uanome.

On-device vs the cloud: where your health data is safest

Updated June 2026

Health data privacy

Health data privacy is not like other privacy. You can reset a leaked password and replace a stolen card number, but you can't change your genome, your medical history, or the years of body metrics that describe you. So the question of where that data lives — on your own device, or on a company's cloud servers — is one of the most consequential choices you'll make about your health. This is the broader principle behind every "upload your file here" prompt: once it's uploaded, it's uploaded forever.

Why health and genetic data is uniquely sensitive

Most personal data is replaceable. Health and genetic data is not.

Your DNA is permanent. The variants you carry today are the same ones you'll carry in fifty years, so a genome that leaks now is exposed for the rest of your life — and beyond. Genetic data is also shared by relatives: your file reveals probabilistic information about your siblings, parents, and children, none of whom agreed to anything.

The same permanence applies to the rest of your health record. A timeline of lab results, resting heart rate, sleep, weight, and conditions paints an unusually intimate portrait. It can hint at things you'd never volunteer — pregnancy, mental health, substance use, a diagnosis you haven't told anyone about. That's why regulators treat it as a special category, and why you should too.

How cloud processing actually works

When an app or website processes your data "in the cloud," the sequence is simple to describe and easy to underestimate. Your file — a raw DNA export, a lab PDF, a stream of health metrics — is transmitted over the internet to the company's servers. There it is stored, processed, and usually retained so the service can show it back to you later or run new analyses against it. The insights you see in the app are the results of computation that happened somewhere you can't see, on a copy of your data that now exists somewhere you don't control.

That model has real strengths, which is why it's everywhere. Cloud servers have effectively unlimited computing power, so they can run heavy analyses a phone couldn't. Your data syncs automatically across every device you sign in on. Backups are handled for you, so a lost phone doesn't mean lost history. And sharing is trivial. For a lot of software, these are exactly the right trade-offs.

The catch is structural: once your data is on someone else's server, your privacy depends on that company's security, its policies, and its future. You've swapped direct control for a promise to behave well. For replaceable data that's usually fine. For a genome, it's a heavier commitment than it looks.

How on-device processing actually works

On-device — or "local" — processing inverts the flow. Instead of your file traveling to a server, the analysis travels to your file. Your phone or computer reads the data directly, interprets it inside the app, and shows you the results, all without the raw file ever crossing the network to a company's database.

Concretely: when you point an on-device tool at your DNA export or connect your health metrics, the parsing runs in the app itself. The file is read into the device's memory, turned into plain-language insights, and kept on hardware you physically hold. There's no server-side copy to breach, sell, or subpoena — because there's no server-side copy at all.

On-device has its own honest trade-offs. You're limited to your own device's computing power, though for the parsing and lookups a personal health app performs, that's rarely a real constraint. Syncing across multiple devices is harder when data doesn't live in a central place. And backup becomes your responsibility rather than the provider's — a well-built local app handles this with encrypted, user-controlled backups, but it's a design problem the cloud gets "for free." What you gain in return is a dramatically smaller attack surface: your privacy no longer depends on anyone keeping a promise, because the sensitive data simply isn't sitting on a server for anyone to lose.

The real risks of cloud and upload models

Uploading isn't automatically reckless, and reputable companies invest heavily in security. But when you upload, you trade direct control for a promise. Three risks are worth understanding clearly.

Data breaches. Any server that stores data is a target, and large genetic and health databases are especially attractive ones. Encryption and good practice reduce the odds, but no remote system is breach-proof. The more copies of your genome that exist on the internet, the larger your exposure — and you can't recall a copy once it's out.

The company being sold — or going bankrupt. This is the risk people underestimate most. When you upload data, you're trusting not just today's company but every future owner of it. Customer databases are frequently treated as business assets that transfer in an acquisition or bankruptcy. The clearest recent example is 23andMe, which filed for bankruptcy in 2025; its database of millions of customers' genetic information became part of the bankruptcy proceedings and a question of who would acquire it. The privacy policy you agreed to was written by a company that may no longer be the one holding your data. "Uploaded forever" means subject to decisions you'll never get to make. We look at this scenario in detail in what happens to your DNA data when a company is sold.

Law-enforcement and subpoena access. Data on a third-party server can be requested through legal process — subpoenas, warrants, or court orders — regardless of how the company feels about it. Some genetic databases have been searched in criminal investigations, including for relatives of the person who actually uploaded a sample. Data that physically lives on your device, by contrast, isn't something a third party can quietly hand over, because they don't have it.

None of this means cloud services are bad. It means uploading sensitive, permanent data is a decision that deserves the same weight as any other irreversible one.

Why this distinction matters more for health data

The on-device-versus-cloud choice exists for all software, but it carries far more weight for health and genetic data than for, say, your grocery list or your step count in isolation.

The reason is the combination of sensitivity, permanence, and reach. Ordinary data is usually replaceable and time-limited — you can change it, delete it, or simply outlive its relevance. Your genome is none of those things: it's fixed for life, uniquely identifying, and revealing about conditions you may not even know you're at risk for. It also implicates people who never consented, because the same file that describes you describes your relatives probabilistically. A leaked password affects one account; a leaked genome affects a family, permanently. When the data is that consequential, the difference between "on a server, protected by a promise" and "only on my device" becomes the whole decision.

Why on-device is increasingly viable

For years, the practical excuse for uploading was that phones weren't powerful enough to do serious analysis, so the work had to happen on big servers. That's largely no longer true.

