Oraya
Terms Privacy Disclaimer Home

Privacy Policy

Oraya LLC
Effective Date: March 24, 2026
Table of Contents
  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. Data Storage and Security
  6. Your Rights and Choices
  7. "Do Not Sell or Share My Personal Information"
  8. Cookies and Tracking Technologies
  9. Do Not Track Signals
  10. Children's Privacy
  11. Sensitive Wellness Data
  12. Data Breach Notification
  13. International Data Transfers
  14. Third-Party Links and Services
  15. Changes to This Privacy Policy
  16. Contact Us

1. Introduction

Oraya LLC ("Oraya," "Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, store, and protect your personal information when you visit our website at orayaus.com (the "Website"), use the Oraya application (the "App"), or interact with any of our services, features, or communications (collectively, the "Services").

We understand that you are trusting us with sensitive information about your emotional wellbeing. We take this responsibility seriously. This Privacy Policy is designed to be transparent about our practices so you can make informed decisions about sharing your information with us.

By accessing or using any of the Services, you acknowledge that you have read and understood this Privacy Policy. Your use of the Services is also governed by our Terms of Service. If you do not agree with our practices as described herein, please do not use the Services.

2. Information We Collect

2.1 Information You Provide Directly

We collect information that you voluntarily provide to us, including:

  • Waitlist and Registration Information: When you sign up for our waitlist or register for an account, we collect your email address and any responses you provide to our registration questions (such as wellness preferences or goals). Waitlist data may be collected via third-party form services such as Google Forms, which are also subject to Google's Privacy Policy (policies.google.com/privacy).
  • Clarity Task Management Data: When you use the Clarity app, we collect the task content you create, task dates, completion status, priority settings, and timestamps. This data is stored in our cloud database (hosted by Supabase, a PostgreSQL cloud service) and linked to your authenticated user account.
  • Clarity Authentication Data: When you sign in to Clarity, we collect your name and email address through your chosen authentication method (Google Sign-In, email one-time password, or anonymous guest access). If you sign in with Google, we receive your name, email address, and profile photo from Google. Anonymous guest accounts receive a system-generated user ID with no personal information collected.
  • Wellness Tracking Data: When you use the App's tracking features, we collect mood scores, stress levels, stress context tags (such as sleep quality, workload, social energy), micro wins and daily tasks, nightly reflection entries and journal content, morning routine data, and energy level ratings.
  • User-Generated Content: Any text, notes, reflections, goals, or other content you create within the Services.
  • Communications: If you contact us directly via email or other means, we collect the content of your communications along with your contact information.
  • Feedback and Survey Responses: Any feedback, responses, or suggestions you provide through surveys, forms, or direct communication.

2.2 Information Collected Automatically

When you access the Services, certain information may be collected automatically, including:

  • Device Information: Device type, operating system, browser type and version, screen resolution, and device identifiers.
  • Usage Information: Pages visited, features used, time spent on pages, click patterns, navigation paths, and interaction data.
  • Log Data: IP address, access times, referring URLs, and error logs.
  • Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to maintain session state, remember preferences, and analyze usage patterns. See Section 8 for more details.
  • Analytics: We may use analytics services, such as Cloudflare Web Analytics, to understand how users interact with the Services. These services may collect anonymized or aggregated usage data.

2.3 Information Stored on Your Device

The Oraya App may store certain wellness data — including mood entries, stress logs, micro wins, reflections, and preferences — locally on your device using browser localStorage or similar client-side storage technologies. This data is stored on your device and is not automatically transmitted to Oraya's servers. You can delete locally stored data at any time through the App's settings or by clearing your browser data. Please note that locally stored data is only as secure as your device; if others have access to your device or browser, they may be able to view this data.

