Privacy Policy
Last updated: 2026-03-24
This policy explains how Phylomena collects and uses your data. Questions: privacy@phylomena.net
What we collect
- Email address — used for account access and essential service communication; never sold or used for marketing without consent.
- Session cookie — a strictly-necessary HttpOnly cookie that keeps you signed in. No tracking or advertising cookies are set.
- Uploaded files — sequence or alignment files you upload for analysis, stored in United States object storage.
- Usage events — job run counts and error logs for service reliability and abuse prevention. No behavioural profiling.
Legal basis
- Contract performance (Art. 6(1)(b) GDPR) — processing your email and files is necessary to deliver the service you signed up for.
- Legitimate interest (Art. 6(1)(f) GDPR) — usage logs and rate-limit data are processed to prevent abuse and maintain service security.
Third-party processors
- Anthropic — optional copilot parameter suggestions. Only non-specific workflow context may be sent to Anthropic. No raw sequence data or additional identifying information is shared. Anthropic's data processing agreement applies.
- OpenAI — optional copilot parameter suggestions. Only non-specific workflow context may be sent to OpenAI. No raw sequence data or additional identifying information is shared. OpenAI's data processing terms apply.
- Google Cloud (United States) — application hosting, object storage for uploaded files and results, and on-demand compute for analysis jobs. Data is stored and processed in the
us-east4region in Northern Virginia. Google's data processing terms apply. - Neon (United States) — the application database, which holds your account, project, and job records. Data is stored in the AWS
us-east-2region in Ohio. Neon's data processing agreement applies. - Resend — delivery of sign-in links and service notices. Only your email address and the message content are shared. Resend's data processing terms apply.
Data retention
- Uploaded files and job outputs are retained until you delete them or the related project is deleted. Phylomena does not currently enforce an automatic retention window.
- Deleting a file removes it from the application immediately and triggers deletion from backing storage. There is no recycle bin or restore workflow today.
- Account and personal-data deletion requests must be sent to privacy@phylomena.net and are handled manually.
Your rights (GDPR Art. 15–20)
You have the right to access, rectify, erase, and port your personal data, and to restrict or object to processing. To exercise any of these rights, email privacy@phylomena.net. We will respond within 30 days.
Cookies
Phylomena sets exactly one cookie: a strictly-necessary session cookie used to keep you signed in. No third-party, tracking, or advertising cookies are used. Because this cookie is strictly necessary for the service to function, it does not require consent under ePrivacy rules, but we disclose it here for transparency.