GeneFox  /  Legal  /  Privacy Policy

Privacy Policy

Privacy Policy for GeneFox

Effective date: July 3, 2026 · Last updated: July 29, 2026

This Privacy Policy explains how the GeneFox app (“GeneFox,” the “app”) handles information. GeneFox is developed and published by Vindhya Data Science (“we,” “us,” or “our”). It applies to the GeneFox apps for iPhone, iPad, Mac, and Android.

The short version. GeneFox is a privacy-respecting tool for exploring publicly available cancer-genomics and gene-expression data and for analyzing expression matrices you choose to import:
  • We do not require a GeneFox account. There is no GeneFox sign-up, login, or user profile. You may optionally save an API key from your separate NCBI account as described in Section 3a; GeneFox works without one.
  • We do not require GeneFox account or profile information, and we operate no servers that receive or store your questions, searches, datasets, or results. If you choose the optional “GeneFox updates” signup, Vindhya Data Science stores the user-submitted email plus confirmation/suppression state, source, timestamps, integrity-result flag, and pseudonymous rate-limit metadata described in Section 3e. The third-party services the app contacts process the limited request data described below.
  • No advertising, third-party tracking, crash reporting, Firebase Analytics product, or behavioral-usage analytics are included in the app. Supported production Apple destinations initialize Firebase Remote Config at launch; Android leaves Firebase uninitialized until a consent-authorized Cloud Assist request. Section 3d describes the resulting configuration and installation metadata.
  • The app connects to public scientific databases and, on supported production destinations only when you opt in, to a Google AI service to interpret harder questions. What is sent to each is described below.
  • GeneFox is built for researchers and other professional users. GeneFox is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment. The optional Cloud Assist feature is restricted to adults 18 or older by its AI provider’s terms (Section 8).
  • Your imported files and saved work remain in app-private storage and are not uploaded by GeneFox or automatically attached to Cloud Assist. On Apple devices, bookmarks and saved cohorts sync through your own private iCloud account, and Apple may include other app-private content in user-controlled backups or device transfers; Vindhya Data Science cannot access either. Public Android v1 disables operating-system backup and device transfer for app-owned data.

1. What GeneFox does

GeneFox lets you browse and visualize gene-expression and related genomic data from public research repositories — for example TCGA cohorts through the NIH Genomic Data Commons, and public datasets from NCBI’s Gene Expression Omnibus (GEO). To do this, the app sends scientific identifiers and search terms (such as gene symbols and dataset accession numbers) to those public services and displays the results. These requests are made directly from your device to the data providers.

You can also import an expression matrix and optional metadata through a system picker for on-device analysis. Those imported bytes are copied to app-private storage and do not trigger a public-provider request; Section 4 describes storage, backup, and export.

2. Information we do not collect

GeneFox does not collect, request, or transmit:

The app does not use the Firebase Analytics product, Crashlytics, Firebase Cloud Messaging, or any comparable behavioral analytics/tracking service. Supported Firebase-enabled Apple destinations use Firebase Remote Config and Firebase Installations at launch for the operational model setting described in Section 3d; their SDK privacy manifests classify limited, unlinked diagnostic metadata under Apple’s “Analytics” purpose. Android uses the same narrow Firebase product families only after an authorized Cloud Assist request reaches its consent-deferred bridge. GeneFox does not display ads.

GeneFox is not intended for personal, patient, or confidential information. If you enter such information into a GEO search or an explicitly authorized Cloud Assist question, that text is transmitted to the applicable third-party service as described below.

3. Information sent to third parties when you use the app

To function, GeneFox sends a limited amount of information from your device to the services below. Public biomedical requests are limited to scientific identifiers (gene symbols, dataset accession numbers, and public sample identifiers) except where you type free text. On supported Firebase-enabled destinations, Firebase separately receives the integrity and installation/configuration metadata described in Sections 3c and 3d, subject to the platform-specific timing described there. All connections use encrypted HTTPS.

3a. Public biomedical data providers

When you search, browse, or open a dataset, the app queries public research resources operated by third parties, including:

What is sent to these services is limited to the scientific query itself — for example a gene symbol, a dataset accession, a sample barcode, or, in the GEO search box, the text you type and any cancer-term expansion GeneFox generates on your device to perform that search. GeneFox does not add a GeneFox account identifier, advertising identifier, or app-specific device identifier to these public-portal queries. Like any Internet service, the recipient necessarily receives standard network request metadata, which can include the source IP address, request time, TLS/HTTP protocol information, and ordinary request headers. Each recipient handles that information under its published policies.