2.4 Information from Third Parties

We may receive limited information from third-party services that you use in connection with the Services, such as Google Forms (for waitlist submissions), analytics providers, and hosting and infrastructure providers. This information is used solely for operating and improving the Services.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Services: To deliver, maintain, and operate the core functionality of the Website and App, including mood tracking, stress monitoring, reflection features, and self-awareness insights.
  • Personalization: To customize your experience within the Services, including generating personalized insights, patterns, and week-over-week comparisons based on your tracked data.
  • Communications: To send you service-related communications, including waitlist updates, product announcements, feature updates, and responses to your inquiries. You may opt out of non-essential communications at any time.
  • Improvement and Development: To understand how users interact with the Services, identify areas for improvement, develop new features, and enhance the overall user experience.
  • Analytics: To analyze aggregate, de-identified usage trends and patterns for the purpose of improving the Services. We do not use your individual wellness data for advertising or marketing purposes.
  • Security and Integrity: To detect, prevent, and address technical issues, security threats, fraud, and abuse.
  • Legal Compliance: To comply with applicable laws, legal processes, and regulatory requirements.

4. How We Share Your Information

We do not sell your personal information. We do not sell, rent, lease, or trade your personal information — including your wellness data — to any third party for their marketing or advertising purposes. We have not sold personal information in the preceding twelve (12) months.

We may share your information only in the following limited circumstances:

  • Service Providers: We share information with trusted third-party service providers who assist us in operating, maintaining, and improving the Services. These providers include hosting and cloud infrastructure services (such as Netlify and Cloudflare), database and authentication services (such as Supabase for Clarity), analytics services (such as Cloudflare Web Analytics), email delivery services (such as Resend), and form processing services (such as Google Forms). These service providers are contractually obligated to use your information only to provide services to us and in accordance with this Privacy Policy.
  • Legal Requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Oraya, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of the transaction. We will notify you via email or prominent notice on the Services of any such change and any choices you may have regarding your information.
  • Aggregate or De-Identified Data: We may share aggregate, anonymized, or de-identified data that cannot reasonably be used to identify you. This data may be used for research, analytics, product development, or industry reporting.
  • With Your Consent: We may share your information with third parties when you have given us explicit consent to do so.

5. Data Storage and Security

We implement commercially reasonable administrative, technical, and physical security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit using TLS/SSL protocols
  • Encryption of sensitive data at rest where applicable
  • Access controls limiting who can view personal data
  • Regular monitoring and assessment of our security practices
  • Secure hosting infrastructure through established cloud providers

However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee absolute security. You acknowledge and accept this inherent risk when providing information through the Services.

5.1 Data Retention

We retain your personal information for as long as your account is active, as needed to provide you with the Services, or as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. When your data is no longer needed for these purposes, we will securely delete or anonymize it.

If you request deletion of your account and data, we will process your request within thirty (30) days, subject to any legal obligations that may require us to retain certain information.

6. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

6.1 All Users

  • Access: You may request a copy of the personal information we hold about you.
  • Correction: You may request that we correct any inaccurate or incomplete personal information.
  • Deletion: You may request that we delete your personal information, subject to certain exceptions required by law.
  • Data Portability: You may request a copy of your data in a structured, commonly used, machine-readable format.
  • Opt-Out of Communications: You may opt out of non-essential communications at any time by clicking the unsubscribe link in our emails or by contacting us directly.
  • Withdraw Consent: Where we rely on your consent to process your information, you may withdraw that consent at any time.

6.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. You have the right to direct us not to sell or share your personal information at any time. You may exercise this right by contacting us at [email protected].
  • Right to Limit Use of Sensitive Personal Information: Wellness data you provide (including mood scores, stress data, and emotional reflections) may constitute sensitive personal information under the CPRA. You have the right to limit our use of sensitive personal information to purposes necessary for providing the Services. We do not use your sensitive personal information for purposes beyond what is necessary to provide the Services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise any of these rights, please contact us at [email protected]. We will respond to verifiable requests within forty-five (45) days.

6.3 European Economic Area, UK, and Swiss Residents (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object to processing. Our legal bases for processing your information include your consent, performance of our contract with you (the Terms of Service), our legitimate interests in operating and improving the Services, and compliance with legal obligations.

To exercise any GDPR rights, please contact us at [email protected]. You also have the right to lodge a complaint with your local data protection authority. If required under applicable law, Oraya will designate a representative in the European Union to serve as a point of contact for data protection inquiries.

