Does 23andMe train on your data?
23andMe holds genotypes. Its privacy statement runs to 23,000 characters and does not use the words "train", "AI" or "machine learning" once.
Genetic data is the most durable personal information a company can hold — it does not change, and it implicates relatives who never consented to anything. The statement is careful in other ways: research participation is an opt-in programme with its own consent, de-identified information is defined, and sample storage is a separate choice. The nearest it comes to the AI question is a bullet in its list of collection sources, labelled "23andMe:", saying it may "infer new information from other data we collect, including using automated means to generate information about your likely preferences or other characteristics" — predicting "certain health predispositions" from Genetic Information is its own example. That is a statement about deriving results for you, not about whether customer data builds models. If anything it sharpens the question: predicting predispositions from genotypes means models sit somewhere in the pipeline, and whether customers' genetic and self-reported information trained them is exactly what the document never takes up. No form of "train", no "machine learning", no "artificial intelligence", no "model" appears anywhere, and consent given to research is not consent to that.
- 23andMe privacy policy, captured 2026-08-30 (https://www.23andme.com/legal/privacy/full-version/)
- train, training, trains, fine-tune, machine learning, artificial intelligence, AI model, large language model
- 0
- 1 Sept 2026
What each plan can refuse
The same questions, asked of every plan we could identify. Every cell comes from a quoted clause or a documented search - see the evidence above.
- Not established
- Not stated
- —
- —
- Not established
How to opt out of 23andMe AI training
Plan by plan, from what 23andMe's own policy says about refusing. Where it publishes the steps, they're listed here with the limits they carry. Where there's nothing to switch off, or nothing graded, this says so instead of inventing a menu path.
All accounts
Not graded, so no route is pointed at. Genetic data is the most durable personal information a company can hold — it does not change, and it implicates relatives who never consented to anything. The statement is careful in other ways: research participation is an opt-in programme with its own consent, de-identified information is defined, and sample storage is a separate choice. The nearest it comes to the AI question is a bullet in its list of collection sources, labelled "23andMe:", saying it may "infer new information from other data we collect, including using automated means to generate information about your likely preferences or other characteristics" — predicting "certain health predispositions" from Genetic Information is its own example. That is a statement about deriving results for you, not about whether customer data builds models. If anything it sharpens the question: predicting predispositions from genotypes means models sit somewhere in the pipeline, and whether customers' genetic and self-reported information trained them is exactly what the document never takes up. No form of "train", no "machine learning", no "artificial intelligence", no "model" appears anywhere, and consent given to research is not consent to that.
What this policy has done since we started watching
The record starts here. 23andMe's policy was first captured on 30 Aug 2026, and there's no earlier copy to compare it against, so this verdict has no history behind it yet. From now on every re-read is diffed against that copy, and anything that moves appears here.
Everything we read
Vendor response
We haven't yet written to 23andMe about this verdict, and they haven't disputed, clarified or announced a change to any clause quoted above. When either happens it's published here, word for word.
Report a wrong clause