Last updated: June 24, 2026
This Privacy Policy describes how sigscape ("the Service", "We", "Us", or "Our") handles information when You use the website at sigscape.org and the in-browser sigscape studio. sigscape is an academic, open-source software hub and analysis tool developed and maintained by the Park Lab and the Gülhan Lab at the Department of Biomedical Informatics, Harvard Medical School, and operated by the President and Fellows of Harvard College ("the University").
sigscape is provided as a free, publicly accessible resource for the scientific community. It is not a commercial product. It does not require registration, the creation of a user account, or signing in. We have designed it to collect as little information about You as possible.
When You visit sigscape, Our infrastructure providers — Cloudflare, Inc. (DNS, CDN, and security) and Vercel, Inc. (hosting) — automatically record standard server-log and network information in the course of serving and securing the site, including:
This data is recorded to ensure the reliable operation of the Service, to monitor for abuse, and to keep the site secure. sigscape itself does not include any analytics service (such as Google Analytics), advertising network, or third-party tracking script; the only collection is the standard logging performed by Vercel and Cloudflare as part of hosting and securing the site.
sigscape does not require You to create an account, provide an email address, or submit any personal information to use the Service. We do not collect names, email addresses, or other directly identifying information through normal use of the site. The only Personal Data that may be processed is the IP address contained in the server logs described above.
The sigscape studio runs entirely in Your browser. Any files You load (for example VCF, MAF, BED, SBS-96 matrices, or exposure tables) are read and processed locally on Your Device using the browser's JavaScript File API. No file You load — genomic or otherwise — is transmitted to, received by, or stored on Our servers at any point.
The studio also ships with a small set of example datasets derived from published or publicly released data. These are bundled static files served like any other page asset; loading them sends Us no information about You beyond the standard request log.
sigscape does not set any cookies of its own, and it does not use advertising, remarketing, or cross-site tracking cookies. It uses a minimal set of browser-storage items, all strictly functional and all stored only on Your Device — none are transmitted to Our servers. No consent banner is shown because none of these items require consent.
Studio datasets
Browser session storage · Administered by: Your browser
When You load files into the studio, the parsed result is kept in Your browser's session storage so Your work survives navigation and reloads within the same tab. It is cleared automatically when You close the tab, and is never sent to Us.
Studio state
Browser session storage + URL fragment · Administered by: Your browser
Your current studio layout (open tabs, selected records, and view settings) is kept in session storage and encoded into the page's URL fragment so a link reproduces Your view. It contains only studio state, not personal information.
Theme preference
localStorage (theme) · Administered by: Your browser
Your light/dark mode preference is stored in Your browser's local storage so the site remembers it on Your next visit. This value is not transmitted to Our servers.
Cloudflare Bot Management
Cookie (__cf_bm) · Administered by: Cloudflare, Inc.
Cloudflare may place a __cf_bm cookie on Your Device as part of its bot management, to distinguish legitimate visitors from automated traffic. It expires after 30 minutes of inactivity, is encrypted, is generated independently per site, does not correspond to any user ID in Our application, and is not used to track users across sites.
Cloudflare Challenge Clearance
Cookie (cf_clearance) · Administered by: Cloudflare, Inc.
If Cloudflare presents a security challenge (for example a CAPTCHA or JavaScript verification), a cf_clearance cookie records that the challenge was passed, preventing repeated challenges on subsequent requests.
These Cloudflare cookies are administered by Cloudflare as part of delivering and securing the site; they are strictly necessary and are not used by Us for analytics, advertising, or tracking.
Because every storage item described here is strictly necessary for the functionality it supports, it falls within the “strictly necessary” exemption under Article 5(3) of the ePrivacy Directive (and equivalent legislation) and does not require consent.
The limited information that reaches Us (server logs) is used exclusively to:
We do not use any collected information for advertising, marketing, profiling, automated decision-making, or any commercial purpose. We do not sell, rent, or trade Your information to any third party.
