DNA analysis without upload is two jobs, not one
Job one: resolve a public identifier. rs1799945 is in ClinVar for anyone. That query can go over HTTPS. No API key is required.
Job two: attach those annotations to your genotypes. That file is identifying. Keep it on the machine that already holds it.
Products that mix both jobs into one upload form a different threat model. genome.sh refuses the mix. The HTTP API never accepts VCF, BAM, CRAM, or 23andMe files.
- Public: rsID, gene symbol, HGVS, coordinates
- Private: VCF, BAM, CRAM, 23andMe, AncestryDNA, MyHeritage
- Remote: GET https://api.genome.sh/v1/query/{id}
- Local: genome query, genome annotate, /import
Public identifiers can travel; genotypes should not
An rsID is a dbSNP cluster name. Sending rs334 to an API is sending a word that is already on the internet. Sending the two letters you carry at rs334 is sending a fact about a person.
Logs, chat transcripts, and analytics pipelines leak genotypes when people paste files to save a minute. Look the id up. Grep the file yourself.
Missing chip sites stay not called. They are not wild type. A genotyping chip is not whole-genome sequencing. DNA analysis without upload is still limited by what the file actually measured.
Local CLI path
Install the crate genome-sh. The binary is genome. Then install a database tier: lite for ClinVar-oriented work, standard or full when you need gnomAD frequencies.
genome query handles one identifier or a gene catalog. genome annotate streams a VCF. Formats are human, json, and compact. Scripts and agents should use JSON.
After genome db install, identifier queries and VCF annotation hit SQLite on disk. They do not need the network. Confirm the snapshot with genome db status.
cargo install genome-sh genome db install standard genome db status genome query rs1799945 --format json genome annotate local.vcf.gz --filter clinical --format json
In-browser importer path
The local analysis page at /import parses supported files in the tab. The file is not uploaded to genome.sh. That is the no-install path for a first look.
The website query page at /query is a different tool. It looks up public identifiers through the API. Do not paste a raw-data file into the query box.
If the importer does not support a format, convert it locally or use the CLI. Do not fall back to emailing the file to a web service.
What the HTTP API will never accept
Base URL: https://api.genome.sh. GET /v1/query/{id}, GET /v1/gnomad/{id}, GET /v1/gene/{gene}, GET /v1/sources, GET /v1/stats, GET /v1/health. No key.
There is no POST for a VCF. There is no multipart form for 23andMe. A 413 or a 400 on a file body is the design, not a missing feature.
Use the API from CI when the host must not hold genomes. Use the CLI when the host already holds genomes. Cache public identifiers. Never put GT values in a URL.
curl -s https://api.genome.sh/v1/query/rs1799945 | jq . curl -s https://api.genome.sh/v1/gnomad/rs429358 | jq . curl -s https://api.genome.sh/v1/sources | jq .
Agents that stay on disk
A coding agent can run genome on the user's machine, fill the HTML report template, and render a private A4 PDF. That job is local. It is not an integration that uploads genomes.
Copy the template out of the repository before writing personal data. Do not commit filled HTML or PDF. The site ships a prompt that forbids upload and forbids pasting genotypes into the chat.
Give the agent paths, not file contents. genome query rs1800562 --format json and genome annotate INPUT.vcf.gz --format json are the allowed tools. Missing markers stay not called.
AlphaGenome is opt-in and separate
AlphaGenome prediction is a separate CLI command. It requires a key and explicit consent. It is not the default query path and it is not the HTTP API.
AlphaMissense is a static score table in the local database. Do not confuse the score table with the opt-in predictor. Ordinary ClinVar and gnomAD lookup needs neither a key nor a remote model.
If you do not want any remote model involved, do not run genome predict. genome query and genome annotate stay on local SQLite after install.
Limits of chips, panels, and public annotations
A 23andMe export covers a biased slice of dbSNP. A panel VCF covers a panel. Most ClinVar pathogenic records will not be in those files. DNA analysis without upload cannot invent coverage.
ClinVar is submitted interpretation. gnomAD is frequency among sequenced haplotypes. Neither database knows your genotype until you match the id to a local call.
genome.sh is informational software, not a medical device. It is not a replacement for clinical sequencing or genetic counseling. Clinical testing belongs in a clinical lab.
- Chip miss: not called, not wild type
- No ClinVar row: not evidence of benignity
- No gnomAD row: not evidence of pathogenicity
- No upload: still not a clinical assay
Questions
How do I do DNA analysis without upload?
Install genome-sh, run genome db install, then genome query or genome annotate on a local file. Or parse the file in the /import tab. Public rsIDs can use the HTTP API; files cannot.
Can I analyze DNA without uploading a 23andMe file?
Yes. Keep the export on disk. Look up rsIDs with genome query or the identifier API. Match genotypes locally. The API rejects the file.
Is the REST API a back door for files?
No. It rejects genome uploads by design. GET /v1/query/{id} accepts rsIDs, genes, HGVS, and coordinates only.
What about AlphaGenome?
Effect prediction is a separate, opt-in CLI command. It requires a key and explicit consent. It is not the default query path and not an HTTP upload.
Can I use this in clinic?
genome.sh is informational software, not a medical device. Clinical testing belongs in a clinical lab.
Can I annotate a VCF without the cloud?
Yes. genome annotate local.vcf.gz --format json after genome db install standard. Add --filter clinical for ClinVar-touched rows.
Does the website store my genome?
No. /import parses in the browser. /query sends identifiers only. The CLI reads disk. Nothing in that trio is a genome-upload product.
What if a chip site is missing?
Write not called. Do not infer the reference allele. Consumer arrays miss most ClinVar pathogenic variants.