Privacy Policy
Last updated: 11 September 2026
Quanome is built privacy-first. Your health records and raw genetic data are parsed and stored on your device. Your DNA never leaves it. The limited text that does leave — coach messages you send, and lab documents you choose to have read by AI — is described precisely below, along with your rights.
1. Who we are
Quanome is published by Cultmetrics Oy ("we", "us"), the data controller — a company registered in Finland (Business ID 3595346-9). Contact: [email protected]. As an EU company we process personal data in accordance with the GDPR.
2. What Quanome handles, and where it lives
Quanome works with health information you choose to add:
- Apple Health data you grant access to (e.g. steps, heart rate, sleep, body measurements).
- Lab and medical documents you import (read via on-device text recognition).
- DNA files you import (23andMe, Ancestry, VCF, or whole-genome).
- A profile you enter: name, date of birth, sex, and height.
All of this is stored in a database on your device only. We do not host an account system and you do not log in. Your raw genetic files are never uploaded to our servers. Lab documents are read on the device; their recognized text is sent for AI extraction only when you import them (section 3). Apple Health data is read on the device; specific values are included in an AI request only when the coach needs them to answer a question you ask (section 3).
3. The AI coach and AI document reading
Two features use AI processing, which means some text leaves your device when you choose to use them:
- AI coach. When you ask the coach a question, your message and only the small, specific slices of your health data needed to answer it are sent to our backend (
api.quanome.com), which forwards the request to our third-party AI provider, OpenRouter (openrouter.ai, which routes the request to the underlying large-language-model provider), to generate a reply. Your raw genome and full record set are not sent; the coach requests only the specific values it needs. - AI document import. When you import a lab document, the recognized text is sent to our backend and the same third-party AI provider (OpenRouter) to extract structured results, which are then stored back on your device.
What is shared and with whom: the only personal data that leaves your device is the text of your coach message (or imported document) plus the specific health values needed to answer it, sent to OpenRouter via our backend. This data is used only to generate your result in the moment. We do not use your health content to train AI models, and we route AI requests only to zero-data-retention endpoints whose operators do not collect or train on the content. It is not kept as a long-term record on our servers beyond what is needed to process the request and basic operational logging. The coach asks for your confirmation in the app before its first AI request; starting a document import is your instruction to process that document's text. Before document text is passed to the AI provider, our backend also strips Finnish personal identity codes (henkilötunnus) from it.
Legal basis: your explicit consent, given by choosing to use these features. You can simply not use them, and the rest of the app continues to work fully on-device.
4. Pseudonymous usage statistics and abuse prevention
To understand and manage costs, we log basic usage of the AI coach: a random install identifier (a token with no name, email, or contact details — pseudonymous data under the GDPR), the number of AI tokens used, and the processing cost. These logs contain no message content and no health data and are deleted after 90 days.
To protect the service against abuse, our backend also keeps daily request counters keyed by the install identifier and your IP address, and technical import diagnostics; both are deleted after 7 days. Legal basis for this section: our legitimate interest (Art. 6(1)(f) GDPR) in operating, securing, and paying for the service.
5. Health and genetic data (special category)
Health and genetic data are "special category" data under the GDPR and receive heightened protection. Quanome's design reflects this: such data stays on your device by default, and it only leaves it for the AI features above, which you control and consent to. Quanome is an educational and informational tool and does not provide medical diagnosis or advice.
6. Third parties
- Apple HealthKit — accessed on your device under Apple's permissions. We have no access to your HealthKit store; specific values are included in an AI coach request only when needed to answer a question you ask (section 3).
- OpenRouter and the underlying AI model provider(s) (currently Google's Gemini models) — process AI coach and document-import requests on our behalf, on zero-data-retention endpoints.
- Hostinger — hosts our backend.
- Cloudflare — our website (quanome.com) is delivered through Cloudflare's network, which processes visitor IP addresses as part of serving and protecting the site.
- SendFox — if you subscribe to our email updates, your email address is processed by SendFox, our email provider, to send you occasional product updates and news. SendFox is US-based; transfers rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses. You can unsubscribe from any email at any time.
- Genetic testing partners — Quanome may link to third-party genetic testing vendors (e.g. DanteLabs) using a referral link. If you follow such a link and purchase, that vendor handles your data under its own privacy policy; we do not share your Quanome data with them.
- Google — we use Google Analytics 4 and Google Tag Manager to measure website traffic in aggregate, and may use Google Ads to measure the effectiveness of our advertising. These load on the website only, and only after you consent.
- Meta Platforms — we use the Meta (Facebook) Pixel on the website to measure actions such as clicks on our app-store buttons, so we can gauge and improve our advertising. It loads only after you accept Marketing cookies and can be declined without affecting the site; it is not used in the Quanome mobile app.
We do not sell your personal data.
7. International transfers
Some providers (such as our AI provider) may process data outside the European Economic Area, including in the United States. Where this happens we rely on appropriate safeguards such as the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
8. Data retention
Data stored on your device remains until you delete it or remove the app; you can clear imported DNA results and other data from within Quanome at any time. AI requests are processed transiently on zero-data-retention endpoints. On our backend, pseudonymous AI usage logs are kept for 90 days, and abuse-prevention counters and import diagnostics for 7 days (section 4).
9. Security
Your health data lives on your device, protected by your device's own security (passcode, biometrics, and OS-level encryption). Data in transit to our backend and AI provider is encrypted over HTTPS.
10. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent at any time. Because your health data is stored on your device, you can exercise much of this directly by editing or deleting it in the app, or by deleting the app. For anything else, contact us at [email protected].
You also have the right to lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman (tietosuoja.fi).
11. Children
Quanome is not directed at children and is intended for users aged 16 and over. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the latest revision, and material changes will be shown on this page.
13. Cookies and website analytics
This website (quanome.com) uses cookies and similar technologies. Strictly necessary cookies are always active. Analytics and other optional cookies load only after you consent via our cookie banner, which you can reopen any time from the "Cookie settings" link in the footer. We use Google Analytics 4 (through Google Tag Manager) with Google Consent Mode to measure site traffic in aggregate. If you accept Marketing cookies, we also load the Meta (Facebook) Pixel — and may load Google Ads tags — to measure and improve our advertising (for example, how many visitors click through to our app-store pages); these do not load if you decline Marketing cookies. You can withdraw or change your choice at any time. This section concerns the website only — the Quanome mobile app does not use advertising or website-analytics cookies.
If you subscribe to our email updates, we collect the email address you provide, with your consent, to send you occasional product updates and news about Quanome. We store it on our own backend (hosted by Hostinger) and use SendFox, our email provider, to send those messages (see Third parties above). We do not sell it, and you can unsubscribe from any email at any time.
14. Contact
Questions about this policy or your data: [email protected] (Cultmetrics Oy, Finland).