Why we exist
In late 2023, a major consumer genomics company disclosed that hackers had accessed the genetic data of nearly 7 million people. The company that had asked millions to "trust us with your DNA" could not protect it. By 2025, it had filed for bankruptcy, and the fate of 15 million people's genetic records hung in the balance.
Meanwhile, the science of genomics was accelerating faster than ever. AI systems like AlphaFold were predicting protein structures at a pace unimaginable a decade ago. A pan-European trial (PREPARE, Swen et al., The Lancet 2023) showed that a pharmacogenetic panel could reduce clinically relevant adverse drug reactions by about 30%. The technology to read and interpret human DNA was ready. What was missing was a layer that tools could call without each of them rebuilding it.
DeepDNA was founded to fill that gap: a privacy-first, European-born genomic interpretation layer that other software can call, and that does not sell what it reads to anyone.
Our mission
Your DNA is a letter your body wrote before you were born. Most people will read it through the tools they already use: a personal agent, a health app, a clinic's software. We make sure those tools read it correctly, with sources, and without keeping it.
DeepDNA is built for the people building the tools: one API designed to parse raw DNA exports (23andMe, AncestryDNA, MyHeritage; VCF later in the beta), annotate them against ClinVar, PharmGKB, gnomAD and GWAS, turn laboratory PDFs into structured biomarkers, and cross DNA with bloodwork. We used to plan a consumer report; we retired it in September 2026 to become the layer that agents and apps call instead. The knowledge endpoints are live and free. The parsing endpoints are specified and in private beta, not yet deployed.
European origin, European values
DeepDNA is based in Spain and operates under Spanish and EU law. This is not incidental; it is fundamental to how we operate. Europe wrote the GDPR, and we believe it should also lead the era of genomic self-knowledge rather than import it.
Being European-born means:
- GDPR-native architecture — We did not retrofit privacy. The EU General Data Protection Regulation informed every technical decision from day one. Genetic data is classified as a special category under GDPR Article 9, and we treat it accordingly.
- Data sovereignty — The parsing pipeline is designed for EU-only processing with no transfers of genetic data outside the EEA. We will state the processing location and subprocessors before the beta handles a real file, not after.
- Regulatory alignment — We design for the GDPR and for the AI Act's transparency obligations, and we will say which European Health Data Space provisions apply to us when they apply. We design for compliance, not against it.
- Cultural responsibility — From the inscription at the Temple of Delphi — Know thyself — to Kant's Sapere Aude, the European tradition of self-knowledge runs deep. We carry it forward in nucleotides.
The team
DeepDNA is built by a small team in Spain, with AI assistance and human review on everything that is published, including this page. We are intentionally lean, and we would rather describe what the work involves than inflate who does it.
Curation
Reading the primary literature and the guideline bodies, and turning them into records where every claim has a source and every empty field stays empty rather than guessed.
Parsing and annotation
The unglamorous part: provider formats, genome builds, strand orientation, no-calls, laboratory PDFs and units. This is the private beta, and it is where the correctness lives.
Privacy and infrastructure
Designing for zero-retention processing, encryption in transit and at rest, and the processor role under GDPR Art. 28 for special-category data.
Writing
Docs, gene pages and the blog: explaining what a result means and, just as carefully, what it does not.
Everyone shares a single conviction: your genome belongs to you.
How we work
How the API works
The knowledge endpoints serve a curated dataset — 12 genes, 30 variants and 51 drug–gene pairs today, each record with its sources — bundled into the function at deploy time. No database, no third-party call, no model in the response path. The sources are ClinVar, PharmGKB, PharmVar, the CPIC and DPWG guidelines, OMIM, dbSNP and the primary literature.
The parsing endpoints — DNA files, lab PDFs, the crossover — are specified in the OpenAPI and in private beta, not yet deployed. They are designed to parse in memory and retain nothing. For the approach to variant interpretation and evidence, see our Methodology page.
Privacy by design
The knowledge endpoints receive nothing personal. For the beta, DeepDNA is designed to act as its customers’ processor for GDPR Art. 9 data; the data processing agreement, the processing location and the subprocessors will be published before the beta handles a real file. We set zero cookies and use no third-party trackers. Today’s Privacy Policy describes the website and the beta-request form.
Our values
- Privacy by design — Your genetic data is the most personal information that exists. We engineered our entire system around not keeping it.
- Scientific rigour — Every claim in a DeepDNA record is backed by a cited source. We say when a field is empty rather than guessing. We never overstate what the science says.
- Transparency — We tell you exactly what we do with data, how the API works, and where every record comes from. No black boxes. Read our Methodology for the full technical approach.
- Spanish and EU law — DeepDNA operates from Spain, under Spanish and EU law, and designs for the GDPR rather than around it.
- Accessibility — Genomic knowledge should not be a luxury. The knowledge endpoints are free with no key, and parsing will be priced by usage with a real free tier. No seats, no subscriptions, no paywall on what a gene means.
- Open science — We publish our methodology and cite every data source. Science that cannot be scrutinised is not science.
What we are not
DeepDNA is not a medical device and does not provide medical diagnoses. The API’s responses are educational information. It does not replace a clinician; it gives the tools you use something concrete to bring to one.
We do not collect DNA samples. We do not run laboratory tests. We do not sell reports to individuals. We are building the layer that reads the genotype files and lab reports people already own, on behalf of the agents and apps they trust. Think of it as a translator that other software calls: the DNA file and the lab PDF are the raw text, and the API is designed to turn them into something a tool can act on and a clinician can check.
Transparency pages
We believe that trust is built through transparency. These pages document every aspect of how DeepDNA operates:
- Methodology — Our scientific approach, variant interpretation, data sources and how evidence is weighed
- Privacy Policy — What data we collect, how we handle genomic data, GDPR compliance, and your rights
- Terms of Service — The legal terms governing use of DeepDNA
- Manifesto — What we believe and why we exist
- API Docs — Every endpoint, live and beta, with the response shape and data handling
Contact
For general enquiries, partnerships, or press:
- Email: [email protected]
For privacy-related questions or data rights requests:
- Email: [email protected]
For scientific or methodology questions:
- Email: [email protected]