Featured

What Happens to Your DNA Data After a Genealogy Test?

You spit in a tube and mail it off. Here's what actually happens to your DNA data afterward — storage, sharing, and the worst case.

5 min read
By Gerrit | famstory
Tutorial
PrivacyDNAGenealogyData OwnershipSecurity
What Happens to Your DNA Data After a Genealogy Test?

You spit in a tube, mail it off, and a few weeks later you get an ethnicity breakdown and a list of relatives you've never met.

That's the part you see.

What you don't see is what happens to your DNA data after that — where it's stored, who gets to use it, and what happens to it if the company behind the test changes hands.

Most people never ask. And for years, the answer felt safe enough to ignore. That changed.

Your Sample Becomes Two Things #

When a lab processes your test, your spit gets turned into data — and that data usually outlives the sample.

There are two separate things a testing company holds:

The physical sample. The actual saliva or cheek swab. Many companies store this by default so they can re-test it later. You can often ask for it to be destroyed, but you usually have to ask.

The digital data. Your genotype file — hundreds of thousands of data points about you — plus everything derived from it: matches, health markers, ethnicity estimates. This is the part that gets copied, analyzed, and, in some cases, shared.

Deleting your account later doesn't automatically undo everything that happened to that data in between.

Where Your DNA Data Actually Goes #

Once your genotype exists, it rarely just sits in a folder waiting for you to log in.

Depending on the company and the consent boxes you ticked at signup, your data may be used for:

Relative matching. Your DNA is compared against everyone else in the database to find shared segments. This is the feature people sign up for — but it also means your genetic information is being cross-referenced with strangers, some of whom are blood relatives who never tested themselves.

Research and pharmaceutical partnerships. Several large testing companies have partnered with drug makers, sharing genetic data — usually de-identified and opt-in — for research. "De-identified" is not the same as anonymous, though. Genetic data is inherently identifying; it's literally the code that makes you you.

Internal analysis. Improving matching algorithms, building bigger reference panels, training models. Standard for any data-driven business.

None of this is necessarily hidden. Most of it is in the terms of service. But the terms are long, and almost nobody reads them before clicking "I agree." This is the same gap we wrote about in Who Owns Your Family Tree Data? — owning your data and controlling it are not the same thing.

The Part That Changed Everyone's Mind #

For a long time, the reassurance was: "your data is safe with us."

The problem is that "us" is a company, and companies don't last forever.

In 2023, 23andMe suffered a breach that exposed data connected to roughly 6.9 million users. Then in March 2025 the company filed for bankruptcy — and the genetic data of more than 15 million people became an asset to be sold. It ended up transferred to a nonprofit founded by the company's former CEO.

The point isn't to single out one company. The point is structural: when your DNA lives inside a business, its fate is tied to that business's balance sheet. Bankruptcy, acquisition, a policy change under new owners — any of these can move your most personal data somewhere you never agreed to.

For genealogy platforms in general, this is why where and how your data is stored matters as much as whether it's "secure."

Why DNA Is Different From a Password #

Here's what makes genetic data a category of its own.

If your password leaks, you change it. If your credit card is stolen, the bank issues a new number.

You cannot reissue your genome. A compromised DNA profile is compromised permanently. It also implicates people who never consented — your children, your siblings, your parents share large portions of that same code.

That's not a reason to panic. It's a reason to be deliberate about what you hand over and to whom, before you do it.

Keeping Family History Without Handing Over Your DNA #

Here's the part that often gets lost: you don't need a DNA test to build and preserve a real family history.

Records, census data, church books, documents, photos, and the stories of living relatives are the actual foundation of genealogy. DNA is an add-on, not the core.

That research deserves a home that treats it the way you'd expect — private by default, not part of anyone's matching network or research dataset. That's the idea behind end-to-end encrypted family tree storage: your family's history stays yours, encrypted, with no public profiles and no genome to leak. famstory is built around exactly that.

You can't undo a DNA test you've already taken. But you can decide, from here on, how much of your family's story lives somewhere only you control.

FAQ #

Can I delete my DNA data after a test? #

Most companies let you delete your account and data and request destruction of your physical sample. But data already shared with research partners or de-identified for analysis may not be fully recoverable. Do it as early as possible.

Is de-identified DNA data really anonymous? #

Not entirely. Genetic data is inherently identifying, and studies have shown de-identified genomes can sometimes be re-linked to individuals. Treat "de-identified" as reduced risk, not zero risk.

What happens to my DNA data if the company goes bankrupt? #

Your data can be treated as a company asset and transferred to whoever buys it, potentially under different privacy terms. The 23andMe bankruptcy in 2025 made this concrete for over 15 million users.

Related Articles