What we collect, what we don't, and what we do with it.
The Source Biome Project (“we,” “us,” “our”) is a 501(c)(3) community-funded nonprofit organization. Atlas is our first product. This Privacy Policy describes the information we collect when you visit our website, create an Atlas account, upload microbiome data, keep a journal, or contact us — how we use it, who processes it, and what your rights are.
1. What we collect
Account information. When you create an account, our authentication provider (Clerk) collects your email address and, if you choose Google sign-in, your Google account’s basic profile (name/email). We receive your account identifier and email.
Data you upload and create in Atlas.
- Microbiome test files and parsed results — the files you upload and the taxa and abundances we parse from them, along with the sequencing method and sample type you specify.
- Journal entries — the diet, symptom, medication, and note entries you record.
- Research-contribution choices — whether and at what level you have opted in to the research commons.
Website and diagnostic data. If you use our newsletter or Contact forms, we collect the email address, name, subject, and message you provide, plus your browser/user-agent string and a timestamp for diagnosing technical issues.
2. What we do not collect
- Cookies or tracking pixels for advertising, and no behavioral analytics or session replay
- Information from third-party data brokers
- Payment card details (the product is currently free; if we introduce paid plans, a payment processor — not us — would handle card data)
2a. Sensitive information
Microbiome data can be sensitive and, depending on how you use Atlas, may reveal information related to your health. We treat the data you upload and your journal entries as confidential, restrict access to it, and process it only to provide the Service to you. Atlas is not a HIPAA-covered entity and the data you provide is generally not “protected health information” under HIPAA; nonetheless we apply the protections described in this policy. Please do not upload information about anyone other than yourself.
3. How we use what we collect
We use your information only to:
- Provide Atlas — authenticate your account, store and parse your uploaded data, render your visualizations and trends, and save your journal
- Send you account, security, and (if you have not opted out) product-update emails, and notify you about new research dispatches
- Include your data in anonymized research paired with your journal, which you opt into by creating an account; you can change which data is shared, lower the level, or withdraw entirely at any time in Settings → Contribute
- Respond to messages you send us
- Diagnose technical problems, maintain security, and comply with law
That is the entire list. We do not use your data for any other purpose.
4. What we will never do
- Never sell your data. Individual-level information is not for sale to anyone, for any reason. This is a foundational commitment we will not break.
- Never share with advertisers. We do not run ads, and we do not work with advertising platforms.
- Never use signup data to train AI models. Your email and contact messages are not training data.
- Never combine your email with data from other sources to build a profile of you.
5. Service providers (sub-processors)
We use a small number of vetted service providers that process data on our behalf, under contract, and only to provide the Service:
- Supabase — database and file storage for your account, uploaded data, and journal. Data is stored in the United States and encrypted at rest and in transit.
- Clerk — user authentication (sign-in and account management).
- Vercel — web hosting.
- Resend — transactional and notification email.
- An AI provider you configure us to use (such as Anthropic, OpenAI, or Google) — used only to write the research dispatches from public scientific literature. See Section 5a.
These providers are contractually prohibited from using your data for their own purposes. We do not otherwise share your data with any third party except with your consent, to comply with law, or as described in this policy.
5a. How the research dispatches are generated
The research dispatches are written by an AI system from public scientific literature (for example, abstracts from PubMed, Europe PMC, and preprint servers). Your account, uploaded test data, and journal entries are never sent to the AI provider and are not used to generate the dispatches. The dispatches are the same for all readers and are not personalized to your data. As noted in our Terms, AI-generated content may be inaccurate and is educational only — not medical advice.
6. Your rights
Regardless of your jurisdiction, you have the right to:
- Access — request a copy of the data we have on you
- Correct — fix anything that is inaccurate
- Delete — have your data permanently removed
- Withdraw consent — opt out of communications and remove yourself from the waitlist at any time
- Portability — receive your data in a structured, machine-readable format
To exercise any of these rights, email privacy@sourcebiome.org. We respond within 30 days. There is no charge.
6.1 California residents
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the additional right to know what categories of personal information have been collected and the right to opt out of any “sale” or “sharing” of personal information. We do not sell or share personal information as defined under California law. To make a request, email privacy@sourcebiome.org.
6.2 European Economic Area, United Kingdom, Switzerland
Under the EU and UK General Data Protection Regulations (GDPR), you have additional rights including the right to lodge a complaint with your local data protection authority. The lawful basis for processing your email is your consent (you provided it when signing up); you may withdraw consent at any time. The Source Biome Project is the data controller; Supabase and Vercel are the data processors. To exercise any GDPR right, email privacy@sourcebiome.org.
7. Children
The Source Biome Project is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has signed up, contact privacy@sourcebiome.org and we will delete the data.
8. Data retention and deletion
We keep your account data — including uploaded tests, parsed results, and journal entries — for as long as your account is active. You can delete individual tests or journal entries at any time, or delete your entire account from Settings, which permanently removes your data from our systems (and requests deletion of your login from our authentication provider). Deletion is permanent and cannot be undone.
When you upload a test that parses successfully, we retain the original file’s text alongside the parsed results. We keep it for one reason: if we later find and fix a bug in the importer for your file’s format, we can re-run your original file so your results stay accurate. This text is stored with your account, is only accessible to you (and, for support, our service systems), and is permanently removed when you delete the test or your account. If a file fails to parse, we do not keep its contents at all — only the error messages and the file’s size and type, so you can see why it was rejected.
Newsletter/signup emails are retained until you request deletion or five years from your most recent interaction, whichever is earlier. Contact-form submissions are retained for up to two years to handle follow-up correspondence, then deleted. Data already incorporated into a released anonymized research dataset cannot be retracted, as described in our Terms.
9. Security
Data is encrypted in transit (TLS) and at rest (AES-256 at the database layer). Access to the production database is restricted to a small number of authorized team members. We will notify affected users without undue delay if we discover a security breach involving their personal information, consistent with applicable law.
10. Changes to this policy
We may update this Privacy Policy as the project evolves. We will note the last-updated date at the top of the page. Material changes will be communicated by email to anyone whose data we hold. Continuing to use the site after a change means you accept the updated policy.
11. Governing law
This Privacy Policy is governed by the laws of the State of Wyoming, without regard to its conflict-of-law provisions. Any dispute arising out of or relating to this policy shall be resolved in the state or federal courts located in Wyoming.
12. Contact
For privacy questions or to exercise your rights, email privacy@sourcebiome.org.
For everything else, email hi@sourcebiome.org.