DNAForge Privacy Policy
Effective date: August 25, 2026 Company: Humic Labs Incorporated, doing business as DNAForge Contact: hassaan@dnaforge.com
DNAForge is software for designing, organizing, importing, and routing biology work. Users may use DNAForge to manage sequences, plasmids, primers/oligos, notebook context, protocols, files, annotations, provider requests, returned results, and related scientific records. This policy explains how DNAForge collects, uses, shares, stores, and deletes data in the product.
This policy covers the DNAForge product, website, beta downloads, desktop/web applications, hosted services, provider-routing workflows, support channels, diagnostics, analytics, and import/migration tools. It does not govern DNAForge's internal legal/corporate document vault or founder/counsel document-storage process, which is handled separately.
DNAForge does not sell users' raw confidential scientific records, raw Customer Content, or personal information generally. A user who explicitly chooses Join before using Free Hosted activates a Research Contribution setting that allows DNAForge to create and confidentially license qualifying AI Workflow Scenario Data to approved AI research organizations for AI-system development. These recipients may not use or disclose the underlying research for scientific publication, patenting, therapeutic or biological product development, wet-lab experimentation, or competitive exploitation. DNAForge may also create, use, disclose, license, and commercialize aggregated, de-identified, statistical, derived, benchmark, synthetic, transformed, normalized, labeled, scored, or otherwise non-identifying information, including workflow demand, experiment categories, provider availability, quote/order patterns, turnaround times, pricing, failure modes, routing outcomes, provider performance, market trends, and model-training/model-evaluation datasets.
1. Data we collect
Account and workspace data. We collect account identity data such as name, email address, authentication provider, workspace or organization membership, invitations, role/permission settings, account status, and audit-log events. We use this to authenticate users, administer workspaces, enforce access controls, provide support, and maintain security records.
Product and scientific work data. Users may upload, create, edit, import, or generate scientific records in DNAForge. This may include DNA/RNA/protein sequences, plasmids, constructs, primers, oligos, annotations, protocols, notebook entries, experiment plans, files, comments, tags, metadata, provenance, project organization, and import/migration records. This may include unpublished research, proprietary constructs, genetic or sequencing data, and confidential laboratory context.
Electronic lab notebook and source-system migration/import data. If a user uses a DNAForge migration tool, browser extension, file import, or source-system connector, DNAForge may process data the user is authorized to access in electronic lab notebooks, molecular-biology tools, sequence/design tools, LIMS, file stores, or other scientific source systems, including Benchling, SnapGene, and similar software. This may include source URLs, source IDs, entity names, notebook entries, sequence records, files, comments, attachments, project/folder structure, field mappings, import reports, unsupported-field notes, and user-selected migration bundles. A local migration bundle remains local unless the user uploads or imports it into DNAForge. Users are responsible for confirming that they have the right to export, migrate, upload, import, or otherwise process data from those source systems under applicable employer, university, institution, provider, customer, source-system, and third-party terms.
Provider-routing data. When users ask DNAForge to help request quotes, place orders, route jobs, track provider status, or receive returned results, DNAForge may collect and process provider names, selected services, quote/order metadata, project context, order files, sequence/design files, sample metadata, shipping or operational metadata, provider account references, order status, provider communications, returned results, invoices or reconciliation metadata, and support messages.
Website product analytics. Website product analytics is opt-in and browser-local. If a user accepts the website analytics choice, DNAForge uses PostHog for categorized page navigation, approved control interactions, feature-use events, and the DNAForge account ID when the user is signed in. The website analytics choice does not authorize desktop product analytics. Users can turn website product analytics off through the website controls.
Desktop product analytics. Desktop product analytics starts enabled on a new or stale desktop profile. DNAForge shows a persistent disclosure that links to this policy. Users can turn desktop product analytics off at any time in Settings, and an existing opt-out remains in effect across upgrades. DNAForge uses PostHog for categorized navigation, approved control interactions, feature-use events, error categories, and signed-in account identity.
Product analytics content limits. Both website and desktop product analytics disable session replay and console capture. Product analytics excludes typed text, DOM text, arbitrary DOM attributes, clipboard contents, nucleotide or protein sequences, filenames, file contents, prompts, assistant content, tool payloads, terminal content, and raw provider errors. The analytics controls accept only approved semantic events and privacy-safe categories. Sampling and retention are project-configured and may change as the beta evolves.
Authentication health telemetry. Separately from optional website product analytics, DNAForge sends bounded authentication start, success, and failure signals to PostHog so it can detect broken sign-in routes, including organization SSO. These signals include only a fixed authentication-flow category, a fixed provider category, a fixed failure category when applicable, and a fresh random attempt identifier. They do not include the user's email address, account ID, provider message, organization name, or scientific content, and they do not create a PostHog person profile. This authentication-health processing continues when website product analytics is off.
