Privacy
Updated 4 October 2026
This page says what EviGeno holds about you, why, who can see it, and what you can ask for.
Who runs EviGeno
EviGeno is run by an independent consultant. For anything about your data, write to [email protected].
What EviGeno holds
- Your account: your name, your email address, and either a password or your Google sign-in. A password is stored only as a one-way hash.
- Your case: what you enter about the patient, such as diagnosis, stage and history, and any records you upload, such as pathology and genomic reports.
- Who is on the case: the people you add, their permission level, and how they relate to the patient.
- What the service prepares for the case: matched trials, research, reports, reminders, plan items, and your analyst's review decisions.
How it is used
- To prepare and keep up your case. Records are read to find what applies to this patient.
- To run your account: signing in, invitations, and emails about the case.
- Your analyst reads every result before it reaches you.
Records are never sold or licensed. They are not used for advertising.
Who can see your case
- The people you add to the case, at the permission level you give them: owner, collaborator or viewer.
- EviGeno staff who work on cases.
- Comments on a case can be read only by the people on that case and their EviGeno analyst. Deleting a comment removes its text.
- No other family or user can see it.
Services that handle data for EviGeno
- AI models from outside providers help read documents and search sources. Calls go through OpenRouter and are limited to providers that do not keep or train on the data.
- Public research sources, such as ClinicalTrials.gov and PubMed, are searched with disease and gene terms. They do not receive the patient's name.
- Hosting: servers in the United States.
- Email: account and invitation emails are sent through Purelymail.
- Google: if you choose to sign in with Google, Google handles that sign-in. Page fonts are also loaded from Google Fonts, so your browser contacts Google when a page opens and Google can see your IP address.
- Backups: a daily copy of the system is kept in cloud storage so it can be restored.
Where your data is kept
On servers in the United States. If you live in the EU, EEA, UK or Switzerland, that means your information leaves your region. At the start of a case you are asked for your explicit consent to use health and genetic data. You can withdraw it at any time.
How long it is kept
For as long as the case is open and you want it kept. Ask for deletion and EviGeno deletes the case and its records. Backup copies are removed too.
Your choices
- You can ask what EviGeno holds, ask for a copy, ask for a correction, withdraw your consent, or ask for deletion. Write to [email protected].
- In the EU, EEA, UK and Switzerland you also have the rights your local law gives you, including access, correction, deletion, restriction, portability and objection. You may complain to your data protection authority.
- You can change your name, picture and password in Settings. The owner of a case can remove people from it.
Security
- Pages are served over HTTPS.
- Passwords are stored as one-way hashes, never in plain text.
- Sign-in uses a signed cookie that scripts on the page cannot read.
- A case is open only to the people on it and to EviGeno staff. Pages with case information are not kept in your browser's cache.
No system is perfectly secure. If EviGeno learns that your information was exposed, it will tell you.
Cookies
EviGeno sets only the cookies it needs to work.
- A sign-in cookie, kept for up to 30 days, so you stay signed in.
- An invitation cookie, kept for up to 24 hours, so an invitation link survives signing in.
There are no advertising cookies, and EviGeno does not run analytics.
Children
Accounts are for adults. A parent or legal guardian can send a case for a patient under 18.
Changes
When this page changes, the date at the top changes.