Privacy Policy
Effective: 26 May 2026 · Last updated: 26 May 2026
Biosmith is a free, open-source molecular biology tool. We collect as little data as possible — which, in practice, means almost none.
What we collect
Short answer: essentially nothing.
- No user accounts. No registration. No login.
- No analytics or tracking (no Google Analytics, no pixels, no fingerprinting).
- No cookies beyond what Vercel's edge network sets for basic operation.
- No server-side storage of your sequences, plasmids, or any scientific data.
Data that stays on your device
Biosmith stores data locally in your browser (localStorage/IndexedDB) or on your local filesystem (desktop app). This includes:
- Plasmid sequences and annotations you load or create
- App settings and preferences
- AI assistant configuration (provider, model name, API key)
- Construction provenance history
None of this is sent to Biosmith servers. It lives on your device and you can clear it at any time through your browser settings.
AI assistant (bring your own key)
Biosmith's AI assistant uses a "bring your own key" model. You configure your own API key for your chosen AI provider (OpenAI, Anthropic, OpenRouter, Ollama, or a custom endpoint).
- Your API key is stored in your browser's localStorage only — it is never sent to Biosmith servers.
- When you use the AI assistant with a cloud provider, your messages (which may include plasmid sequence data) are sent directly to that provider. This is governed by their privacy policy, not ours.
- When you use Ollama or another local model, everything stays on your machine.
- Biosmith provides a thin proxy route (
/api/chat) to handle CORS for providers that block browser requests. This proxy forwards your request and does not log, store, or inspect any data.
Hosting
The web version is hosted on Vercel. Vercel may collect standard web server logs (IP address, browser type, request timestamps) as part of their infrastructure. We do not access or analyse these logs. See Vercel's privacy policy for details.
Third-party services
- Vercel — hosting and edge network
- Your chosen AI provider (only if you use the AI assistant) — governed by their terms
- NCBI BLAST (only if you use the BLAST search tool) — your query sequence is sent to NCBI's public API
- Google Fonts — the Inter typeface is loaded from Google's CDN on the landing pages
Children's privacy
Biosmith does not knowingly collect any personal data from anyone, including children. Since no accounts or personal information are required, there is no age-specific data collection.
GDPR and CCPA
Since Biosmith does not collect, store, or process personal data, GDPR and CCPA rights (access, deletion, portability, opt-out) are satisfied by default. All your data lives on your device and is under your control. If you believe we hold any of your data, contact us and we will address it.
Changes to this policy
If Biosmith adds features that collect data (user accounts, analytics, etc.), we will update this policy before launching those features. The "last updated" date at the top will always reflect the current version.
Contact
Paul Maciocia
p.maciocia@ucl.ac.uk
University College London, UK