For an ARCHS4 fallback, GeneFox sends maayanlab.cloud the exact public GSE accession, the species value human or mouse, and the complete list of public GSM accessions for that series. ARCHS4 also receives the ordinary network metadata described above. GeneFox does not add your typed GEO search text, NCBI API key, imported data, or any GeneFox account, advertising, device, or authentication identifier to this request. Immediately before this provider admission, GeneFox refreshes the public Series accession, record type, assay, organism, declared sample count, and enumerated GSM list from NCBI GEO; bookmark-transfer or caller-supplied metadata cannot authorize ARCHS4. The declared count and GSM list must agree. GeneFox accepts the returned raw-count matrix only when it covers that complete public GSM list; it never silently truncates a cohort, and it does not represent ARCHS4 raw counts as TPM.

ARCHS4 states that its provided gene-expression files are licensed under CC BY 4.0. Separately, ARCHS4 states that its data are free for non-commercial purposes and that commercial users should contact MSIP. Please cite Lachmann A et al., “Massive mining of publicly available RNA-seq data from human and mouse,” Nature Communications 9, 1366 (2018), doi:10.1038/s41467-018-03751-6. See archs4.org/help.

For CCLE cell-line expression, the app contacts only xena.treehouse.gi.ucsc.edu. UCSC/Treehouse is both the publisher/provenance source and the one network recipient for this feature. GeneFox sends that endpoint the gene symbol you request, the two fixed public Treehouse dataset names, and public sample identifiers. It does not send a GeneFox account ID, advertising ID, app-specific device ID, authentication token, or API key. The Treehouse Cell Line Compendium v1 content is sourced from CCLE RNA-seq in the NCI GDC. GeneFox requests the six fixed fields published in the exact Treehouse index — Name of cell line, TCGA Acronym, Tissue, disease, Histology, and Subtype/subcategory — for local display and user-initiated export. TCGA Acronym, Tissue, disease, Histology, and Subtype/subcategory are also available as grouping dimensions. The Treehouse sidecar attributes some fields to Cellosaurus, TCGA Acronym to GDSC, and Histology to GDSC and COSMIC. Those are upstream content provenance statements: the GDSC-derived and GDSC/COSMIC-derived fields are retrieved only from the Treehouse index, and CCLE, NCI GDC, Cellosaurus, GDSC, and COSMIC are not separately contacted by this feature. This policy does not make a blanket CC BY claim for every upstream-derived field.

For Treehouse pediatric and rare-tumor expression, the app contacts the same xena.treehouse.gi.ucsc.edu endpoint and adds no new recipient. GeneFox sends the gene symbol you request, the two fixed public Treehouse Tumor Compendium 25.01 PolyA dataset names, and public sample identifiers. It requests five fixed clinical fields — disease, pedaya, sex, age_at_dx, and source_name — for local display, stratification, and user-initiated export. The compendium also publishes study_donor_id and study_dataset_id, which are per-donor identifiers from the contributing studies; GeneFox never requests, displays, or exports either. GeneFox admits only samples whose source study is St. Jude Cloud, the Sequence Read Archive, EGA, ICGC, or the Children's Brain Tumor Network, because the TCGA and TARGET samples in that compendium are the same specimens GeneFox already serves from the GDC hub.

On the first methylation lookup for which the validated reference is not already cached, GeneFox makes one fixed HTTPS GET to https://gdc-hub.s3.amazonaws.com/download/HM450.hg38.manifest.gencode.v36.probeMap. That request contains no gene symbol, sample identifier, dataset accession, free text, or query parameter; AWS receives only the fixed object path and standard network metadata. GeneFox accepts the response only if its exact size and SHA-256 match the audited reference, then caches the parsed map locally (in backup-excluded Library/Caches on Apple platforms, where the operating system may purge it, and in memory for the Android app session).

For the limited UCSC/Treehouse recipient flow, we reviewed UCSC’s published Privacy Principles and logging policies. They state purpose limitation, collection limitation, access limited to legitimate business purposes, safeguards against unauthorized access or disclosure, and no commercial use of personal information. Based on those published commitments, Vindhya Data Science confirms that UCSC/Treehouse provides the same or equivalent protection described in this policy for the limited request information it receives. This confirmation is limited to that direct flow and those published commitments; it is not a claim that GeneFox controls UCSC logs or has a separate data processing agreement. See the UCSC links in Section 6.

