your data.
I don't see any other way to do it haha