1. What We Collect
When you run an analysis, the following data is processed:
- Gene symbols and disease context you enter into the analysis form — used solely to query biological data services and generate your results. These inputs are not logged to a persistent database by the standard analysis flow.
- Standard server logs (IP address, browser type, request timestamp) — retained for up to 30 days for operational monitoring, then deleted.
- Locally stored analysis data — your browser's localStorage may retain your last analysis result and trust scoreboard metrics. This data never leaves your browser unless you explicitly share or save a snapshot.
2. Saved Snapshots
If you use the "Save Analysis" or snapshot feature, the analysis output (gene panel, disease context, results, and scoring metadata) is stored server-side and assigned a UUID. A shareable snapshot may be accessible to anyone with its UUID link. Do not include personally identifiable patient data in analysis inputs.
3. What We Do Not Collect
- We do not require account registration or email addresses for standard analysis.
- We do not use third-party advertising trackers or analytics that profile individual users.
- We do not sell or rent your analysis data for advertising or data-broker purposes.
- GaiaLab is not offered as a service for processing protected health information (PHI). Do not enter patient-identifiable data.
4. Third-Party Biological Data Queries
During an analysis, GaiaLab can query an integrated catalog of external biological data services, including sources such as PubMed, ChEMBL, Open Targets, BioGRID, and ClinicalTrials.gov. The sources actually contacted vary by analysis context, source availability, credentials, feature flags, and plan entitlements; GaiaLab does not claim that every integrated source is queried on every run. Gene symbols and disease context may be transmitted to applicable third-party services as part of those queries. Each service has its own terms of use and privacy policy.
5. AI Model Providers
AI synthesis may use one or more configured model providers, which can include DeepSeek, OpenAI, Google, and Anthropic. The biological context needed for synthesis, such as a gene panel and disease context, may be included in prompts sent to the selected provider. Provider use varies by runtime configuration and availability. Do not submit patient-identifiable information.
6. Cookies
GaiaLab uses localStorage for browser-side preferences and analysis-interface state. No cross-site advertising cookies are set by GaiaLab.
7. Research Use Only
GaiaLab is a research tool. Outputs require expert validation before clinical or therapeutic application. Do not enter patient-identifiable information or protected health information. GaiaLab does not market the standard service as HIPAA-compliant and does not offer a BAA for the standard research workflow.
8. Data Retention
- Server request logs: up to 30 days for operational monitoring
- Saved analysis snapshots: retained according to platform controls or until deletion under an applicable account/workspace policy
- localStorage data: browser-controlled; cleared when you clear browser data
9. Contact
For privacy questions or data deletion requests: partnerships@gailabai.com
GaiaLab · Houston, TX