Download, install, boot, and reliability processing. Separately from product analytics, DNAForge may process crash and error reports, the app version, operating system, browser or device metadata, download records, installation, update, and boot events, performance telemetry, and reliability events. DNAForge processes consent-independent download, installer-start, installer-complete, packaged-app boot, and diagnostic-delivery events under its legitimate interests in providing, securing, and repairing the product. This processing continues if a user turns off product analytics. It uses limited technical metadata, such as the app version, target platform, release or build tag, failure category, and pseudonymous download, installer-run, or install identifiers.
Raw diagnostic uploads. Packaged desktop crash, boot-failure, and user-requested log-bundle uploads can include capped tails from DNAForge logs. The desktop app scrubs known secret, email, and home-directory patterns before upload. The receiving service also removes control characters and obvious absolute paths before storage. Text redaction is best-effort and may miss unexpected sensitive content. Routine successful-boot uploads contain no log files. DNAForge stores these raw records separately from PostHog product analytics. The desktop install-beacon and diagnostic-upload records remain stored until an authorized deletion process removes them. DNAForge does not currently apply a fixed automatic deletion period to those records.
Turning website or desktop product analytics off stops new product-analytics collection and deletes unsent application-managed telemetry. It does not stop the separate consent-independent processing described above, and it does not automatically erase events already accepted by PostHog. Users may request deletion of account-linked remote telemetry at hassaan@dnaforge.com. Local purge is application-level and is not a promise of forensic erasure from storage media.
AI Workflow Scenario Data. Before a user's first Free Hosted attempt, DNAForge presents a separate Join / Not now Research Contribution choice. If the user chooses Join, DNAForge records that choice together with the applicable Terms, Privacy Policy, account-setting, and authority versions, and may then collect the starting workspace state actually accessed by an AI feature; the user request; approved agent plan or reasoning summary; human and agent actions; tool calls, inputs, observations, and results supplied to the model; content accessed or created for the session; resulting workspace state; and evaluation, correction, acceptance, rejection, or reward signals. If the user chooses Not now, DNAForge does not start that Free Hosted workflow or collect its Scenario Data. We may retain a limited record of the choice itself. Local, bring-your-own-key, command-line, or other available alternatives remain governed by their own terms and settings.
We do not treat unrelated workspace content, credentials or secrets, data excluded by the Terms or this policy, AI activity that remains only on a user's machine and is not transmitted to DNAForge, general product analytics, or crash-diagnostic content as AI Workflow Scenario Data merely because those categories may be collected through a separate telemetry feature. Separately collected product analytics and reliability diagnostics are Usage Data governed by this policy, not AI Workflow Scenario Data, unless the same information is independently included in the qualifying AI workflow record. An AI workflow using a user-supplied provider key may be eligible only when DNAForge receives the relevant workflow data and the applicable account setting, plan terms, or written agreement designates that workflow as Research Contribution. The provider key itself, credentials, and secrets are never AI Workflow Scenario Data.
Support and communications. If users contact DNAForge, we collect the information they provide in support requests, emails, Slack/Discord/Telegram/meeting channels if used for support, feedback forms, and other communications.
Billing/payment data. If DNAForge adds paid features, payments, credits, subscriptions, provider-routing payments, or invoicing, billing identity and payment-related records may be processed by DNAForge and/or payment processors. DNAForge generally uses payment processors, provider portals, or secure vendor-supported systems where available. If provider credentials or tokens are enabled, DNAForge may store or process the information needed for user-directed provider connections, subject to product controls and security measures.
2. How we use data
DNAForge uses data to:
- provide accounts, authentication, workspace membership, access control, and audit logs;
- create, import, store, search, display, and export scientific product records;
- generate, validate, transform, route, and track provider job/order packets at the user's direction;
- communicate with providers, labs, CROs, and users about quotes, orders, status, exceptions, and returned results;
- run AI and agent workflows requested by the user;
- for accounts with an applicable Research Contribution setting, create confidential workflow scenarios and license them to approved AI research organizations solely for AI-system development;
- debug errors, investigate reliability issues, improve performance, and secure the service;
- provide support, onboarding, migration assistance, and beta feedback workflows;
- comply with legal, security, accounting, tax, and compliance obligations;
- create, use, disclose, license, and commercialize aggregated, de-identified, statistical, derived, benchmark, synthetic, transformed, normalized, labeled, scored, or otherwise non-identifying information, including workflow demand, experiment categories, provider availability, routing patterns, pricing, turnaround, failure modes, routing outcomes, market trends, model-training datasets, model-evaluation datasets, and model benchmarks.
3. AI and agent processing
DNAForge may use AI models, model APIs, local models, agent tools, or workflow services to help users transform sequences, draft protocols, parse imports, validate provider packets, summarize records, classify files, debug product behavior, or operate product agents.
