Privacy
How we limit, protect, and govern the little data we handle.
Shared Blood is designed to collect as little data as possible. We define a clear purpose before collecting anything, protect what we hold, restrict who can use it, review before we publish, and delete it when it is no longer needed.
Every collection has an approved purpose. If there is no valid purpose, we do not collect. We prefer anonymous and aggregate records and never require national identity data such as CNIC or B-Form.
The genetic calculators are educational and transient. Your inputs and results are not saved, not used for research, and never become a medical or genetic record. We do not store parent status, family relationship, or calculated risk.
Survey research is anonymous and aggregate. We prefer age ranges over exact dates of birth, avoid precise addresses, and never use full IP addresses as research variables or secretly fingerprint participants.
Attendance is kept separate from assessments and sensitive data. Training assessments are anonymous and aggregate; where a before/after comparison is needed we use pseudonymous codes that carry no personal information.
Audio perspectives are published only with specific consent. Taking part in an interview does not by itself authorise recording, voice publication, name publication, transcript publication, or translation (each is a separate choice.
Analytics are aggregate and privacy-minimized (for example, that a page or calculator was opened. We never infer disease status, carrier status, genetic risk, pregnancy status, or political or advocacy beliefs from your use of the site.
We keep data only while its purpose is active. When the purpose ends, retention is reviewed and data is deleted or anonymized. "May be useful later" is not a reason to keep data, and hiding a row is not deletion.