Privacy
Privacy notice
What Indaga collects, why, who else handles it, how long we keep it, and what you can ask of us. The short version for your DNA file is on Your DNA file at Indaga.
Last updated 26 September 2026.
Who is responsible
Indaga is a product of CryptoSvit (Ruslan Plakhuta, eenmanszaak, KVK 89565568), Soesterberghof 102, 2631 LH Nootdorp, Netherlands. CryptoSvit decides how your data is used and is responsible for it. Write to support@indaga.ai about anything on this page. We have not appointed a data protection officer.
What we collect
- Your account. When you sign in with Google, we keep your email address and account IDs, nothing else from Google.
- Your DNA file and what we build from it. The raw data file you upload (23andMe, AncestryDNA, MyHeritage or FamilyTreeDNA), the genotypes read from it, and your report.
- Health data from our iOS app, only if you use it and allow it: the Apple Health readings you choose to share, and notes you type.
- Payment records. Stripe takes your payment on its own page. We receive whether you paid, the amount and the date, never your card number.
- What you write to us at support@indaga.ai.
- Technical logs. Our server logs requests, including IP addresses, to keep the service working and secure. The app uses only the cookie that keeps you signed in, and no advertising or analytics trackers.
Why, and on what legal basis
- Your DNA and health data are used only to build your report and show your readings, on the basis of your explicit consent (GDPR Art. 9(2)(a)). You give it with the box on the upload page, and you can withdraw it at any time.
- Your account and emails are used to provide the service you asked for (Art. 6(1)(b)), for example to tell you when your report is ready.
- Payment records are kept because Dutch tax law requires it (Art. 6(1)(c)).
- Technical logs are kept to protect the service (Art. 6(1)(f), our legitimate interest in its security).
Your report is produced by software. It makes no decision about you with legal or similarly significant effects, and it is wellness information, not medical advice.
Where it is kept, and how
On our dedicated server in the Netherlands (EU), rented from Worldstream. Everything personal on it sits on an encrypted disk, and our backups are encrypted before they leave the server. The disk is unlocked while the server runs, so the encryption protects a removed drive or a switched-off server, not a break-in to the running server. There is no separate key for each person.
Who else handles it
- Worldstream (Netherlands) hosts our server and our backups.
- Cloudflare runs the network in front of our server. Your upload and your report cross it on their way between your browser and our server; Cloudflare does not store them.
- Google handles sign-in. Stripe takes payment. Resend sends our emails, which carry a link and never any genetic information. Your DNA data never reaches these three.
Your genetic data is stored and analysed only on our server in the Netherlands, and it is not sent to any outside database or service.
Cloudflare, Google, Stripe and Resend are US companies. Where they handle personal data in the US, the transfer relies on the EU–US Data Privacy Framework or on the European Commission's standard contractual clauses in our agreements with them.
What we never do
Your personal data is never sold, and never shared for advertising. Your DNA data is never used for research. It never goes to an employer, an insurer or anyone who advises them. It goes to police or other authorities only with a warrant or court order, and we tell you unless we are forbidden to. We will not use data we already hold in a new way without asking you first.
If the business behind Indaga is ever sold, merged or closed, your DNA data will not pass to anyone else without your explicit consent. Without that consent, we delete it.
How long we keep it
- Your DNA file, what we build from it and your account: until you ask us to delete them. We keep the file so your report can be rebuilt when our methods improve.
- Backups: a deleted file stays in our encrypted backups for up to about 8 weeks, then expires.
- Payment records: 7 years, as Dutch tax law requires. They hold no genetic information.
- Server logs: 30 days.
- Emails to support: as long as we need them to help you.
What you can ask of us
Wherever you live, you can ask us to show you the data we hold about you and who else has handled it, to correct it, to give you a copy, to stop using it, or to delete it. You can also withdraw your consent at any time; that does not undo what was done with it before. To withdraw and have your DNA data deleted, use the button on your dashboard or email support@indaga.ai from the address you sign in with; for anything else, email. We stop using your DNA data within 15 days of a withdrawal (straight away with the button) and delete it within 30, and we answer every other request within 30 days.
If we turn a request down, reply with the word “appeal” and we will look at it again and answer within 45 days. You can also complain to the Dutch data protection authority (the Autoriteit Persoonsgegevens) or to the authority where you live. In the US, you can complain to your state's Attorney General.
A few specific rules
- Age. Indaga is for adults. Don't upload a file if you are under 18, or a file that isn't yours unless you are legally allowed to share it.
- Consumer health data. What Washington, Nevada and Connecticut law call consumer health data, and how we handle it, is on our consumer health data policy.
- Florida. We received your DNA data from you. We give the results to your doctor if you ask us to, and we never use them for insurance, employment or credit decisions.
Changes
When this notice changes, the new version appears here with its date. A change never lets us use data we already hold in a new way without asking you first.