6.4 Washington State Residents

If you are a Washington state resident, you may have rights under the Washington My Health My Data Act regarding your consumer health data. Wellness data such as mood scores, stress levels, and mental health reflections may qualify as consumer health data under this law. You have the right to access, delete, and withdraw consent for the collection and sharing of your consumer health data. Oraya will not sell or offer to sell consumer health data without your prior written consent. To exercise these rights, please contact us at [email protected].

6.5 Other State Privacy Laws

Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws may have additional rights to access, correct, delete, and opt out of the processing of personal information. To exercise rights under your state's privacy law, please contact us at [email protected]. We will respond within the timeframe required by applicable law.

7. "Do Not Sell or Share My Personal Information"

Oraya does not sell your personal information, and we do not share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding twelve (12) months. If you wish to exercise your right under applicable law to opt out of any future sale or sharing, you may do so by contacting us at [email protected].

8. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the Services. The types of cookies we use include:

  • Essential Cookies: Necessary for the basic functioning of the Services, such as maintaining session state and security. These cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with the Services so we can improve functionality and user experience. These may be provided by third-party analytics services.
  • Preference Cookies: Remember your settings and preferences (such as dark mode) to provide a more personalized experience.

You can manage your cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of the Services.

We do not use cookies for advertising purposes and do not allow third-party advertisers to set cookies through our Services. For users in jurisdictions that require affirmative cookie consent (such as the European Economic Area), we will implement a cookie consent mechanism allowing you to accept or reject non-essential cookies.

9. Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals. Because there is no common standard for interpreting DNT signals, the Services do not currently respond to DNT signals. We will update this policy if a standard for DNT signals is established.

10. Children's Privacy

The Services are not directed to children under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take prompt steps to delete such information.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at [email protected] and we will take immediate steps to remove such information.

11. Sensitive Wellness Data

We recognize that the wellness data you share with Oraya — including mood scores, stress levels, emotional reflections, and personal journal entries — is deeply personal and sensitive. We are committed to treating this data with the highest level of care and respect.

Our commitments regarding your wellness data:

  • We will never sell your wellness data to any third party
  • We will never use your wellness data for advertising or marketing purposes
  • We will never share your individually identifiable wellness data with third parties without your explicit consent, except as required by law
  • We will never use your wellness data to make automated decisions that have legal or similarly significant effects on you
  • We will provide you with the ability to export and delete your wellness data at any time
  • We will be transparent about any changes to how we handle your wellness data

12. Data Breach Notification

In the event of a data breach that affects your personal information, we will notify affected individuals and applicable regulatory authorities in accordance with applicable state, federal, and international law. We will endeavor to provide such notification as promptly as reasonably practicable, and in no event later than the deadlines required by applicable law.

Notification will include, to the extent known, a description of the nature of the breach, the types of information involved, the steps we are taking to address the breach, and recommendations for steps you can take to protect yourself.

13. International Data Transfers

Oraya is based in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that are different from those of your country.

By using the Services, you consent to the transfer of your information to the United States and other jurisdictions as described in this Privacy Policy. Where required, we will implement appropriate safeguards to protect your information in accordance with applicable data protection laws.

14. Third-Party Links and Services

The Services may contain links to third-party websites, services, or applications (including Google Forms used for waitlist registration). This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Services.

15. Clarity App — Your Data Rights

If you use the Clarity task management app, you have the following additional rights:

  • Account Deletion: You can permanently delete your Clarity account and all associated task data at any time from within the app (Profile → Delete Account). This action is irreversible and removes all your tasks, completion history, and profile information from our servers.
  • Data Portability: Your task data is stored in a standard database format. You may request a copy of your data by contacting us.
  • Widget Data: Clarity's iOS widgets store a local copy of your task data on your device using App Group shared storage. This data is only accessible by the Clarity app and its widget extension. Deleting the app removes this local data.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable laws. When we make material changes, we will update the "Effective Date" at the top of this Privacy Policy and may notify you through the Services, via email, or through other reasonable means.

Your continued use of the Services after the posting of a revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data pract