Privacy Policy
Last Updated: May 1st, 2025
Welcome to Everygene—we provide everyday consumers and patients easy access to hospital-grade genetic testing in collaboration with MassGeneralBrigham and downloadable access to their whole genome file. This Privacy Notice explains how Everygene, PBC (collectively referred to as “Everygene”) collects, uses, discloses, and otherwise processes personal data in connection with Everygene’s services and any product, service, or application that references or links to this Privacy Notice.This Privacy Notice does not address our privacy practices relating to Everygene job applicants, employees and other employment-related individuals, nor data that is not subject to applicable data protection laws (such as deidentified or publicly available information). This Privacy Notice is also not a contract and does not create any legal rights or obligations not otherwise provided by law.
Our Role in Processing Personal Data
Data protection laws sometimes differentiate between “controllers” and “processors” of personal data. A “controller” determines the purposes and means (the why and how) of processing personal data. A “processor,” which is sometimes referred to as a “service provider,” processes personal data on behalf of a controller subject to the controller’s instructions.This Privacy Notice describes our privacy practices where we are acting as the controller of personal data.
Our Collection and Use of Personal Data
The categories of personal data we collect depend on how you interact with us and our services. For example, you may provide us your personal data directly when you sign up for our mailing list, register for an account, or otherwise contact us or interact with us.We also collect personal data automatically when you interact with our websites and other services and may also collect personal data from other sources and third parties.
Personal Data Provided by Individuals
We collect the following categories of personal data individuals provide us:
- Contact Information, including first and last name, email address, mailing address, and communication preferences. We use this information primarily to fulfill your request or transaction, to communicate with you directly, and to send you marketing communications in accordance with your preferences.
- Account Information, including first and last name, email address, date of birth, biological sex, account credentials or one-time passcodes, and the products or services you are interested in, purchased, or have otherwise used. We use this information primarily to administer your account, provide you with our products and services, communicate with you regarding your account and your use of our products and services, and for customer support purposes.
- Payment Information, including payment card information, billing address, and other financial information (such as, routing and account number). Please note that we use third-party payment providers, including Stripe, to process payments made to us. We do not retain any personally identifiable financial information, such as payment card number, you provide these third-party payment providers in connection with payments. Rather, all such information is provided directly by you to our third-party payment providers. The payment provider’s use of your personal data is governed by their privacy notice. To view Stripe’s privacy policy, please click here.
- Genetic and Biological Information, including any information or genetic materials you provide to us when you submit a DNA testing kit. We use this information to coordinate the performance of your genome sequencing test, and to facilitate the provision of test results.
- Health Information, including any health information you provide to us in response to our inquiries regarding your health conditions, diagnoses, and history. We use this information to facilitate, for example, the provision of test results.
- Feedback and Support Information, including the contents of custom messages sent via our email address or other contact information we make available to customers. We use this information primarily to investigate and respond to your inquiries, to communicate with you via email, and to improve our products and services.
If you choose to contact us, we may need additional information to fulfill the request or respond to your inquiry. We may provide additional privacy disclosures where the scope of the request we receive or personal data we require fall outside the scope of this Privacy Notice. In that case, the additional privacy disclosures will govern how we may process the information you provide at that time.
Personal Data Automatically Collected
We, and our third-party partners, automatically collect information you provide to us and information about how you access and use our products and services when you engage with us. We typically collect this information through the use of a variety of our own and our third-party partners’ automatic data collection technologies, including (i) cookies or small data files that are stored on an individual’s computer and (ii) other, related technologies, such as web beacons, pixels, embedded scripts, mobile SDKs, location-identifying technologies and logging technologies. Information we collect automatically about you may be combined with other personal information we collect directly from you or receive from other sources.We, and our third-party partners, use automatic data collection technologies to automatically collect the following data when you use our services or otherwise engage with us:
- Information About Your Device and Network, including the device type, manufacturer, and model, operating system, IP address, browser type, Internet service provider, and unique identifiers associated with you, your device, or your network (including, for example, a persistent device identifier or advertising ID). We employ third-party technologies designed to allow us to recognize when two or more devices are likely being used by the same individual and may leverage these technologies (where permitted) to link information collected from different devices.
- Information About the Way Individuals Use Our Services and Interact With Us, including the site from which you came, the site to which you are going when you leave our services, how frequently you access our services, whether you open emails or click the links contained in emails, whether you access our services from multiple devices, and other browsing behavior and actions you take on our services (such as the pages you visit, the content you view, videos you watch, the communications you have through our services, and the content, links and ads you interact with). We employ third-party technologies designed to allow us to collect detailed information about browsing behavior and actions that you take on our services, which may record your mouse movements, scrolling, clicks, and keystroke activity on our services and other browsing, search or purchasing behavior. These third-party technologies may also record information you enter when you interact with our products or services, or engage in chat features or other communication platforms we provide.