When a user runs an AI/agent workflow, data relevant to that workflow may be sent to model providers or tool services. This may include prompts, selected records, files, metadata, generated outputs, provider-routing context, error traces, and tool-call results.
Training and controls posture:
- Where DNAForge's provider terms or configuration allow it, DNAForge does not authorize third-party model providers selected by DNAForge to train their general foundation models on raw Customer Content submitted through DNAForge for AI features.
- DNAForge may use feedback, usage data, logs, evaluations, derived data, aggregated data, de-identified data, routing outcomes, user-approved examples, and eligible AI Workflow Scenario Data to improve DNAForge products, models, agents, validation systems, routing logic, benchmarks, provider matching, and marketplace intelligence.
- DNAForge may use, disclose, license, or sell aggregated, de-identified, statistical, derived, benchmark, synthetic, transformed, normalized, labeled, scored, or otherwise non-identifying customer-derived data to third-party labs, model builders, providers, customers, or partners for training, fine-tuning, evaluating, benchmarking, validating, or improving their models, tools, products, services, or market intelligence.
- The Free Hosted Research setting, activated by an explicit Join choice, may authorize confidential licensing of qualifying AI Workflow Scenario Data to approved AI research organizations. Selecting Not now does not activate Free Hosted or create a private Hosted setting. Paid, team, enterprise, and written-agreement accounts may have different data-use settings and restrictions.
- DNAForge does not use private Customer Content outside the applicable account setting, plan, or written agreement to train DNAForge-owned models in a way that reveals confidential Customer Content or directly identifies a user/workspace.
- DNAForge does not promise per-workspace AI disablement, bring-your-own-key support, local-only models, per-call consent, provider allowlists, or zero-data-retention unless those controls are available for the specific product feature or plan.
4. Local vs. cloud storage
DNAForge may include local desktop features, local files, local import bundles, and hosted/cloud workspaces.
Data that remains only on the user's machine is not stored by DNAForge unless the user uploads it, syncs it, imports it into a hosted workspace, sends it to DNAForge or an external provider through an AI/agent workflow, attaches it to a support request, routes it to a provider through DNAForge, or the desktop app includes a scrubbed, capped log tail in consent-independent crash or boot-failure diagnostics as described above. Product analytics does not upload complete local workspace files or stored content buffers.
Data stored in a hosted DNAForge workspace may be stored in DNAForge-controlled cloud infrastructure and subprocessors. It may be accessed by workspace members according to their roles and by limited DNAForge personnel or service providers when needed for support, security, reliability, legal/compliance, or user-directed processing.
5. How we share data
DNAForge may share data in the following cases:
- Workspace sharing. Data is shared with members of the user's workspace or organization according to roles, permissions, invitations, and audit-log settings.
- User-directed providers/labs/CROs. When a user routes a quote, order, job packet, file, sample context, or result workflow to a provider/lab/CRO, DNAForge shares the information needed to complete that workflow.
- Segment-level demand intelligence and derived data products. DNAForge may share, license, sell, or commercialize aggregated, de-identified, statistical, derived, benchmark, synthetic, transformed, normalized, labeled, scored, or otherwise non-identifying information about workflow demand, experiment categories, provider availability, routing patterns, pricing, turnaround, failure modes, routing outcomes, market trends, and model-training/model-evaluation datasets, provided the information does not reveal confidential Customer Content or directly identify a user/workspace. DNAForge may use aggressive small-segment reporting under reasonable aggregation thresholds.
- Confidential Workflow Scenarios. DNAForge may confidentially provide qualifying AI Workflow Scenario Data to approved AI research organizations for AI-system development. Recipients are contractually prohibited from scientific publication, patenting, biological research, wet-lab experimentation, therapeutic or biological product development, reidentification, disclosure, redistribution, or competitive exploitation of the underlying research.
- Opt-in identified marketplace demand. If a user asks DNAForge to request quotes, contact providers, publish a provider-facing request, join a marketplace, seek provider outreach, or otherwise make demand visible, DNAForge may share the relevant organization identity, contact information, request details, workflow context, and provider-routing data with selected providers, labs, CROs, marketplace participants, or support services.
- Service providers/subprocessors. DNAForge uses infrastructure and service providers for hosting, authentication, storage, email, analytics/diagnostics, payments, model processing, support, cloud storage, and security. These providers process data to provide services to DNAForge.
- Support and troubleshooting. DNAForge personnel or service providers may access data when needed to answer support requests, investigate bugs, recover data, secure accounts, or respond to user-directed requests.
- Legal/compliance/security. DNAForge may disclose data if required by law, legal process, security investigation, corporate transaction, or to protect rights, safety, or security.
- User-directed exports. Users may export, download, share, or transfer their own data out of DNAForge.
