01
Scope and applicable framework
This Privacy Policy applies to the guntingAI website, account workspace, application interfaces, analysis services, private-model training functions, public-contribution workflows, documentation, and related operator-controlled systems.
We intend to process personal information consistently with applicable privacy and data-protection requirements, including the Philippine Data Privacy Act of 2012, its implementing rules and regulations, and applicable issuances of the National Privacy Commission. Additional laws may apply depending on your location, institution, data, and intended use.
02
Information we may collect or process
Depending on how you use guntingAI, information may include:
- Account and provenance information: name, email address, institution, department or affiliation, position, role, account status, login events, and administrative records.
- Authentication and security information: password hashes, session identifiers, anti-forgery tokens, security events, rate-limit identifiers, and access-control data.
- Technical and usage information: IP address, approximate network information, browser and device information, timestamps, request identifiers, logs, error reports, page interactions, and service-performance telemetry.
- Research inputs: guide sequences, target sequences, FASTA records, annotations, model names, organism descriptions, genomic coordinates, parameters, notes, and related files or text you submit.
- Generated and derived information: predictions, nearest results, scores, coordinates, job records, model artifacts, embeddings, normalized annotations, metadata, exports, and administrative review records.
- Public and third-party research data: publicly available genomes, annotations, accessions, public datasets, public model artifacts, literature-derived metadata, and user-designated public contributions.
03
Why we process information
We may process information to:
- provide Search, Design, Multiplex, and private-model functions;
- create and administer accounts and preserve research provenance;
- associate jobs, models, limits, results, and publication requests with an account;
- authenticate users, prevent misuse, enforce limits, and protect service integrity;
- store, retrieve, display, export, and delete records at a user’s request;
- debug, secure, monitor, maintain, improve, and develop the service;
- review models proposed for public contribution;
- comply with law, enforce agreements, respond to lawful requests, and protect rights;
- produce aggregated, statistical, de-identified, or non-personal service insights.
Depending on the circumstances, processing may be based on consent, steps necessary to provide requested services, legitimate and lawful operational interests, compliance obligations, protection of legal rights, or another basis recognized by applicable law.
04
Why having an account matters
An account provides continuity and convenience. It allows guntingAI to associate analyses, private models, annotation files, publication requests, quotas, provenance, and saved records with an authenticated user. It also lets users return to completed jobs without depending solely on a browser session.
Guest use may be temporary, session-bound, less recoverable, or deleted sooner. We do not guarantee that guest records can be restored after a session expires, a browser is cleared, a device changes, or temporary storage is removed.
Account creation is optional unless a feature requires persistent ownership, private storage, training, publication review, or account-specific resource controls.
05
Cloud storage and public-data discretion
To provide convenient access, persistent records, reproducible analysis, model availability, backup, caching, indexing, recovery, and service continuity, we reserve the right to store, copy, normalize, transform, cache, replicate, back up, migrate, and process public data and user-authorized data in cloud-based or remotely operated systems selected by us.
Information may be distributed among databases, object storage, processing services, repositories, caches, logs, backup systems, content-delivery systems, and administrative systems. These components may be operated by us or by service providers and may be located in more than one jurisdiction.
Data that is public, placed in a public contribution workflow, already available from a public source, or deliberately submitted for public listing should not be treated as confidential. We may preserve public-source references, metadata, provenance, normalized derivatives, and public-model artifacts for service operation, reproducibility, and historical integrity.
We may decide where and how public data is hosted, mirrored, cached, indexed, or migrated. Convenience features, including persistent account records, depend on this storage discretion.
06
Public and private repositories; copying and theft risk
guntingAI may use both public and access-restricted repositories or storage systems for software, models, checkpoints, manifests, datasets, deployment artifacts, documentation, and service records. Access controls reduce risk but cannot eliminate every risk.
Unauthorized parties may attempt to scrape, copy, fork, clone, download, leak, exfiltrate, steal, redistribute, or reverse engineer materials because of unlawful conduct, credential compromise, vulnerabilities, configuration errors, third-party incidents, or the inherent accessibility of web-delivered systems.
Any unauthorized access, copying, forking, downloading, disclosure, or possession does not create a license, ownership right, public-domain dedication, waiver, consent, or authorization from guntingAI or the Operator. We reserve all available rights and remedies against unauthorized acquisition, use, redistribution, commercialization, impersonation, or misappropriation.
We use safeguards appropriate to the nature and operation of the service, but no internet, repository, cloud, authentication, or storage system can be guaranteed completely secure. You should retain independent copies of important research data and avoid submitting secrets or sensitive information that is not necessary for the requested function.
09
Retention, deletion, and backups
We retain information for as long as reasonably necessary for the purposes described in this policy, including account operation, research provenance, result retrieval, model ownership, security, audit, legal compliance, dispute resolution, and enforcement.
Retention periods may differ by data category. Guest records may be shorter-lived. Public-source records, public contributions, de-identified information, audit records, and information needed to establish or defend legal rights may be retained longer.
Deletion from an active interface may not immediately remove copies from backups, logs, caches, disaster-recovery systems, public mirrors, previously exported files, third-party systems, or independently copied materials. Backup copies may remain until overwritten under normal retention cycles.
10
Security and incidents
We seek to use reasonable administrative, organizational, technical, and access-control measures appropriate to the service. Measures may include authentication, role controls, encryption or protected storage where supported, logging, rate limits, restricted administrative functions, backups, and incident review.
No measure guarantees absolute confidentiality, integrity, availability, or recoverability. To the extent required by applicable law, we will assess and respond to reportable personal data breaches and make required notifications.
11
Your privacy rights
Depending on applicable law and relevant exceptions, you may have rights to be informed, access personal data, object to certain processing, correct inaccurate information, request erasure or blocking, obtain data portability where applicable, withdraw consent where consent is the basis, file a complaint, or seek other remedies.
We may need to verify identity and authority before acting on a request. Some requests may be limited where retention is required by law, security, public interest, contractual necessity, public-source status, intellectual-property protection, legal claims, or another lawful exception.
12
Your responsibilities
You are responsible for:
- submitting only data you are authorized to process;
- providing required notices and obtaining consent or approvals;
- removing unnecessary identifiers before submission;
- protecting account credentials and devices;
- maintaining independent backups;
- choosing appropriate privacy and security controls for your project;
- complying with institutional, contractual, ethical, biosafety, export-control, and legal requirements.
13
Children and supervised users
guntingAI is intended for adult researchers, professionals, educators, and properly supervised learners. A minor may use the service only with authorization and supervision from a parent, guardian, institution, or responsible adult where permitted by law. Do not submit a minor’s personal or genomic data without every required lawful basis and safeguard.
14
Changes to this policy
We may update this policy to reflect legal, technical, operational, security, or service changes. The revised version becomes effective when posted unless a later date is stated. Continued use after the effective date means the updated policy applies to subsequent use, subject to rights that cannot lawfully be waived.
15
Privacy contact
Submit privacy questions or requests through the official contact channel published by ChordexBio. Include enough information to identify the relevant account or record, but do not send passwords, private keys, or unnecessary sensitive data.
You may also have the right to raise a concern with the competent privacy or data-protection authority in your jurisdiction.