ORAYA

Legal

Privacy Policy

How ORAYA collects, uses, discloses, and protects information across the ORAYA clinical platform, the MyORAYA patient app, our websites, and the notifications we send you.

Effective July 29, 2026 Last updated July 29, 2026

What this policy covers.

Our text messaging practices, stated up front.

These are the points people most want answered directly, so we state them here. They are repeated in full detail in Section 6.

We never share your number for marketing

We do not sell, rent, lease, trade, or share your mobile phone number, or your consent to receive text messages, with any third party or affiliate for their own marketing or promotional purposes. Mobile information is never shared with third parties for marketing purposes. The only parties that receive your mobile number are the communications vendors that transmit messages on our behalf, and only so that they can deliver the message you asked for.

Message frequency varies

ORAYA texts are transactional and event-driven, not recurring marketing campaigns. Most messages are sent only in direct response to something you do (for example, requesting a sign-in code). Typical volume is fewer than 10 messages per month.

Message and data rates may apply

Your mobile carrier's standard messaging and data charges apply to messages you send to and receive from ORAYA. ORAYA does not charge you for text messages.

You can stop messages at any time

Reply STOP to any ORAYA text message to opt out, or HELP for assistance. See Section 6.5.

Health data, HIPAA, and your provider.

What we collect, and where it comes from.

CategoryExamples
Account and identityName, date of birth, email address, mobile phone number, and identifiers used to match you to your medical record
AuthenticationPasswords, one-time passcodes ("OTP"), account recovery answers, security settings
Contact preferencesThe email address and mobile number you designate for notifications, and changes you make to them
Content you submitMessages you send through the app, appointment requests, record requests, self-reported medications, allergies, symptoms, and intake responses
Support communicationsInformation you provide when you contact us for support
We design our logging so that message bodies, one-time passcodes, and full contact addresses are redacted; phone numbers and email addresses appear in our logs only in masked form.

Six purposes, and nothing beyond them.

We do not sell your personal information, and we do not use your health information or contact information for third-party advertising.

Three channels, all transactional.

ORAYA communicates with you over three channels. All three exist to operate your account and your care, not to market to you.

ChannelUsed forProvider
EmailVerification codes, security notices, account and connection notices, invitations to connect your recordAmazon Simple Email Service (AWS)
SMS / textOne-time passcodes and account-security alerts onlyTwilio
Mobile pushAppointment confirmations, changes, cancellations, 24-hour appointment reminders, new document available, record-connection noticesExpo push notification service (Apple APNs / Google FCM)

Authentication and account-security messages only.

MessageWhen it is sent
Sign-in verification codeEach time you request a code to sign in
Contact-change verification codeWhen you add or change an email address or mobile number
Contact-change noticeTo your previous contact point, when your email or mobile number is changed
Account recovery noticeWhen your account is recovered on a new device and prior sessions are signed out
Important: because ORAYA texts carry sign-in codes and security alerts, opting out of SMS may prevent you from signing in by text and will stop security notices to that number. If you opt out, add or verify an email address in the app so you can still receive verification codes and account alerts.

Five circumstances, and no others.

7.1 With your provider

Information you enter in MyORAYA (contact updates, self-reported allergies and medications, appointment and record requests, and messages) is shared with the Provider that treats you, so that it can become part of your care.

7.2 With service providers

We use vetted vendors to operate the Services. Each is bound by contract, and by a HIPAA Business Associate Agreement where they may encounter PHI, to use information only to provide services to us.

7.3 Business transfers

If ORAYA is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy and to continuing HIPAA obligations. We will provide notice of any material change in how your information is handled.

7.4 Legal and safety

We may disclose information when required by law, subpoena, court order, or other legal process; to cooperate with regulators or public-health authorities; to enforce our agreements; or to protect the rights, safety, and property of ORAYA, our users, or the public.

VendorPurpose
Amazon Web ServicesCloud hosting, storage, and email delivery (SES)
Supabase / managed PostgreSQLApplication database
TwilioSMS delivery
Expo, Apple APNs, Google FCMMobile push notification delivery
We never sell your personal information, and we never share it with data brokers or advertising networks.

Safeguards designed to meet the HIPAA Security Rule.

What you control, and where to exercise it.

How long we keep information, and where it lives.

11. Data retention

We retain information for as long as needed to provide the Services and as required by our agreements with Providers and by law. Retention of medical record data is governed by your Provider's retention obligations, which commonly run seven or more years. Authentication artifacts such as one-time codes are retained only briefly. Security and HIPAA audit logs are retained for at least six years, as required by the HIPAA Security Rule. De-identified and aggregated data may be retained indefinitely.

12. Children's privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 for our own purposes. Where a Provider treats a minor patient, the minor's health information is handled under the Provider's direction and applicable law, and access is granted through the Provider to the patient or an authorized personal representative.

13. Where information is processed

The Services are operated in the United States, and information is stored and processed in U.S.-based facilities. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above. If we make material changes to how we use your information or to our messaging practices, we will provide additional notice through the Services, by email, or by other appropriate means before the change takes effect. We will not materially change our text messaging opt-in, sharing, or frequency practices without notifying you and, where required, obtaining your consent again.

Who to reach, and for what.

Questions about your data?

Reach us at info@orayasolutions.com, or read the Terms & Conditions that go with this policy.