DNAForge does not sell raw Customer Content or personal information. Aggregated, de-identified, statistical, derived, benchmark, and user-directed marketplace/demand data are separate categories and may be used or commercialized as described in this policy and applicable terms.
6. Service Providers and Subprocessors
DNAForge uses service providers and subprocessors in categories including:
- hosting/application infrastructure;
- database/storage/object storage;
- authentication/identity;
- analytics/diagnostics/crash reporting;
- email and notification services;
- support/customer communication tools;
- model providers and AI tool services;
- payment processors, if paid features or provider-routing payments are enabled;
- cloud file storage for user-directed uploads or internal operations.
DNAForge may update service providers and subprocessors from time to time without requiring users to re-sign these terms. We may maintain a current material-subprocessor page or comparable notice. Libraries or dependencies that do not receive customer data are not subprocessors.
Current analytics processor information is available from PostHog's subprocessor list. This direct operational link does not represent a complete named register of every DNAForge service provider or subprocessor.
7. Retention, deletion, workspace removal, and export
Users may request export of product data from DNAForge in a reasonable machine-readable format where technically feasible.
Users may request deletion of their account or removal from a workspace. Workspace owners may request deletion or export of workspace data, subject to role/permission checks and legal/security constraints.
Users may also request deletion of account-linked PostHog analytics. A local analytics toggle stops future capture and purges unsent application-managed telemetry; it is not itself a remote deletion request. Remote deletion is asynchronous and may remain subject to processor capabilities, security/audit records, legal holds, and backup lifecycle constraints.
Some data may remain after deletion for a limited period, including:
- backups and disaster-recovery copies;
- audit logs and security records;
- provider order records and support communications;
- billing/accounting/tax records;
- legal/compliance records;
- de-identified, aggregated, statistical, derived, benchmark, synthetic, transformed, normalized, labeled, scored, demand-intelligence, marketplace-intelligence, routing-intelligence, model-training, model-evaluation, and model-benchmark data that no longer identifies a user/workspace or reveals confidential Customer Content.
For accounts with an applicable Research Contribution setting, withdrawal from contribution is prospective after processing. It stops later Free Hosted workflows and new Scenario Data collection under the withdrawn setting, but does not revoke rights already granted or require DNAForge or recipients to recall, delete, or untrain prior scenarios, delivered corpus copies, model weights, evaluation systems, reward models, or other derived/model effects. A later Join creates a new setting generation for new workflows only. DNAForge deletes raw identifiable source data within 60 days after a verified deletion request, except for the minimum records DNAForge may retain for security, legal, audit, provenance, abuse prevention, and similar permitted purposes.
8. Security
DNAForge uses commercially reasonable administrative, technical, and organizational safeguards appropriate for the beta stage of the product, including access controls, role-based permissions where available, encrypted transport, vendor-supported encryption, audit/security logs where available, secrets management, internal access restrictions, and incident-response procedures.
During beta, security controls are evolving. Do not import data whose contractual, regulatory, export-control, clinical, patient, or institutional restrictions exceed DNAForge's current published controls.
Incident/security contact: hassaan@dnaforge.com.
9. Sensitive biology data
DNAForge treats unpublished scientific work, proprietary constructs, genetic/sequencing data, provider-order packets, protocols, and laboratory context as sensitive product data. DNAForge does not represent this data as ordinary generic SaaS text. Access is limited by workspace controls, product permissions, subprocessors, user-directed provider sharing, and support/security needs.
DNAForge does not claim support for human genetic data, regulated clinical data, export-controlled data, biosecurity-sensitive sequences, institutional data-use agreements, or customer-specific restricted data unless the user has all required permissions and DNAForge has expressly confirmed support for obligations DNAForge itself must satisfy.
10. International, institutional, and regulated data
DNAForge's initial beta policy states what the product is and is not designed for:
- DNAForge is not yet a HIPAA-covered service or clinical records system.
- DNAForge is not yet positioned as a regulated GxP, CLIA, CAP, GLP, GMP, or validated quality system.
- Do not upload, import, route, or process HIPAA-regulated data, clinical records, GxP/CLIA/CAP/GLP/GMP-regulated data, export-controlled data, human-subjects data, or institutionally/sponsor/customer/employer-restricted data unless you have all permissions, approvals, rights, and agreements needed to do so.
- Users are responsible for confirming that they are allowed to upload/import/share data under their employer, university, institution, sponsor, funder, provider, customer, electronic lab notebook, source-system, and third-party terms.
- DNAForge may add enterprise/security addenda later for customers with stricter requirements.
This is the closed-beta boundary for publication. Later enterprise, regulated-data, biosecurity, or institutional support requires separate terms, addenda, and product controls.
11. Policy changes
DNAForge may update this policy as the product, subprocessors, AI providers, provider-routing workflows, or legal obligations change. DNAForge will publish the effective date and may provide notice of material changes through the website, app, email, or other reasonable means.