Privacy policy

Plain English, because DNA is the most identifying kind of personal data there is.

In short: your DNA is used only to match and analyse kits on this site. Raw uploads are deleted after processing, kits belong to your account, nothing is sold or sent to third parties, and you can delete a kit โ€” or your whole account โ€” at any time.

1. Who is responsible

RomanyDNA ("we", "us") is a free community genetic-genealogy service at romanydna.com. For the purposes of the UK General Data Protection Regulation (UK GDPR) we are the data controller for the personal data described here.

Privacy questions, requests and complaints: admin@romanydna.com. We aim to answer within 30 days.

2. What we collect

  • Account data โ€” name, email address, password (stored only as a one-way hash), and anything optional you add: username, region, language, bio, legacy contact.
  • DNA data โ€” the raw file you upload is read once, converted to a compact binary of chromosome, position and two allele letters, and the raw file is then deleted. The binary is what we match against; it carries no rsIDs or names.
  • Derived results โ€” matches and shared segments, admixture / Global25 coordinates, Y and mtDNA haplogroups, phasing and reconstruction outputs, and (for Tree DNA) inferred segments.
  • Family tree content โ€” people, relationships, dates, places, photos, tags, comments and DNA-match links that you or other members add to the shared tree.
  • Messages you send through the site, and feedback you submit.
  • Technical and security data โ€” IP address, last-seen time, and an audit log of security-relevant actions (login, upload, deletion, tree edits).

3. Why we process it, and on what legal basis

  • To run the service (account, matching, analysis, tree) โ€” performance of our contract with you (UK GDPR Art. 6(1)(b)).
  • Genetic data โ€” processed with your explicit consent (Art. 9(2)(a)). You give it when you upload a kit; you can withdraw it by deleting the kit or your account.
  • Security and abuse prevention โ€” our legitimate interests (Art. 6(1)(f)) in keeping accounts and the service safe.
  • Legal obligations we may have to comply with (Art. 6(1)(c)).

4. Who can see your data

  • Your account data is visible to you and, in minimal form (name, username, public profile if you enable it), to other signed-in members.
  • Your DNA matches are visible to the members you match, as they are on any DNA site; raw genotypes are not downloaded or shown to other members.
  • The family tree is shared and editable by signed-in members. Treat anything you add there as visible to the community; use the comments or contact us if a person or photo should be handled differently.
  • We do not sell data, share it with advertisers, or send your DNA to GEDmatch, law enforcement or anyone else. There is no law-enforcement upload path.
  • Ordinary infrastructure providers process data on our behalf: the hosting server, and third-party content delivery only for page assets (jsDelivr for some scripts/styles, OpenStreetMap tiles on map views). Those requests disclose your IP address to the provider as any website request would.

5. How long we keep it

  • Kits and derived results: kept while your account is open, or until you delete the kit. Deleting a kit removes its binary and derived files; deleting your account removes your kits and account data.
  • Tree content: kept while the shared tree exists. You can ask us to correct or remove contributions about you or a person you represent.
  • Security/audit logs: kept for a limited period for security and abuse investigations, then removed.

6. Cookies and tracking

We use a single strictly necessary session cookie (PHPSESSID) to keep you signed in. It is HttpOnly, Secure and SameSite=Lax, and there are no advertising, analytics or third-party tracking cookies on this site.

7. Your rights

Under UK GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten");
  • restrict or object to certain processing;
  • receive data you provided in a portable format;
  • withdraw consent at any time (this does not affect processing already done).

To exercise any of these, email admin@romanydna.com. You can also complain to the UK Information Commissioner's Office (ico.org.uk).

8. Security

Data is stored on a server we control, access is password-protected, DNA files are kept in a compact non-identifying binary, and security-relevant actions are logged. No online service can promise perfect security; if we ever become aware of a breach affecting your data we will tell you and the ICO as the law requires.

9. Children

The service is not intended for children under 18. Please do not upload a child's DNA; test kits for minors should be managed by a parent or guardian on the minor's behalf and with their assent as they grow old enough to understand.

10. Changes

If this policy changes materially we will post the new version here and, where appropriate, email account holders. See also our terms of use.

Last updated: 25 September 2026. This page is the full privacy policy; the homepage carries a short summary.