Several features of sigscape operate entirely within Your browser and transmit no data to Our servers:
sigscape's domain is managed through Cloudflare, Inc., which provides DNS resolution, TLS/SSL termination, content delivery, DDoS protection, and bot management. When You access sigscape, Your request is routed through Cloudflare's global network before reaching Our hosting provider. Cloudflare collects end-user log data — including IP addresses, HTTP request headers, and traffic metadata — to operate and secure its network, and may set the cookies described in the “Cookies and Browser Storage” section above. Cloudflare processes this data as a data processor on Our behalf. Its privacy policy is available at cloudflare.com/privacypolicy.
sigscape is hosted on Vercel, Inc. After passing through Cloudflare, requests are served by Vercel's infrastructure, which records standard server logs (including IP address, request headers, and traffic metadata) and serves the site's static assets via its CDN. Vercel's privacy policy is available at vercel.com/legal/privacy-policy.
sigscape uses the Outfit, Fira Code, and Space Grotesk typefaces. These fonts are downloaded at build time and self-hosted as part of the site's assets (served via Vercel's CDN); no requests are made from Your browser to any third-party font service when You visit the Service.
The Service links to external resources such as GitHub repositories, package registries (PyPI, Bioconda, CRAN), published research papers, and laboratory websites. We have no control over and assume no responsibility for the privacy practices of these external sites.
Server logs are retained by Vercel and Cloudflare subject to their respective data-retention policies. We do not independently store, archive, or process server logs beyond what these providers retain in the ordinary course of providing their services.
Browser-storage items remain on Your Device under Your control: the studio session-storage items are cleared when You close the tab, and the theme preference persists in local storage until You clear Your browser data. None of these are stored on Our servers.
sigscape is operated from the United States. If You access the Service from outside the United States, the Usage Data in server logs may be processed by Cloudflare at edge locations worldwide and by Vercel in the United States, where data-protection laws may differ from those of Your jurisdiction. Where required by applicable law (including the GDPR), We rely on Vercel's and Cloudflare's data-processing agreements and standard contractual clauses to safeguard international transfers.
All connections to sigscape are encrypted via HTTPS/TLS, terminated at Cloudflare's edge and re-encrypted to Vercel's origin servers. Because the studio processes Your files locally and nothing is uploaded, Your scientific data never traverses Our infrastructure. We use commercially reasonable measures to protect the Service, but no method of electronic transmission or storage is completely secure, and We cannot guarantee absolute security.
sigscape is a scientific research tool and is not directed at children under 16 years of age. We do not knowingly collect Personal Data from children under 16. If You believe a child has provided Us with Personal Data, please contact Us so that We can take appropriate action.
If You are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, You have rights under the GDPR and equivalent local legislation.
To the extent We process any Personal Data (primarily IP addresses in server logs via Vercel and Cloudflare), Our legal basis is:
For browser storage: every item used by sigscape falls within the “strictly necessary” exemption under Article 5(3) of the ePrivacy Directive, as each is required for the Service to function (studio state, display preference). No consent is therefore required.
You have the right to:
To exercise any of these rights, contact Us at the address below. We will respond within one month, extendable by two further months for complex requests. If You believe Our processing of Your data violates the GDPR, You have the right to lodge a complaint with a supervisory authority in the EU/EEA Member State of Your habitual residence, place of work, or place of the alleged infringement.
If You are a California resident, the CCPA (as amended by the CPRA) provides You with specific rights regarding Personal Information.
In the preceding twelve (12) months, the only category of Personal Information that may have been collected is:
We do not collect sensitive Personal Information as defined under the CPRA.
We do not sell Your Personal Information. We do not "share" Your Personal Information for cross-context behavioural advertising as defined under the CPRA. We have not sold or shared Personal Information in the preceding twelve (12) months.
To exercise these rights, contact Us at the address below. We will respond within 45 days, extendable by an additional 45 days where reasonably necessary.
In compliance with CalOPPA:
sigscape does not operate any analytics or tracking service and does not track users across third-party websites. We honour Do Not Track (DNT) browser signals in the sense that We have no tracking infrastructure to disable. Our infrastructure providers (Vercel, Cloudflare) may process standard server/network logs regardless of DNT settings as part of providing their services; consult their respective privacy policies for details.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage You to review this page periodically. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
If You have questions about this Privacy Policy or wish to exercise any of Your data-protection rights, please contact:
Prof. Peter J. Park
Department of Biomedical Informatics
Harvard Medical School
10 Shattuck Street, Boston, MA 02115
Email: peter_park@hms.harvard.edu
© 2026 by the President and Fellows of Harvard College. All rights reserved.