By SterlingMedicalCenter.org Editorial Team
SterlingMedicalCenter.org is an independent editorial publication. It is not a medical practice, clinic, or healthcare provider, and nothing here is medical or legal advice. Sources were checked on October 2, 2026.
Before you send a sample or share health details with a consumer health-test company, you can ask five things about the data: what categories it collects, who receives it, how long it is kept, how you can have it deleted, and when the policy was last updated. If a company's privacy terms do not answer those five questions in plain words, that gap is itself useful information, and you can ask the company in writing before you buy.
The Short Answer: Five Questions Before You Submit a Sample
- What data do you collect? This includes your sample, the results derived from it, and everything around it (name, address, payment details, device and browsing data).
- Who receives it? Look for named categories of recipients, such as the lab, payment processors, and any marketing or research partners.
- How long do you keep it? Ask separately about the physical sample, the results, and account data.
- How do I delete it? Look for a specific route (a form, an email address, an account setting) and what is and is not removed.
- When was this policy last updated, and how will I be told about changes?
Why These Five Questions Matter
A health-test result can describe something deeply personal, and you may not be able to take it back once it is shared. The Federal Trade Commission's business guidance on genetic testing kits notes that HIPAA protects health information collected by certain types of entities. That wording is a reminder not to assume a consumer test seller is covered by the same rules as your doctor's office. Ask the company how it handles your data instead of assuming.
The same FTC guidance says companies should explain deletion of physical samples and of derived genetic information separately, and should notify customers about material changes to how data is used. Those two points map directly onto the retention, deletion, and policy-date questions above.
The Privacy-Term Comparison Sheet
Use this sheet to read any provider's privacy policy, or to compare two providers side by side. For each of the five terms, find the answer in the policy, copy the exact wording, and note whether the wording is specific or vague. The layout below is our own reading aid. It is not an official standard and is not part of the NIST Privacy Framework.
Term 1: Data Categories
- What to find: A list of what is collected, split into sample, results, account and payment details, and device or website data.
- Specific wording looks like: A named list of categories.
- Vague wording looks like: “information we may collect from time to time,” with no categories named.
Term 2: Recipients
- What to find: Who gets the data: the testing lab, service providers, partners, or other third parties, and for what purpose.
- Specific wording looks like: Named types of recipients, each tied to a purpose.
- Vague wording looks like: “trusted partners” or “affiliates,” with no purpose stated.
Term 3: Retention
- What to find: How long the physical sample, the results, and the account data are kept, and what happens to a sample after testing.
- Specific wording looks like: A stated period or a stated trigger (for example, “until you ask us to delete it”).
- Vague wording looks like: “as long as necessary,” with no further detail, or silence about the physical sample.
Term 4: Deletion Route
- What to find: The specific way to request deletion, what is deleted, what may be kept, and whether the lab is covered.
- Specific wording looks like: A named form, address, or account setting, plus a list of what remains afterward and why.
- Vague wording looks like: “contact us” with no method, or a promise of deletion that says nothing about the lab or backups.
Term 5: Policy Date
- What to find: A “last updated” date and a statement about how changes are communicated.
- Specific wording looks like: A dated policy and a commitment to notify you of material changes.
- Vague wording looks like: No date, or “we may change this policy at any time” with no notice.
Save a dated copy of the policy (a PDF or a screenshot) before you submit anything. If the terms change later, you will have a record of what you agreed to.
Worked Example 1: Reading Two Invented Policy Excerpts
The two excerpts below are invented for illustration. They do not describe any real company.
- Provider A (invented): “We may share information with partners to improve our services. We keep data as long as necessary. Contact us with questions. Last updated: not shown.”
- Provider B (invented): “We share your sample with our contracted laboratory to run your test. We share results only with you unless you choose to send them to a clinician. We keep your results until you delete your account, and the lab discards the sample after testing. Delete your account under Settings, then Privacy, or write to the contact address listed. Last updated: a stated date.”
