"Would you really trust a company with your DNA after what happened with 23andMe?"
I’ve seen this question come up a lot recently, and it’s a fair one.
In 2023, 23andMe suffered a significant data breach affecting nearly 7 million customers. Attackers exploited weak password practices to access accounts, then used the platform's own DNA matching feature to harvest data at scale - exposing names, ancestry profiles, and health predisposition data.
It shook confidence in the genetics industry, and understandably prompted people to ask hard questions about how their data is handled.
The lesson wasn't simply about security. It highlighted the responsibility that comes with holding deeply personal information, both in how it's protected and how it's used.
People are starting to take their data seriously. And when it comes to something as personal as DNA, they absolutely should.
I’m the CEO and founder of FitnessGenes. We’ve spent the last 12 years helping people understand their genetics, and our view on data ownership has always been simple:
Your DNA belongs to you.
Not us. Not partners. Not the highest bidder.
You decide if it’s used, how it’s used, and whether it stays with us at all. If you want to delete it, you can do, with zero friction.
Some companies in the genetics space have built business models around monetising customer data, whether that’s through partnerships, research, or aggregation.
We haven’t. And we won’t.
We don’t sell your data.
We don’t share it for someone else’s financial benefit.
We don’t use it for research without your explicit consent.
So, what do we use your data for?
Just one thing: to make your experience better.
FitnessGenes has been built on the simple idea that by providing you with better, more personalised insights into your health and wellbeing, we can give you back years of healthy life.
To this end, your data is used to improve our model and recommendations. To understand what is working and what is not, so we can deliver that value to you.
Occasionally, that means collaborating with academic and industry institutions. We work with select groups, including the Universities of Oxford, Loughborough and Birmingham. Every partnership involves a formal ethical review, requires opt-in consent, and commits us to publishing research outcomes - including findings that don't support our current approach.
We believe that kind of transparency is important. It's how good science works, and it's how we keep getting better.
Designed with privacy in mind
We designed our platform with privacy in mind from the outset, and that continues to guide how we operate today.
As a GDPR-compliant business, privacy is built into the way we work. That means limiting access to personal data, applying modern security practices, and regularly reviewing our processes as expectations and standards evolve.
Protecting customer data is an ongoing responsibility, and one we take seriously.
Why it matters
Awareness of personal data privacy, especially around genetic information, is growing. I think that's a good thing.
Trust matters in this industry, but it shouldn't be taken for granted. People should understand how their data is used, who can access it, and what control they have over it.
That's why we've always tried to be clear about our approach to data privacy and ownership. It's how we've operated for more than a decade, and it's how we'll continue to operate.
The bottom line
Asking questions about how your genetic data is handled is sensible. In fact, more people should.
The question isn't whether a company can be trusted with DNA data. It's whether that company is transparent about how it uses your data, how it protects it, and what control you have over it.
Those are the questions worth asking.
You can find our full Privacy Promise here.
FAQs
1. What happens to my physical DNA sample once it’s been analysed?
Saliva samples are received and processed by our ISO-certified laboratory partner, where they are held in a secure facility with restricted access and 24-hour surveillance. Following analysis and delivery of results, samples are permanently destroyed within 28 days of receipt by the laboratory.
2. Can I request to delete my genetic data and account permanently?
You are in control of your data. You can access, download, or delete your data at any time via your member account settings. This will erase all your data securely and permanently, right down to our backups.
3. Can I download my raw DNA data, and is it safe to do so?
You can download your raw DNA data at any time from within your member account settings. Once you download your Personal Data from FitnessGenes, it will no longer be secured by the encryption we provide on our servers and, as per our Privacy Policy, you will become fully responsible for ensuring the security of this data.
It is safe to download your data, but we recommend you are cautious about sharing your Personal Data with others due to potential unforeseen social, legal or economic implications for you as an individual. You take full responsibility for any possible consequences resulting from your sharing access to your Results with others.
4. What safeguards do you have against data breaches or hacking?
In accordance with the GDPR, we have appropriate technical and organisational measures in place to safeguard your Personal Information. These include technical and physical restrictions on our servers, which are password protected and only accessible to authorised personnel of FitnessGenes.
Our databases are all encrypted at rest (AES-256) with strict white list access only. Users’ personal details are password protected and stored on secure servers, with genetic and personal data held on separate servers.
Test result data is stored in an encrypted format and saliva samples are anonymised using unique barcodes printed on the collection tubes, which do not contain any Personal Information.
5. Do I have to opt-in to research or can I just get my results?
Your results are the most important thing for you, so if that is all you want, then we are more than happy for you to just get your results.
Upon account registration, we ask for your explicit opt-in consent before sending marketing communications or including your data in research activities. Our lawful basis for both is consent - we will only contact you with marketing emails, product updates, and promotional offers, or use your data for research purposes, if you have actively agreed to each at the point of registration. These are separate opt-ins; agreeing to one does not imply agreement to the other. You can withdraw either consent at any time.
6. How are FitnessGenes different to 23andMe in terms of privacy and data protection?
We do not handle ancestry data like 23andMe did. This means we do not use open matching databases (where people find long-lost cousins), therefore, your data remains entirely private to you, and you choose if you want to share it with others.