Genomic Data Privacy Notice
Supplement to the Mito Health Privacy Policy and Consumer Health Data Notice.
Last Updated: August 5, 2026 · Effective: August 5, 2026
1. Scope
This Genomic Data Privacy Notice (the “Notice”) describes how Mito Health Inc. (“Mito,” “we,” “us”) handles biological samples and genomic data in connection with the Genetic Services. It supplements our Privacy Policy and Consumer Health Data Notice.
Override for genomic data. To the extent our Privacy Policy or Terms contain more general language permitting use or disclosure of de-identified or aggregated information “for any lawful purpose,” or disclosure to research or advertising partners, that language does not apply to biological samples or genomic data. Genomic data is governed by this Notice. We also recognize that genomic data is inherently identifying and cannot be reliably de-identified. We therefore do not rely on de-identification as a basis to repurpose it.
2. Genomic Information We Process
- Fulfillment identifiers: the name, email, phone, and shipping address needed to ship a kit and return your sample.
- Biological sample: the sample you provide, processed by the accredited laboratory.
- Genomic data files: such as your .genome bundle, gVCF, and (on request) FASTQ.
- Genomic insights: interpretation artifacts, insight panels, and answers generated from your genome.
- Concierge interactions: questions you ask and educational responses that reference your genomic insights.
3. Roles and Responsibilities
- Mito is the controller and business for your personal and genomic data in connection with the Genetic Services, and is your first point of contact for privacy requests.
- Genetic Superintelligence Company (operating “The Genome Computer Company”), our sequencing provider (the “Sequencing Provider”), is our processor and service provider, sequencing and processing your sample and genome on our documented instructions.
- The accredited laboratory is an independent controller for the limited sample-retention, quality-assurance, and method-improvement activities required by its accreditation.
- AI model providers are subprocessors engaged under commercial terms that exclude use of your data for training their general models and apply only limited retention (for security, abuse-prevention, legal, and service-operation purposes).
4. How We Use Genomic Data
We use genomic data only to: deliver the sequencing you ordered; generate and surface your educational insight panels and Concierge explanations; provide support; maintain security and prevent fraud; and comply with law.
We will not:
- sell or share your genomic data for cross-context behavioral advertising;
- use your genomic data for targeted advertising;
- use your genomic data to train artificial-intelligence models;
- use your genomic data to make automated decisions producing legal or similarly significant effects about you;
- license or commercially distribute genomic datasets;
- disclose your genomic data to researchers, pharmaceutical companies, insurers, employers, or data brokers; or
- operate any research program on it.
5. Disclosure of Genomic Data
We disclose genomic data only to the processors and subprocessors listed in Section 12, each bound by data-protection terms, and only to provide the Genetic Services to you, plus, where strictly required, in response to valid legal process (see Section 11). We also reserve the right to disclose genomic data in the event of a merger, sale of corporate assets, or similar transaction where the succeeding entity will be bound by the commitments in this Notice.
6. Artificial Intelligence and the Concierge
To produce plain-language explanations, bounded, relevant genomic context may be sent to our AI model subprocessors. We do not send data to AI providers for model training. Where an insight panel or answer is displayed, its safety metadata and limitations are shown unmodified. You can avoid AI processing of your genomic data by not using the Concierge’s genomic features. Current AI subprocessors are named in our subprocessor list, available on request.
7. Consent and Withdrawal
We collect and process your genomic data on the basis of your express written consent, obtained through the Consent and Authorization for Genetic Services before sequencing. You may withdraw consent at any time by contacting help@mitohealth.com or using in-app controls. Withdrawal stops future processing and, at your election, triggers deletion (Section 8). It does not reverse processing already completed and is subject to legal record-keeping.
8. Retention and Deletion
- Your choice at checkout: secure delivery followed by deletion of the hosted genome within approximately 30 days, or ongoing hosting with periodic re-annotation.
- On cancellation or withdrawal: any hosted genome and biological sample are deleted within approximately 30 days. You may first request a portable copy of your genomic data files.
- Deletion timeline: on your deletion instruction, genomic data files and associated records are removed from active systems within approximately 14 days, and from backups within approximately 90 days.
- Biological sample: you can request destruction of your biological sample at any time. In response to such a request, we will instruct the accredited laboratory to destroy the sample and they will do so within 30 days unless they are required by applicable laws, regulations, or government orders (including accreditation guidelines) to retain your sample for a longer period, in which case the laboratory will destroy your sample when permitted by the relevant law, regulation, or order.
If you want to request deletion of your genomic data or your biological sample, please email help@mitohealth.com.
Please note that after we process requests under this section we will retain certain transaction records required by tax and accounting law, with no genomic content.
9. Security and Breach Notification
Genomic data is encrypted in transit and at rest, with least-privilege access controls and audit logging. Our Sequencing Provider is contractually required to notify us of a confirmed personal-data breach affecting your data without undue delay and within 72 hours of confirmation. If a breach affecting your genomic or health data occurs, we will notify affected individuals and regulators as required by applicable law, including the FTC Health Breach Notification Rule and applicable state genetic-privacy and consumer-health-data laws.
10. Where Your Genomic Data Is Stored
Your genomic data is stored and processed in the United States. We do not transfer genomic data outside the United States, and we do not make genomic data accessible to Mito affiliates or personnel located outside the United States. (Bounded context sent to AI subprocessors is processed in the locations described in those providers’ documentation and our agreements with them.)
11. Legal Process
We do not voluntarily provide genomic data to any government agency, but we do so where compelled by valid legal process. Where legally permitted, we will notify you before disclosure so you may challenge the request, and we construe such requests narrowly.
12. Subprocessors
We rely on subprocessors in the following categories, each under a data-protection agreement:
- CLIA/CAP-accredited laboratory sequencing (United States);
- genome sequencing, hosting, and interpretation technology provider (Genetic Superintelligence Company, operating “The Genome Computer Company”);
- cloud hosting, databases, and object storage;
- payment processing;
- email delivery; and
- AI model providers used to generate educational explanations.
A current, named subprocessor list is available on request at help@mitohealth.com.
13. Your Rights
Subject to applicable law, you may request to access, correct, port, or delete your genomic data, obtain a list of the third parties to whom relevant data is disclosed, withdraw consent, and appeal a denied request. We are your first point of contact and will assist with any request that involves our Sequencing Provider. Email help@mitohealth.com. We respond within the timeframes required by law.
14. State-Specific Provisions
- California (GIPA / CCPA as amended by CPRA): genomic data is sensitive personal information. You have access, deletion, correction, portability, sample-destruction, and limit-use rights described above.
- Washington (My Health My Data Act): genomic data is consumer health data and, in addition to this Notice, is also subject to our Consumer Health Data Notice. In the event of a conflict between our Consumer Health Data Notice and this Notice, this Notice will control.
- Other states: equivalent genetic-privacy and comprehensive-privacy rights apply where required, including in Nevada, Connecticut, Colorado, Virginia, Utah, and other states with relevant laws.
- Texas: the Genetic Services are not offered to Texas residents or persons located in Texas at this time (see the Genetic Services Terms).
15. Minors
The Genetic Services are for adults aged 18 and over. We do not knowingly collect genomic data from minors. If you believe a minor’s data has been provided, contact help@mitohealth.com and we will delete it.
16. Changes and Contact
We will notify you of material changes to this Notice before they take effect. Privacy questions and requests: help@mitohealth.com. Our Privacy Officer is Kenneth Lou, reachable at kenneth@mitohealth.com.