Modern phones run on-device machine learning routinely — recognizing faces in photos, transcribing speech, translating text, all without sending your data anywhere. Interpreting a genotype file (reading known variants and matching them against a reference), organizing lab values, and assembling wearable metrics into a timeline are well within what today's hardware handles locally. Population-scale research still needs cloud compute, but the personal analysis a consumer health app performs generally does not. The convenience gap that once justified uploading has narrowed to the point where "we had to upload it" is rarely a technical necessity — it's a design choice.

This is the same upload-risk principle we cover in our guides on downloading your 23andMe raw data and the best tools to interpret 23andMe raw data — the safest tool is the one that never asks you to hand over the file.

How to tell what an app actually does with your data

Marketing language won't tell you where your data lives; the details will. A few reliable ways to check:

What "private by design" should look like in a health app

"Private by design" is more than a tagline. A health app that genuinely respects your data tends to share a few traits:

These traits are also what to look for when you choose a tool to keep all your health records in one place — our guide to what a personal health record app actually does walks through the rest, and our health data privacy checklist turns these traits into a step-by-step audit you can run on any app.

Quanome is built on this principle: your DNA, Apple Health data, labs, and body metrics are unified into one timeline on your device, with raw files parsed locally and never uploaded.

Practical questions to ask before you upload anything

Before you hand any health or genetic file to a service, get clear answers to these:

  1. Does this happen on my device, or is my file uploaded to a server? If it's uploaded, everything below applies.
  2. Where is my data stored, and for how long? Look for a real retention policy, not "indefinitely."
  3. Can I delete it completely — and how do I confirm it's gone? A one-click, verifiable delete is a good sign. If you've already uploaded somewhere, our walkthrough on how to delete your 23andMe data shows what a real deletion looks like.
  4. What happens to my data if the company is acquired or shuts down? The answer is often in the fine print, as 23andMe's customers learned.
  5. Is my data ever sold, shared, or used for research? Read this clause specifically, including any default opt-ins.
  6. How would the company respond to a law-enforcement request? Transparency reports tell you whether they've thought about it.

If a service can't answer these plainly, that's information too.

The bottom line

Cloud services aren't the enemy, and uploading isn't always wrong. But health and genetic data is permanent, revealing, and shared with the people you're related to — so the default should lean toward keeping it close. When a tool can do the same job on your device, that's almost always the safer choice, because the strongest privacy guarantee is the one that doesn't depend on anyone keeping a promise. Your genome is yours for life. Treat where it lives like the lasting decision it is.

Keep your DNA and health data on your device

Quanome parses your DNA, labs, and Apple Health data on your phone — your raw files are never uploaded to a server. Learn more about Quanome →

Try the iOS beta →

Frequently asked questions

Is it safe to upload your DNA to a website for analysis?

It can be, but it is a one-way decision. Once your genome is on someone else's server it is subject to their security, their policies, and whatever happens to the company later. On-device analysis avoids that risk entirely because the file never leaves your phone.

What does on-device DNA analysis mean?

It means your raw data file is read and interpreted locally on your own phone or computer, rather than being sent to a remote server. The analysis happens in the app, so the genetic data stays with you.

Why is genetic data considered more sensitive than other personal data?

You can change a password or cancel a credit card, but you cannot change your genome. Genetic data also reveals information about your blood relatives, who never consented to share it. That permanence is why uploading it deserves extra caution.

What happens to my DNA data if a genetics company is sold or goes bankrupt?

Customer data is often treated as a business asset that can transfer to a new owner. When 23andMe entered bankruptcy in 2025, its database of customer genetic information became part of the proceedings, which is why keeping your own copy and limiting uploads matters.

Is on-device processing always better than the cloud?

Not for everything. Cloud services offer genuine advantages — effortless sync across your devices, automatic backups, heavy computation, and easy sharing. On-device processing trades some of that convenience for a much smaller privacy exposure. For permanent, sensitive data like your genome, that trade usually favors staying local; for ordinary data you'd happily re-create, the calculus is different.

How can I tell whether an app processes my data on-device or in the cloud?

Read the privacy policy and look for specific language like 'processed on your device,' 'stored locally,' or 'never uploaded.' Vague marketing about being 'secure' or 'encrypted' does not tell you where the data lives. If an app can analyze your file without an account or internet connection, that is a strong signal the work happens locally. When in doubt, ask support directly.

Are phones actually powerful enough to analyze DNA and health data locally?

For the kind of parsing and pattern-matching a consumer health app does — reading a raw DNA file, looking up known variants, organizing lab values and wearable metrics into a timeline — yes. Modern phones run on-device machine learning for photos, speech, and text, and interpreting a genotype file is well within reach. Population-scale research still needs cloud compute, but your personal analysis generally does not.

Does on-device mean I lose my data if I lose my phone?

It can, which is the honest downside — backup becomes your responsibility rather than the provider's. A well-designed on-device app addresses this with encrypted, user-controlled backups so you keep continuity without shipping your raw files to a company's servers. Keeping your own copy of source files, like your downloaded DNA data, is also good practice.

The Quanome iOS beta is live

Make sense of your DNA and health data privately — try Quanome free on TestFlight now (Android coming later).

Try the iOS beta →

Free TestFlight beta for iPhone. Not on iOS? Leave your email and we'll keep you posted (and ping you when Android lands).