Back to home

Privacy Policy

Effective Date: February 17, 2026 · Last Updated: February 17, 2026

Oraëya (“we,” “our,” or “us”) operates the Oraëya health intelligence platform, including the website, mobile applications, and related services (collectively, the “Service”). This Privacy Policy describes how we collect, use, disclose, and protect your personal information, including health and activity data obtained through third-party wearable device integrations such as Garmin Connect, Apple Health, Oura, WHOOP, and other compatible platforms.

This Privacy Policy applies to all users of our Service, regardless of how they access it. By accessing or using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use our Service.

1. Information We Collect

1.1 Information You Provide Directly

  • Account registration information (name, email address, password)
  • Profile information (age, sex, height, weight, health goals)
  • Health and wellness information you manually input
  • Communications with us (support inquiries, feedback)

1.2 Activity and Health Data from Wearable Devices

When you connect a third-party wearable device or health platform to Oraëya (including but not limited to Garmin, Apple Health, Oura, WHOOP, and other compatible devices), we may collect the following categories of data with your explicit authorization:

  • Activity Data: Steps, distance, calories burned, active minutes, exercise sessions, activity type, intensity, and movement patterns.
  • Heart Rate Data: Resting heart rate, real-time heart rate, heart rate variability (HRV), heart rate zones, and stress scores.
  • Sleep Data: Sleep duration, sleep stages (light, deep, REM), sleep quality scores, sleep onset and wake times, and respiration during sleep.
  • Body Composition Data: Weight, body fat percentage, BMI, and related measurements where available.
  • Respiratory Data: Blood oxygen saturation (SpO2), respiration rate, and respiratory metrics.
  • Stress and Recovery Data: Stress levels, Body Battery or recovery scores, and relaxation metrics.
  • Metabolic Data: Metabolic rate estimates, energy expenditure, and nutrition-related metrics where available.

1.3 Information Collected Automatically

  • Device information (device type, operating system, unique device identifiers)
  • Log data (IP address, browser type, access times, pages viewed)
  • Usage data (features used, interaction patterns, session duration)
  • Cookies and similar tracking technologies

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To Provide and Personalize the Service: We analyze your activity and health data to generate personalized health insights, pattern recognition, system coherence assessments, and recommendations through our Coherence Compass and related features.
  • To Improve Our Service: We use aggregated and de-identified data to improve our algorithms, develop new features, and enhance the accuracy of our health intelligence models.
  • To Communicate with You: We send service-related communications, respond to inquiries, and, with your consent, send educational health content and product updates.
  • To Ensure Safety and Security: We use information to detect fraud, protect our users, and maintain the integrity of our platform.
  • To Comply with Legal Obligations: We process data as required by applicable laws and regulations.

Important: Oraëya is a health intelligence and wellness platform. We do not provide medical diagnoses, treatment recommendations, or clinical advice. All insights generated by the Service are reflective and educational in nature.

3. How We Share Your Information

We do not sell your personal information or activity data. We may share your information in the following limited circumstances:

  • Service Providers: We share data with trusted third-party service providers who assist in operating our platform (e.g., cloud hosting, analytics, customer support). These providers are contractually bound to protect your data and use it only for the purposes we specify.
  • With Your Consent: We may share information when you explicitly direct us to do so, such as sharing health summaries with a healthcare provider.
  • Aggregated or De-Identified Data: We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you, for research, analytics, or business purposes.
  • Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Oraëya, our users, or others.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to the commitments in this Privacy Policy.

4. Third-Party Wearable Device Integrations

Oraëya integrates with third-party wearable devices and health platforms — including Garmin Connect, Apple Health, Oura, WHOOP, and others — to collect activity and health data. By connecting your wearable device account to Oraëya, you authorize us to access and retrieve the data categories described in Section 1.2.

Authorization and Consent

We only access your wearable data after you provide explicit consent through the third-party platform's authorization process (e.g., OAuth 2.0). You will be clearly informed of what data we are requesting before you grant access. You may revoke this access at any time through your Oraëya account settings or directly through the third-party platform (e.g., Garmin Connect app settings).

Data Use Limitations

Activity data received from wearable device integrations is used solely for the purposes described in Section 2 of this Privacy Policy — specifically, to generate personalized health insights and wellness reflections within the Oraëya platform. We do not:

  • Use your wearable activity data for advertising or marketing purposes
  • Sell, rent, or lease your activity data to any third party
  • Share your individually identifiable activity data with third parties for their own purposes
  • Use your activity data to build advertising profiles or target ads

Data Retention and Deletion

We retain wearable device data for as long as your account is active and as needed to provide the Service. You may request deletion of your wearable data at any time by contacting us at privacy@oraeya.com or by deleting your account. Upon account deletion or data deletion request, your wearable activity data will be permanently removed from our active systems within 30 days. Backup copies are purged within 90 days, subject to any legal retention requirements.

Data Minimization

We only request access to the specific categories of data necessary to provide the Service. We do not access or store data beyond what is needed for the features you use.

Third-Party Policies

Your use of third-party wearable devices and platforms is subject to those providers' own privacy policies and terms of service. We encourage you to review the privacy practices of any wearable device or platform you connect to Oraëya. Oraëya is not responsible for the data practices of third-party wearable device manufacturers or platforms.

5. Data Security

We implement industry-standard technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and authentication measures
  • Regular security assessments and monitoring
  • Secure cloud infrastructure with SOC 2 compliant hosting providers

While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or de-identify your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).

Aggregated, de-identified data that cannot be used to identify you may be retained indefinitely for research and analytics purposes.

7. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to legal exceptions.
  • Portability: Request a portable copy of your data in a structured, machine-readable format.
  • Withdraw Consent: Withdraw consent for data processing where consent is the legal basis.
  • Revoke Wearable Access: Disconnect any linked wearable device at any time through your Oraëya account settings or directly through the third-party platform.
  • Opt-Out of Communications: Unsubscribe from marketing communications at any time.

To exercise any of these rights, please contact us at privacy@oraeya.com.

8. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws, including, where applicable, Standard Contractual Clauses approved by the European Commission.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Service. These include:

  • Essential Cookies: Required for the Service to function (e.g., authentication, security).
  • Analytics Cookies: Help us understand how users interact with the Service so we can improve it. These collect aggregated, anonymized usage data.
  • Preference Cookies: Remember your settings and preferences for a better experience.

We do not use advertising or behavioral tracking cookies. You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Service.

11. Additional Rights for Specific Jurisdictions

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information as defined under the CCPA/CPRA.

European Economic Area, UK, and Switzerland (GDPR)

If you are located in the EEA, UK, or Switzerland, we process your personal data on the following legal bases: your consent (which you may withdraw at any time), performance of our contract with you, our legitimate business interests, and compliance with legal obligations. You have additional rights under the GDPR, including the right to lodge a complaint with your local data protection authority.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website, updating the “Effective Date” above, and, where appropriate, sending you a notification via email or in-app. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Oraëya

Email: privacy@oraeya.com

Website: www.oraeya.com

Portsmouth, New Hampshire, United States

For data deletion requests or to revoke wearable device access, please email privacy@oraeya.com with the subject line “Data Request” and we will respond within 30 days.

© 2026 Oraëya. All rights reserved.