GeneFox has no account system. Separately, if you have an NCBI account, you may choose to paste an NCBI E-utilities API key into About/Settings to raise NCBI’s request-rate limit. GeneFox works without a key. If you save one:

Because this optional key identifies the user’s separate NCBI account, store disclosures conservatively treat it as a User ID used for app functionality, linked to the user, and not used for tracking.

For conservative store disclosure, GeneFox treats free-text GEO search history as linked because NCBI receives ordinary network metadata with the request and, when configured, the optional NCBI API key. GeneFox does not add a GeneFox account identifier, advertising identifier, or app-specific device identifier.

Because a free-text search term is transmitted to NCBI, please do not enter personal or confidential information into search fields.

3b. “Ask GeneFox” AI assistant (optional, opt-in)

GeneFox includes an optional natural-language assistant, “Ask GeneFox.” It first tries to interpret your question on your device. For harder questions it can, only with your explicit consent, send the question to Google’s Gemini model through Firebase AI Logic (a Google service) to interpret it.

Cloud Assist is available on supported production iPhone, iPad, native macOS, iPad-on-Mac, and Android execution. Production uses App Attest on supported physical iPhone/iPad hardware, DeviceCheck on supported native macOS and iPad-on-Mac execution, and Play Integrity on Android. An unsupported device, missing or mismatched Firebase configuration, unavailable attestation provider, or other failed release gate leaves Cloud Assist inactive and the local interpretation path available.

3c. App integrity verification

To help ensure that Cloud Assist requests come from a genuine GeneFox app, production uses Firebase App Check with Apple’s App Attest on supported physical iPhone/iPad hardware, Apple’s DeviceCheck on supported native macOS and iPad-on-Mac execution, and Google Play Integrity on Android. Developer and test builds use Firebase’s registered debug providers rather than a production provider.

App Check sends cryptographic app/device attestation and an integrity token to Google. This processing is for security and fraud prevention, not advertising or tracking. Because an integrity token accompanies a Cloud Assist request, Google may be able to associate that request with app/device integrity state. Provider registration and Firebase AI Logic enforcement are console-side controls that the installed client cannot verify; they must be confirmed independently as release evidence. Periodic App Check token auto-refresh is disabled on every platform; a protected authorized request obtains a current token on demand. This does not prevent the provider from processing the attestation needed for that request.

3d. Cloud configuration and installation metadata

Supported Firebase-enabled production Apple destinations use Firebase Remote Config at startup to obtain the currently deployed Cloud Assist model name and retain a real-time listener for published configuration changes while the app runs. These Apple configuration exchanges occur even if you never consent to send a Cloud Assist question.

Android performs only local capability preflight at launch and does not initialize Firebase then. When a consent-authorized Cloud Assist request first reaches Android’s deferred bridge, the app initializes the exact reviewed Firebase identity, Firebase Installations, Play Integrity App Check, Remote Config, and Firebase AI. Before the first AI model is selected, Android installs the reviewed local model default and waits for one Remote Config fetch-and-activate attempt. A transient fetch failure may use the already activated value or that reviewed default. Android does not register a real-time configuration listener. Periodic App Check token refresh is disabled. These configuration and integrity exchanges do not include a question, search term, dataset, result, bookmark, or saved cohort; the separately described question is sent only as part of the authorized Firebase AI request.

For these exchanges, Firebase uses a pseudonymous Firebase Installation ID and installation authorization token to select and deliver configuration values. It also receives limited app/device configuration metadata such as country and language codes, time zone, operating-system version, app version/build, Firebase app ID, bundle identifier, and SDK version. Firebase’s Apple SDK privacy manifests classify limited aggregate SDK/OS metadata as Other Diagnostic Data, used for the store’s Analytics purpose, not linked to you, and not used for tracking. On Android, store taxonomies may classify the country code as approximate location, the installation and integrity identifiers as device or other IDs, and limited OS/app/SDK information as diagnostics. These store-purpose labels do not mean that GeneFox includes the Firebase Analytics product or records your in-app screens, actions, searches, or analyses. Google handles this metadata and the installation identifier under Firebase’s privacy and retention controls linked in Section 6. Firebase documents that it retains a Firebase Installation ID until the Firebase customer requests deletion or app-installation inactivity triggers its lifecycle controls; after deletion, associated data is removed from live and backup systems within 180 days. GeneFox does not currently offer an in-app Firebase Installation deletion control and cannot reliably match a support request or email address to this provider-held pseudonymous identifier. Clearing the app’s data or uninstalling it stops that installation from using the identifier; Firebase’s documented inactivity/deletion lifecycle then governs its provider-held copy. The identifier is unique to an app installation and does not uniquely identify a person or physical device.

