Privacy & Data

Privacy and data security

Your genetic data is among the most sensitive information that exists. Here is exactly how helixXY protects it — technically, legally, and ethically.

7 min read helixXY Help Center

Our commitment

Your genetic data is not like other personal information. A raw DNA file can reveal health predispositions, ancestry, family relationships, and biological characteristics that are unique to you and, in part, shared by your biological relatives. We treat this data with a level of care that reflects its extraordinary sensitivity.

helixXY is built on three foundational principles: privacy-first design (data minimization and isolation are built into the architecture, not bolted on afterward), zero monetization of genetic data (we have no business model that depends on selling or sharing your data), and full compliance with LGPD (Brazil's Lei Geral de Proteção de Dados) and GDPR (the EU's General Data Protection Regulation).

Technical security

1

AES-256 encryption at rest

Your raw genetic file and all derived data are encrypted at rest using AES-256, the same encryption standard used by banks, defense agencies, and major healthcare systems worldwide. Encryption keys are managed through hardware security modules (HSMs) and are rotated on a scheduled basis.

2

TLS 1.3 for all data transfers

Every byte of data transmitted between your device and helixXY servers uses TLS 1.3 encryption — the current industry gold standard for in-transit protection. No data ever travels over an unencrypted connection, including your raw file during upload.

3

Isolated encrypted genetic file storage

Your raw DNA file is stored in a segregated, encrypted storage environment that is physically and logically separate from your account identity and profile data. This means your genetic file cannot be directly linked to your personal information even within our infrastructure.

4

Strict access controls

Only you and any shares you explicitly authorize can access your genetic data and reports. Internally, access to production systems is restricted to a minimal set of authorized engineers, requires multi-factor authentication, and every access event is logged and audited. No employee can access your genetic file without a traceable support justification.

5

Regular third-party security audits

helixXY undergoes independent penetration testing and security audits on a regular schedule. Our infrastructure operates on cloud providers certified to ISO 27001 and SOC 2 Type II. Audit findings are tracked to full remediation, with critical issues addressed immediately.

helixXY uses a zero-knowledge architecture for genetic file storage. Your raw data file is encrypted with keys that are not accessible to our internal engineering team during normal operations. Even our own staff cannot read the contents of your uploaded file.

What data we collect

We collect only what is necessary to provide the service:

What we do not collect:

Do we share your data?

No. Your genetic data is never sold, rented, or shared with any third party for any commercial purpose. This is an unconditional commitment, not a policy subject to future revision. Specifically:

Be cautious of third-party apps that ask for access to your helixXY data. helixXY will never ask you for your lab login credentials (23andMe, Genera, AncestryDNA, etc.). If any service asks for those credentials claiming to "connect" to helixXY, do not proceed — it is not an authorized integration.

Your rights under LGPD and GDPR

Depending on your country of residence, you are entitled to the following rights under applicable privacy law. helixXY honors these rights for all users regardless of jurisdiction:

To exercise any of these rights, contact our Data Protection Officer at privacy@helixxy.com. We respond to all data rights requests within 30 days.

How to delete your data

1

Open Account Settings

Sign in to your helixXY account, click your profile icon in the top-right corner, and select Account Settings.

2

Navigate to Privacy

Click the Privacy tab within your account settings. This page gives you a complete view of the data we hold about you.

3

Click "Delete Genetic Data"

To delete only your raw DNA file and reports while keeping your account, click Delete Genetic Data. To delete everything including your account, click Delete Account.

4

Confirm with your password

Enter your account password to confirm. Deletion is immediate and irreversible. All data specified in the deletion request is permanently removed from active systems within 30 days and from all backups within 90 days.

Data retention

Still need help?

Our team is here for you. Send us a message and we'll get back to you as soon as possible.

Stay updated and never miss anything.

+1k Join the community

No spam. Cancel anytime.

Related articles

How to upload your data

A guided walkthrough of the secure upload process.

Read article →
Understanding your reports

How to read and interpret your helixXY genetic reports.

Read article →
How to download your raw data

Step-by-step guide for every major genetic testing lab.

Read article →