Privacy Policy
Last updated May 23, 2026
1. What VisualDNA collects
When you use VisualDNA, we collect the information you enter during onboarding (your first name, age, height, weight, gender identity, and self-reported family origins for you, your mother, and your father) and one portrait photo that you either capture with the device camera or upload from your photo library. We also generate a heritage report tied to your account and store a local copy of the photo on your device so you can revisit past reports.
2. Face data
The portrait you submit contains a face. We use it only to generate an entertainment heritage report. VisualDNA does not perform facial recognition, does not create or store a face template, faceprint, or any biometric identifier, and does not attempt to match your face against any database. The portrait is sent to xAI's Grok vision model once per scan, and the model returns a text description of phenotype traits (hair, eye, skin, and face-shape categories) and a narrative heritage report. We do not retain the photo on our servers after the request completes. A copy of the photo remains on your device, inside the app's private storage, so it can be shown alongside your saved reports; deleting a report from History deletes the on-device copy.
3. Third-party AI services we share data with
To generate your report, VisualDNA sends the portrait you submit and the onboarding answers listed in Section 1 to xAI, the operator of the Grok large language model, via xAI's API. xAI processes this data under its own privacy policy, available at https://x.ai/legal/privacy-policy . xAI states that API inputs and outputs are not used to train its models by default. We do not share your portrait or onboarding answers with any other third party. Before your first scan, the app shows an on-screen consent notice naming xAI and the data being sent, and requires you to affirmatively agree before the scan can begin.
4. How the data is sent
Requests are sent over HTTPS to a Supabase Edge Function we operate
(xai-proxy), which forwards the request to xAI. The Edge Function
enforces a per-user daily scan quota and does not persist the portrait or the
request body.
5. Retention
- Portrait: not retained on our servers. A copy lives on your device inside the app's private storage until you delete the corresponding report from History, at which point the file is removed.
- Onboarding answers: stored on your device so re-scans remember your answers. Cleared when you uninstall the app or reset your data from Settings.
- Heritage report: stored on your device (most recent 20 reports) and may be cached on our servers for up to 30 days, keyed by your onboarding answers and photo identifier, so re-running the same scan returns the same report.
6. Withdrawing consent and deleting your data
You can revoke consent at any time by deleting the app, which removes all on-device data, or by contacting us at karishma.mandal1103@gmail.com to request deletion of any server-side cached reports tied to your account.
7. Children
VisualDNA is not directed to children under 13 and we do not knowingly collect data from them. If you believe a child has submitted data, contact us and we will delete it.
Additional policy terms
- Download and use
our mobile application ( VisualDNA) , or any other application of ours that links to this privacy notice
- Engage with us in other related ways, including any sales, marketing, or events
debit/credit card numbers
billing addresses
- Mobile Device Access. We may request access or permission to certain features from your mobile device, including your mobile device's
camera ,and other features. If you wish to change our access or permissions, you may do so in your device's settings.
- Push Notifications. We may request to send you push notifications regarding your account or certain features of the application(s). If you wish to opt out from receiving these types of communications, you may turn them off in your device's settings.
- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called
"crash dumps" ), and hardware settings).
- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
- To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
- Consent. We may process your information if you have given us permission (i.e.
, consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal information when we believe it is necessary to
fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
- For identifying injured, ill, or deceased persons and communicating with next of kin
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
- If the collection is solely for journalistic, artistic, or literary purposes
- If the information is publicly available and is specified by the regulations
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Business Partners. We may share your information with our business partners to offer you certain products, services, or promotions.
- Offer Wall. Our application(s) may display a third-party hosted
"offer wall." Such an offer wall allows third-party advertisers to offer virtual currency, gifts, or other items to users in return for the acceptance and completion of an advertisement offer. Such an offer wall may appear in our application(s) and be displayed to you based on certain data, such as your geographic area or demographic information. When you click on an offer wall, you will be brought to an external website belonging to other persons and will leave our application(s). A unique identifier, such as your user ID, will be shared with the offer wall provider in order to prevent fraud and properly credit your account with the relevant reward.
| Category | Examples | Collected |
A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name |
B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information |
Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | ||
Transaction information, purchase history, financial details, and payment information | ||
Fingerprints and voiceprints | ||
Browsing history, search history, online | ||
Device location | ||
Images and audio, video or call recordings created in connection with our business activities | ||
Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us | ||
Student records and directory information | ||
Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics | ||
- Receiving help through our customer support channels;
- Participation in customer surveys or contests; and
- Facilitation in the delivery of our Services and to respond to your inquiries.
- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data if it is used for targeted advertising
(or sharing as defined under California’s privacy law) , the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ( "profiling" )
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including
California's and Delaware's privacy law)
- Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including Oregon’s privacy law)
- Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including California’s privacy law)
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including Florida’s privacy law)