Privacy Policy

Last updated: September 2026

1. Introduction

Kvali ("we," "our," or "us") operates kvali.app and related services (the "Service"). This policy explains what personal data we collect, how we use it, who we share it with, and your choices.

2. Data We Collect

  • Account data: When you sign up or sign in (email and password, or OAuth with Google, GitHub, or X), we receive identifiers such as your email address and, where provided by the provider, your name and profile metadata. We store account and subscription state in our database.
  • Data you provide: G25 coordinates, sample labels, map placement, bookmarks, workshop inputs, Ancestry Tree profiles (regional assignments without a raw kit), and other content you create in the Service.
  • Raw DNA uploads: If you upload a consumer raw autosomal file (e.g. 23andMe, Ancestry, MyHeritage, FamilyTreeDNA), we process it to derive G25 coordinates and related outputs. We do not keep your full raw file on our servers after processing completes; we retain derived data needed to operate the Service (e.g. G25 string, selected genotype markers for portraits or scoring, conversion entitlements).
  • DNA Portrait (Kvali Origins): We store the subset of markers needed for the portrait panel and curated genotype notes. Optional saved portrait outputs may include a generated image URL, prompt metadata, and derived interpretations—not your original upload file.
  • Support messages: If you contact us via the Support form, we receive your email and message content.
  • Signup attribution: If you answer our optional post-signup question, we store where you said you heard about Kvali.
  • Usage and technical data: Pages and features used, approximate location from IP address, browser and device type, and similar logs needed to secure and operate the Service.
  • Cookies and similar technologies: Essential cookies (e.g. session and preferences), analytics cookies used to understand usage and improve the Service, and the Reddit Pixel used to measure advertising performance.

3. How We Use Your Data

We use data to:

  • Provide, maintain, and improve the Service (map, stories, workshop, Ancestry Tree, portraits, chat).
  • Process subscriptions and one-time purchases (Advanced Explorer, Kvali Origins).
  • Authenticate you and enforce plan limits.
  • Respond to support requests and send service-related communications.
  • Comply with law and protect the Service, users, and our rights.

We do not sell your personal data. We may use aggregated or de-identified data for product improvement and research. For Ancestry Story, we may store anonymized ancestry-component shares (without identities) so we can show how your modeled share compares with other users in aggregate.

4. AI Features

Parts of the Service use third-party AI models (primarily Google Gemini; DNA Portrait image generation may use Google or OpenAI depending on configuration). When you use Kvali AI chat, sample context, ethnicity quiz recommendations, or DNA Portrait, we may send relevant prompts and context (e.g. selected sample metadata, workshop state, summaries of your My DNA entries—not full raw files) to those providers to generate responses or images.

Free accounts have a daily chat limit (5 messages); Advanced Explorer allows up to 100 per day. AI outputs are informational only and may be inaccurate; do not rely on them for medical or legal decisions.

5. Service Providers

We share data only as needed with processors that help us run the Service, under contractual or standard terms where applicable:

  • Supabase — authentication, database, and file storage
  • Vercel — hosting, Analytics, and Speed Insights
  • Reddit — advertising conversion measurement through the Reddit Pixel
  • Mapbox — map tiles and geospatial display
  • Dodo Payments — checkout and subscription billing
  • Resend — transactional and support email delivery
  • Google / OpenAI — AI inference for chat, context, quiz, and portrait features

We may disclose data if required by law or to protect safety, rights, and security.

6. Cookies

Essential cookies are required for sign-in, preferences, and core functionality. We use Vercel Analytics and Speed Insights to understand how the Service is used and improve performance. We also use the Reddit Pixel to measure visits and server-confirmed purchases from our advertising. It may receive page, referrer, browser, device, transaction value, currency, and advertising identifier data. We do not send DNA data or ancestry results. You can clear or block cookies in your browser settings.

7. Data Retention

We retain data while your account is active and as needed to provide the Service, meet legal obligations, and resolve disputes. You may delete My DNA entries and other content in the app where those controls exist. To delete your account or request erasure of associated data, contact us; we will honor requests subject to legal and operational requirements (e.g. billing records).

8. Security

We use reasonable technical and organizational measures to protect your data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

9. Your Rights

Depending on where you live (including the EEA, UK, and certain US states), you may have rights to access, correct, delete, or port your data, or to object to or restrict certain processing. Contact us to exercise these rights. You may lodge a complaint with a supervisory authority where applicable.

10. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.

11. International Transfers

Your data may be processed in the United States and other countries where our providers operate. We rely on appropriate safeguards where required by applicable law.

12. Changes

We may update this policy. We will post changes on this page and update the "Last updated" date. Material changes may be communicated through the Service. Continued use after changes constitutes acceptance where permitted by law.

13. Contact

Privacy questions or data requests: hi@kvali.app. See also our Terms of Service.