Account and contact data
Names, email addresses, affiliations, contact messages, submissions, and reviewer communications are stored in the backend database. Passwords are stored only as password hashes. Admin-only APIs enforce server-side role checks.
Genomic submissions
User-submitted organism metadata, FASTA, GFF3, and MAYA files remain private during review. Approval publishes the selected organism metadata and approved reference assets. Submitters should not upload human-identifiable information, credentials, protected clinical records, or data they are not authorized to share.
BLAST queries
BLAST queries are validated, processed with NCBI BLAST+ against approved BMGA references, and are not intentionally persisted by the application. Query sequence content is excluded from audit logs. Operational infrastructure may still record request metadata such as timestamp, account, IP address, result status, and request ID.
Evidence limitations
MAYA, genome browser, and BLAST outputs are computational and normally genotypic. They do not establish phenotype, pathogenicity, transmission, diagnosis, or treatment. Phenotypic evidence is labelled separately only when reported.
Production governance
Before public production use, the database owner must approve retention periods, incident response, data-subject request handling, jurisdiction-specific notices, data-processing agreements, and the dataset reuse license.