- Information About Your Location, including general geographic location that we or our third-party providers may derive from your IP address.
All of the information collected automatically through these tools allows us to improve your customer experience. For example, we may use this information to enhance and personalize your user experience, to monitor and improve our products and services, to offer communications features such as live and automated chat, and to improve the effectiveness of our products, services, offers, advertising, communications and customer service. We may also use this information to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the site; (b) provide custom, personalized content and information, including targeted content and advertising; (c) identify you across multiple devices; (d) provide and monitor the effectiveness of our services; (e) monitor aggregate metrics such as total number of visitors, traffic, usage, and demographic patterns on our website; (f) diagnose or fix technology problems; and (g) otherwise to plan for and enhance our products and services.For information about the choices you may have in relation to our use of automatic data collection technologies, please refer to the Your Privacy Choices section below.
Personal Data from Other Sources and Third Parties
We may receive the same categories of personal data as described above from the following sources and other parties:
- Our Affiliates: We are able to offer you the products and services we make available because of the hard work of our team members across all Everygene entities. To provide our products and facilitate our services, Everygene entities receive personal data from other Everygene entities for purposes and uses that are consistent with this Privacy Notice.
- Business Partners: We may receive your information from our business partners, such as companies that offer their products and/or services as a part of or in connection with our services. For example, certain of our products and services allow our customers to integrate third-party services. If you choose to leverage these third-party service integrations, we may receive confirmation from our business partner regarding whether you are an existing customer of their services.
- Service Providers: Our service providers that perform services on our behalf collect personal data and often share some or all of this information with us. For example, we receive personal data you may submit in response to requests for feedback to our survey providers. With your authorization, we may also receive your health information from our service providers and your healthcare providers.
- Other Sources: We may also collect personal data about you from other sources, including publicly available sources, third-party data providers, brand partnerships, or through transactions such as mergers and acquisitions.
- Inferences: We may generate inferences or predictions about you and your interests and preferences based on the other personal data we collect and the interactions we have with you.
Additional Uses of Personal Data
In addition to the primary purposes for using personal data described above, we may also use personal data we collect to:
- Fulfill or meet the reason the information was provided, such as to facilitate the provision of genome sequence testing, to fulfill our contractual obligations, to facilitate payment for our products and services, or to deliver the services requested;
- Manage our organization and its day-to-day operations;
- Communicate with you, including via email;
- Facilitate the relationship we have with you;
- Request you provide us feedback about our product and service offerings;
- Address inquiries or complaints made by or about an individual in connection with our products or services;
- Create and maintain accounts for our users;
- Verify your identity and entitlement to our products and services;
- Market our products and services to you, including through email and social media;
- Administer, improve, and personalize our products and services, including by recognizing you and remembering your information when you return to our products and services;
- Develop, operate, improve, maintain, protect, and provide the features and functionality of our products and services;
- Identify and analyze how you use our products and services;
- Infer additional information about you from your use of our products and services, such as your interests.
- Create aggregated or de-identified information that cannot reasonably be used to identify you, which information we may use for purposes outside the scope of this Privacy Notice;
- For research and development so we can understand and improve our services (including artificial intelligence and machine learning models). As part of these activities, we may also create aggregated, de-identified, or other anonymous data from your data;
- Improve and customize our products and services to address the needs and interests of our user base and other individuals we interact with;
- Test, enhance, update, and monitor the products and services, or diagnose or fix technology problems;
- Help maintain and enhance the safety, security, and integrity of our property, products, services, technology, assets, and business;
- Defend, protect, or enforce our rights or applicable contracts and agreements (including our Terms of Use), as well as to resolve disputes, to carry out our obligations and enforce our rights, and to protect our business interests and the interests and rights of third parties;
- Detect, prevent, investigate, or provide notice of security incidents or other malicious, deceptive, fraudulent, or illegal activity and protect the rights and property of Everygene and others;
- Facilitate business transactions and reorganizations impacting the structure of our business;
- Comply with contractual and legal obligations and requirements;
- Fulfill any other purpose for which you provide your personal data, or for which you have otherwise consented.
Our Disclosure of Personal Data
We disclose or otherwise make available personal data in the following ways:
- To Our Affiliates: We are able to offer you the products and services we make available because of the hard work of our team members across Everygene entities. To provide our products and facilitate our services, Everygene entities disclose personal data to other Everygene entities for purposes and uses that are consistent with this Privacy Notice.
- To Marketing Providers: We coordinate and share personal data (excluding health records and genomic information) with our marketing providers in order to advertise and communicate with you about the products and services we make available.