3e. Optional email signup (voluntary)

GeneFox offers an entirely optional way to request occasional product updates. If you enter an email address in the website banner or the app’s About/Settings screen, the address is sent to Vindhya Data Science, with Google Cloud Functions/Cloud Run and Cloud Firestore acting as processors. This is voluntary and gates nothing.

4. Information stored on your device and in your own cloud

5. Notifications

GeneFox does not send marketing notifications or user-visible alert notifications. On Apple devices, the private CloudKit/SwiftData bookmark sync may register with Apple’s Push Notification service and use silent remote notifications in the background to learn that data in your private iCloud database changed. These Apple-managed sync signals are used only to keep your private iCloud data current; GeneFox does not use Firebase Cloud Messaging or a marketing-notification service.

6. Third-party services and their privacy policies

The third parties GeneFox connects to process information under their own privacy policies:

GeneFox does not control these providers’ retention or downstream processing. Review the linked policies before sending free text.

7. Data security

All network connections made by GeneFox use encrypted HTTPS/TLS. Apart from the voluntary email flow described in Section 3e — its address, confirmation/suppression and administrative state, integrity result, pseudonymous rate-limit record, and operational logs — GeneFox does not operate a backend that stores your data. Third-party providers may retain request data under their terms as described above. Access to signup application records is restricted to trusted backend/admin credentials; client access is denied by Firestore rules.

8. Age and permitted audience

GeneFox is intended for researchers and other professional users. Based on its specialized genomics purpose, professional positioning, and marketing, Vindhya Data Science’s good-faith assessment is that GeneFox is not directed to, and is unlikely to be accessed by, individuals under 18. This is an audience assessment, not an age-verification guarantee; GeneFox’s scientific content itself carries no age restriction.

GeneFox is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment.

Users under 18 may not use Cloud Assist. Adults may use it only for professional or business scientific research and never for medical advice, as a medical device, or in clinical practice. The feature is optional and opt-in. Its eligibility confirmation records the user’s statement but does not independently verify age; neither that confirmation nor a store age rating is represented as a safe harbor under Google’s terms. Google does not currently publish a quantitative threshold for “likely to be accessed,” so residual interpretive risk remains. Provider terms may change, and users and the publisher should review the current linked terms. Free-text requests sent to third-party providers remain subject to their terms and privacy policies.

9. International users

The public data providers and Google services described above are operated primarily in the United States, so information sent to them (scientific identifiers; Firebase configuration, installation, and integrity metadata on the applicable platform-specific schedule; an explicitly authorized typed query; an optional NCBI API key; or optional signup information) is processed in the United States and other countries where those providers operate. The signup functions are configured for Google’s us-central1 region; Google Cloud and its subprocessors may process service and security data elsewhere under their terms.

Cloud Assist may be used only in locations where Google makes the deployed Gemini service available and where its billing requirements are satisfied. The allowed-region list, deployed Paid or unpaid service status, App Check provider registrations, and Firebase AI Logic enforcement are external release controls that the installed app cannot prove; the publisher must verify and record them before each release. If the service is unavailable, GeneFox’s local interpretation path remains available.

10. Your rights

Depending on where you live, you may have rights under laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA). Except for the voluntary email signup (Section 3e) — for which you can request access, suppression, correction, or verified deletion by emailing us — Vindhya operates no other receiving backend and generally cannot access provider-held request data. Active app storage is under your control through the in-app removal actions described in Section 4; Apple-managed backups and device-transfer copies are managed through your Apple account, device, or computer backup settings and are not accessible to Vindhya Data Science. Save a blank NCBI API key before uninstalling if you want to ensure the Apple Keychain copy is removed. Vindhya cannot reliably match a support request to a provider-held Firebase Installation ID; clear the app’s data or uninstall it to stop that installation from using the identifier, after which Firebase’s documented lifecycle applies. iCloud-synced bookmarks are managed through your Apple account. Requests sent to third parties are governed by their policies and rights processes. If you have questions about your rights, contact us using the details below.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and post the new version at the same location. Material changes will also be reflected in the app’s store listing.

12. Contact us

If you have any questions about this Privacy Policy or GeneFox’s privacy practices, contact:

Vindhya Data Science
Email: info@vindhyadatascience.com
Website: vindhyadatascience.com