Legal

Privacy Policy

Effective August 23, 2026

Your genome is the most personal data you own. It cannot be changed or reissued once it leaks. Kardi is built so that we never hold it in readable form in the first place: your data is encrypted on your device with keys only you have, and what reaches our servers is ciphertext we cannot open.

1. The short version

We cannot read your genetic data. That is not a promise, it is the architecture. Encryption and decryption happen in your browser. Your password and your keys never leave your device. What we store is unreadable to us, and there is no admin backdoor to change that.

2. What we actually collect

DataWhat we seeWhy
Email addressPlaintextYour login identity, verification codes, password reset, and rare service notices.
PasswordNever. Your browser converts it into a derived credential before sign in. The password itself is never transmitted.Authentication.
Profiles, genotypes, protocols, markersAES-256 encrypted ciphertext onlySo your data can follow you across devices without being readable by us.
Research questions you askThe question text and the specific variants needed to answer it, processed transiently. Profile names are not sent.To generate the cited answer. Questions are metered per account for fair use.
Usage countersA number per monthFair-use limits on research questions.
Standard server logsIP address, timestamps, request statusSecurity and abuse prevention. Retained briefly, then gone.

3. How the encryption works

When you create an account, your browser derives two independent secrets from your password. One becomes your login credential. The other wraps a randomly generated vault key that encrypts your data with AES-256-GCM. The vault key is also wrapped by your recovery key, shown to you once at signup. Our servers store the wrapped keys and the ciphertext, none of which can be opened without a secret that only exists on your side.

The honest consequence: if you lose your password and your recovery key, your data is permanently unrecoverable. We cannot restore it for you, for law enforcement, for your family, or for anyone else, because we cannot decrypt it. This is the price of the guarantee above, and we think it is worth it.

4. What never happens to your data

We do not sell, rent, license, or trade your personal information. We do not share it for cross-context behavioral advertising. There are no ad networks, no tracking pixels, and no third-party analytics scripts in the Service. If a future feature would ever involve sharing anything, it will be opt-in, explained in plain language, and off by default.

5. Who touches the infrastructure

Kardi runs on Amazon Web Services in the United States (hosting, authentication, storage, and the research pipeline). AWS processes ciphertext and operational data on our behalf as a service provider and cannot decrypt your vault either. We do not use other subprocessors. Google Fonts serves the typefaces on our pages; your browser requests those files directly from Google.

6. Legal requests

If we receive a lawful demand for user data, we can produce only what we hold: an email address, usage counters, and encrypted blobs that we cannot decrypt. We will notify affected users of such demands unless the law forbids it.

7. Your browser's storage

Kardi uses browser storage for the session (your login tokens and, while a tab is open, the unlocked vault key) and for small conveniences like your theme choice. Closing the browser locks the vault again. We do not use cookies for tracking.

8. Your rights and controls

Residents of states with genetic privacy or consumer privacy laws may have additional rights. Because our storage design already gives you direct export and deletion, exercising them is self-serve. For anything else, email us.

9. Children

Kardi accounts are for adults 18 and over. A parent or legal guardian may keep a profile for their minor child inside their own account. We do not knowingly collect information directly from children.

10. Security

Beyond the end to end encryption itself: all traffic is TLS, passwords are never transmitted, API access requires signed tokens, and stored data sits in access-controlled AWS services. No system is perfect. If a breach ever affects you, we will tell you quickly and plainly, and the encrypted design means an attacker who copies our database still cannot read your genetic data.

11. Changes to this policy

If this policy changes in any meaningful way, we will post the new version here with a new effective date and notify you for material changes. We will never weaken the core commitments in section 1 retroactively; data collected under a promise stays under that promise.

12. Contact

Privacy questions: mikebailey102@gmail.com.