- To Business Partners: We may share personal data with our business partners, or we may allow our business partners to collect personal data directly from you in connection with our services. Our business partners may use your personal data for their own business and commercial purposes, including to send you information about their products and services.
- To Service Providers: We engage other third parties to perform certain services on our behalf in connection with the uses of personal data described in the sections above. Depending on the applicable services, these service providers may process personal data on our behalf or have access to personal data while performing services on our behalf.
- To Other Businesses as Needed to Provide Services: We may share personal data with third parties you engage with through our services or as needed to fulfill a request or transaction including, for example, payment processing services.
- In Connection with a Business Transaction or Reorganization: We may take part in or be involved with a business transaction or reorganization, such as a merger, acquisition, joint venture, or financing or sale of company assets. We may disclose, transfer, or assign personal data to a third party during negotiation of, in connection with, or as an asset in such a business transaction or reorganization. Also, in the unlikely event of our bankruptcy, receivership, or insolvency, your personal data may be disclosed, transferred, or assigned to third parties in connection with the proceedings or disposition of our assets.
- To Facilitate Legal Obligations and Rights: We may disclose personal data to third parties, such as legal advisors and law enforcement:
- in connection with the establishment, exercise, or defense of legal claims;
- to comply with laws or to respond to lawful requests and legal process;
- to protect our rights and property and the rights and property of our agents, customers, and others, including to enforce our agreements, policies, and terms of use;
- to detect, suppress, or prevent fraud;
- to reduce credit risk and collect debts owed to us;
- to protect the health and safety of us, our customers, or any person; or
- as otherwise required by applicable law.
- With Your Consent or Direction: We may disclose your personal data to certain other third parties or publicly with your consent or direction. For example, with your permission, we may post your testimonial on our websites.
Your Privacy Choices
The following privacy choices are made available to all individuals with whom we interact. You may also have additional choices regarding your personal data depending on your location or residency. Please refer to our Region-Specific Disclosures below for information about additional privacy choices that may be available to you.
Communication Preferences
- Email Communication Preferences: You can stop receiving promotional email communications from us by clicking on the “unsubscribe” link provided in any of our email communications. Please note you cannot opt-out of service-related email communications (such as, account verification, transaction confirmation, or service update emails).
Automatic Data Collection Preferences
You may be able to utilize third-party tools and features to further restrict our use of automatic data collection technologies. For example, (i) most browsers allow you to change browser settings to limit automatic data collection technologies on websites, (ii) most email providers allow you to prevent the automatic downloading of images in emails that may contain automatic data collection technologies, and (iii) many devices allow you to change your device settings to limit automatic data collection technologies for device applications. Please note that blocking automatic data collection technologies through third-party tools and features may negatively impact your experience using our services, as some features and offerings may not work properly or at all. Depending on the third-party tool or feature you use, you may not be able to block all automatic data collection technologies or you may need to update your preferences on multiple devices or browsers. We do not have any control over these third-party tools and features and are not responsible if they do not function as intended.
Modifying or Deleting Your Personal Data
If you have any questions about reviewing, modifying, or deleting your personal data, you can contact us directly at privacy@everygene.com. We may not be able to modify or delete your personal data in all circumstances.
Partner-Specific Preferences
Certain of our third-party providers and partners offer additional ways that you may exercise control over your personal data, or automatically impose limitations on the way we can use personal data in connection with the services they provide:
- Google Analytics: Google Analytics allows us to better understand how our customers interact with our services. For information on how Google Analytics collects and processes data, as well as how you can control information sent to Google, review Google's website here: google.com/policies/privacy/partners. You can learn about Google Analytics’ currently available opt-outs, including the Google Analytics Browser Add-On here: tools.google.com/dlpage/gaoptout.
Children’s Personal Data
Our services are not directed to, and we do not intend to, or knowingly, collect or solicit personal data from children under the age of 13. If an individual is under the age of 13, they should not use our services or otherwise provide us with any personal data either directly or by other means. If a child under the age of 13 has provided personal data to us, we encourage the child’s parent or guardian to contact us to request that we remove the personal data from our systems. If we learn that any personal data we collect has been provided by a child under the age of 13, we will promptly delete that personal data.
Third-Party Websites and Services
Our services may include links to third-party websites, plug-ins, applications and other services. Except where we post, link to or expressly adopt or refer to this Privacy Notice, this Privacy Notice does not apply to any personal data practices of third parties. To learn about the personal data practices of third parties, please visit their respective privacy notices.
Updates to This Privacy Notice
We may update this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the date at the beginning of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify individuals by email to their registered email address, by prominent posting on this website or our other platforms, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided.
Contact Us
If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please email privacy@everygene.com.
