BioAtlas

Privacy Policy

This policy explains how BioAtlas handles information through bioatlas.pro, Pasta Bite, VFSS, Behavior, GenomeSeq, and support requests.

Last updated: July 30, 2026

Privacy at a glance

Desktop tools and local research files

Pasta Bite, VFSS, and Behavior work with files selected by the user on their own computer. These files may include video, audio, annotated sessions, cohort files, spreadsheets, screenshots, behavioral or physiological records, and exported analysis results.

The applications use these files to display media and signals, draw waveforms, mark events, calculate summaries, perform cohort-level analysis, and export user-selected results.

BioAtlas desktop applications do not upload the user's analysis files, video files, audio files, annotated sessions, cohort files, or exported results to BioAtlas servers.

The applications do not require a BioAtlas account to perform local analysis.

Files created by the applications are saved only where the user chooses to save them, such as local folders, external drives, or network locations selected by the user.

Information handled by GenomeSeq

GenomeSeq processes information needed to provide requested online RNA-seq workflows, including:

GenomeSeq uses this information only to authenticate users, run requested analyses, display and export results, support collaboration, maintain project history, troubleshoot failures, and protect the service.

Cloud file storage

GenomeSeq stores uploaded sequencing inputs, project files, processing outputs, logs, and results in private cloud object storage. Database records store associated filenames, sizes, permissions, and storage identifiers.

BioAtlas currently uses Amazon S3 for this storage. Stored objects use server-side encryption, transfers use HTTPS, and downloads are provided through time-limited signed links after an authorization check.

Browser storage and technical data

BioAtlas does not currently use advertising cookies or third-party advertising trackers on bioatlas.pro. Web hosting and network providers may process ordinary request information such as IP address, browser type, requested page, date, time, and security events to deliver and protect the services.

Service providers and disclosures

BioAtlas uses service providers to operate its products. These may include cloud application and database hosting, email delivery, support email, domain and network services, and software distribution services. Those providers process information under their own terms and privacy practices and only receive information relevant to the service they provide.

BioAtlas desktop applications may be distributed through Microsoft Store, which processes download, account, device, security, purchase, review, and diagnostic information under Microsoft's privacy practices. BioAtlas online services use Render for application and database hosting and Amazon Web Services for object storage. These providers may process hosting, database, storage, network, and security information.

BioAtlas may disclose information when reasonably necessary to comply with law or valid legal process; protect users, BioAtlas, or others; investigate fraud, abuse, or security incidents; enforce applicable terms; or complete a business reorganization or transfer with appropriate notice and safeguards.

BioAtlas does not sell personal information or research files and does not disclose them for cross-context behavioral or targeted advertising.

Support requests

If a user contacts BioAtlas for support, BioAtlas receives the information the user chooses to provide, such as name, email address, account or workspace details, a description of the issue, and voluntarily supplied screenshots or files.

Users should remove sensitive personal, patient, or research information before sending support materials whenever possible. BioAtlas uses support information to respond to the request, troubleshoot problems, protect the services, and improve product reliability.

Retention, correction, and deletion

BioAtlas retains information while it is needed to provide an active account, project, or workspace and for legitimate operational, security, support, backup, dispute-resolution, and legal purposes. Retention varies with the type of information and is not guaranteed to follow a single fixed period.

Deleting a GenomeSeq project removes its active project records and associated cloud-storage files. Limited logs or backup copies may remain temporarily for security, recovery, or legal purposes.

Depending on location and applicable law, a person may have rights to request access to, correction of, deletion of, restriction of, or a portable copy of personal information, or to object to certain processing. BioAtlas may need to verify the request and may retain information when required or permitted by law.

Security

BioAtlas uses administrative and technical safeguards designed for the information handled by the services, including password hashing, authenticated sessions, role- and project-based access controls, private encrypted object storage, time-limited signed file links, request rate limits, and audit records.

No internet service, real-time call, or storage method can be guaranteed to be completely secure. Users should protect their passwords and devices, limit uploads to information they are authorized to process, and promptly report suspected unauthorized access.

Sensitive research and genetic information

Research, behavioral, physiological, sequencing, and genetic information can be sensitive even when direct identifiers have been removed. Users and organizations are responsible for obtaining required consent, ethics or institutional review, data-use authorization, and other legal authority before processing or uploading such information.

Users should de-identify research data whenever practical and should not upload protected health information or regulated clinical records unless BioAtlas and the user's organization have first established any required written agreements, security configuration, and compliance responsibilities. BioAtlas services are not presented as HIPAA-compliant clinical repositories by default.

International processing

BioAtlas and its service providers may process information in the United States and other countries where they operate. Those locations may have privacy laws different from the user's location. Organizations using BioAtlas services are responsible for determining whether their use and any international transfer of research or personal information is permitted.

Children's privacy

BioAtlas products are intended for researchers, laboratories, workplaces, and other organizations and are not directed to children under 13. BioAtlas does not knowingly collect personal information directly from a child under 13 through these services. A parent or guardian who believes a child has provided personal information should contact BioAtlas.

Changes to this policy

BioAtlas may update this policy when products, providers, or legal requirements change. The revised policy will be posted on this page with a new “Last updated” date. Material changes may also be communicated through the service or by email when appropriate.

Contact

For privacy questions or requests, email info@bioatlas.pro or use the BioAtlas support page. Please describe the request and the relevant BioAtlas product. BioAtlas may request information needed to verify identity and authority before acting on a request.

Go to BioAtlas support