Filling in the sheet for Provider A: categories are not named, recipients are “partners” with no purpose, retention is “as long as necessary,” the deletion route is “contact us,” and there is no policy date. That is five vague answers, which is a reason to ask questions in writing before buying. For Provider B: the recipient (a contracted laboratory) and its purpose are named, retention has a trigger, there is a deletion route, and the policy is dated. Provider B's wording is more specific. It is still wording on a page, so you would want to confirm that the company actually follows it, but specific wording gives you something to hold the company to.
Worked Example 2: What Happens When Promises and Practice Diverge
The FTC has described a real case that shows why deletion and recipient terms are worth reading closely. In June 2023, the FTC announced a complaint against 1Health.io (also known as Vitagene), a genetic testing company. These were allegations in a complaint. The points below are the FTC's allegations as stated in its announcement.
- Deletion route: The FTC alleged that the company told consumers they could delete their personal information at any time and that it would be removed from all of its servers, but did not live up to that promise.
- Retention of samples: The FTC alleged that, beginning in 2016, the company did not have a policy to make sure the lab that analyzed DNA samples had a policy to destroy them.
- Recipients and policy date: The FTC alleged that in 2020 the company retroactively expanded the types of third parties it could share data with, without notifying or getting consent from consumers whose data had already been collected.
In September 2024, the FTC announced it was sending refunds totaling over $49,500 to 2,432 consumers in connection with the order. The FTC's announcement said that because the company failed to maintain a data inventory, it could not reliably process requests to remove people's personal information. You can read both announcements in the sources below.
What this means for you as a reader: the three terms where the FTC alleged problems (deletion, sample retention, and a changing recipient list) are the same terms on the sheet above. A privacy policy is a promise worth reading, and the policy date and a saved copy help you check later whether the terms changed.
Where Frameworks Fit In
The National Institute of Standards and Technology (NIST) describes its Privacy Framework as a voluntary tool, developed in collaboration with stakeholders, to help organizations identify and manage privacy risk. It is written for organizations, not consumers, and it is not a checklist for buying a test. We mention it because its starting idea, that an organization should know what data it holds and where that data goes, is the same idea behind the questions in this guide. NIST has not reviewed or endorsed this article.
What You Can Do Next
- Read the privacy policy before you add a test to your cart, and fill in the five-term sheet.
- Write to the company's privacy contact with any answer that was vague. Keep its reply.
- Save a dated copy of the policy and your order confirmation.
- Share only what the test needs. If an optional form field asks for extra health details, you can leave it blank.
- If you later want your data deleted, use the route in the policy, ask in writing, and ask what was and was not deleted, including the physical sample if one was sent.
Your rights to access or delete data can vary depending on where you live and on the type of company, so ask the company which rights apply to you. If you believe a company misled you about its data practices, the FTC's online privacy page directs people to report fraud at reportfraud.ftc.gov.
Who Should Seek Professional Advice
Questions about what a test result means, or whether to take a test at all, belong with a licensed clinician who knows your history. This article covers data handling only. It does not say whether any test is accurate, useful, or right for you. If you have a legal question about your privacy rights or a dispute with a company, a qualified attorney can advise you.
What This Guide Does Not Cover
This guide is about tests and services that collect a sample or personal health information. Product reviews on this site, such as our AgeMate review, examine a supplement rather than a test, so the sample-handling questions here do not apply to it. The habit of reading a seller's privacy terms before you check out still does. You can also read how this publication works on our Editorial Standards page and our Medical Disclaimer page.
Sources
- FTC, “Selling genetic testing kits? Read on.” (published March 21, 2019; last modified June 9, 2022). Supports the points about HIPAA coverage applying to certain types of entities, separate explanation of sample and data deletion, and notice of material changes.
- FTC press release, June 2023, on 1Health.io. Supports the allegations about deletion promises, lab sample destruction, and expanded third-party sharing.
- FTC press release, September 9, 2024, on 1Health.io refunds. Supports the refund figures and the data inventory statement.
- NIST Privacy Framework. Supports the description of the framework as a voluntary tool for organizations to identify and manage privacy risk.
- FTC Consumer Advice, Online Privacy and Security. Supports the reference to reporting fraud at reportfraud.ftc.gov.