Consumer Health Data Privacy Notice
Effective Date: March 1, 2025
This Consumer Health Data Privacy Notice (the “Consumer Health Notice”) supplements the Everygene Privacy Notice and explains how Everygene, PBC (“Everygene,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes Consumer Health Data (as defined below) of residents of the state of Washington or Nevada, or individuals whose Consumer Health Data is collected in those states through by Everygene and any other website or mobile application that we own or control and which posts or links to this Consumer Health Notice (all collectively, the “Service”). This Consumer Health Notice does not address privacy practices relating to Everygene job applicants, employees, and other personnel. Please note that this Consumer Health Notice is not a contract and does not create any legal rights or obligations not otherwise provided by law.
Our Collection and Use of Consumer Health Data
The term “Consumer Health Data” as used in this Consumer Health Privacy Notice means any personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status as defined in the Washington My Health My Data Act or the Nevada Consumer Health Data Privacy Law (the “Consumer Health Privacy Laws”). The Consumer Health Data we collect depends on the context of your interactions with us and, in most cases, is information that you decide to share with us. This includes information collected through questionnaires, your communications with us, or from your other interactions with our Service. Consumer Health Data does not include information that is considered deidentified under the Consumer Health Privacy Laws.Examples of Consumer Health Data that we may collect include:
- Information you share about your health-related conditions, symptoms, experiences, diagnoses, testing, or treatments.
- Any health-related information that you share with our customer support services.
- Other information that may be used to infer or derive data related to the above or other health-related information.
We may process and/or use your Consumer Health Data (including with your consent where required by the Consumer Health Privacy Laws) for the following purposes:
- To manage and provide the Service.
- To manage, provide, maintain, and improve the business.
- To respond to your questions, concerns, and other requests for assistance.
- For research and providing insights into health behaviors/conditions.
- To create anonymous, aggregated, or de-identified data.
We may also combine your Consumer Health Data with other personal information we collect directly from you or receive from other sources.
1. Sources of Consumer Health Data
The Consumer Health Data we collect depends on the context of your interactions with our Service and, in most cases, is information that you decide to share with us.We and our service partners may collect this type of information over time and across third-party websites and mobile applications. For more information, please see the “Our Collection and Use of Personal Data” section of our Privacy Notice.
2. Our Disclosure of Consumer Health Data
We may share your Consumer Health Data set forth above as follows:
- Service Providers and Business Partners: We work with a variety of service and business providers who help us process your Consumer Health Data, including helping us operate our Sites and Services and supporting our communications.
- Business Transactions: We may take part in or be involved with a business transaction, such as a merger. We may disclose Consumer Health Data to a third-party during the negotiation of or in connection with such a transaction.
- Legal Obligations and Rights: We may disclose Consumer Health Data to third parties: in connection with the establishment, exercise, or defense of legal claims; to comply with laws or to respond to lawful requests and legal processes; to protect our rights and property and the rights and property of others, including to enforce our agreements and policies; to detect, suppress, or prevent fraud; to protect the health and safety of us and others; or as otherwise required by applicable law.
3. Your Privacy Rights
The Laws provide the following rights with respect to Consumer Health Data we collect about you:
- Right to Access / Confirm: You may have the right to confirm whether we are collecting, sharing, or selling Consumer Health Data about you and with whom we may be disclosing such Consumer Health Data, and to access such data.
- Right to Withdraw Consent: If you have provided your consent for our processing or sharing of your Consumer Health Data, you may have the right to withdraw your consent.
- Right to Delete: You may have the right to request that we delete your Consumer Health Data and that all third parties to whom we have disclosed your Consumer Health Data delete such data.
4. How to Exercise Your Privacy Rights
To exercise any of the privacy rights set forth above or to review [or request changes to] data, please submit a request to privacy@everygene.com. Before processing your request, we will need to authenticate your identity. To authenticate your identity, we will generally require matching a minimum amount of information you provide us with the information we maintain about you in our systems. This process may require us to request additional information from you, including, but not limited to, your email address and phone number.In certain circumstances, we may decline a request to exercise the rights described above, particularly where we are unable to authenticate your identity or locate your information in our systems. If we are unable to comply with all or a portion of your request, we will explain the reasons for our decision.
5. Appealing Privacy Rights Decisions
If your request to exercise a right under the Laws is denied, you may appeal that decision by contacting us at privacy@everygene.com. If the appeal is unsuccessful, you may raise a concern or lodge a complaint with the applicable State Attorney General.
6. Changes to this Consumer Health Data Privacy Notice
We may update this Consumer Health Notice from time to time. When we make changes to this Consumer Health Notice, we will notify you by changing the date at the beginning of this Consumer Health Notice. If we make material changes to this Consumer Health Notice, we will notify individuals by email to their registered email address, by prominent posting on this website or our other platforms, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise specified.