Rayl exists so you can share a verified health status with someone without handing over your medical records. This page explains what that means in practice — including the parts that are less convenient to say.
| What | Why | How long |
|---|---|---|
| Your email address and password | To sign you in | Until you delete your account |
| Which version of these documents you accepted, and when | To evidence your consent | Until you delete your account |
| Your status: a colour, the date of your most recent result, and how long it stays valid | This is what you share | Until you delete your account |
| A record of your handshakes, as opaque tokens | So an exposure alert can reach the right people, and so your connections survive if you change phones | 90 days, then deleted automatically |
| Documents you upload for review | So a reviewer can check them | Deleted after review; the decision is kept |
| Whether you have a current PrEP or doxy-PEP prescription, and whether you have chosen to show each | So a partner can verify a claim you make, if you choose to make it | Until you delete your account |
| Your state and the first three digits of your ZIP code | Aggregate public health statistics | Until you delete your account |
| A log of who accessed health information | Accountability | Retained after account deletion — see below |
They see a status — a colour and a date. Never a result, a condition, or a document.
If you upload a document instead of connecting a provider, a trained reviewer reads it before your status changes. They can see that document. There is no way to have a human check something without a human seeing it. Every time a reviewer opens a document, that access is logged. Documents are deleted after review.
Access to health information is limited to accounts holding a reviewer role, and every such access is recorded. Rayl does not have a screen anywhere that lists who has handshaked with whom. But we should be straightforward: the 90-day record of your connections exists on Rayl's servers, and someone with direct database access could read it during that window. We keep it because losing it would silently break exposure notification for anyone who changes phones, and we limit the harm by keeping only 90 days rather than a history.
If you connect a healthcare provider, Rayl can see whether you have a current PrEP or doxy-PEP prescription. Rayl stores whether one exists and when it was last seen — not the prescription itself, the dose, or the prescriber.
Neither is shown to anyone unless you switch it on. Each is off by default and can be switched off again at any time. An indicator that is off means either that there is no current prescription or that you have chosen not to show it, and the two are indistinguishable to anyone you share with. That is deliberate: if off meant definitely-not-prescribed, choosing not to share would itself be a disclosure.
We should flag something about doxy-PEP specifically. It is recommended for a particular group of people who have had a bacterial infection in the past year, so showing that indicator can tell a partner more about you than you may intend. Rayl explains this before you turn it on, and leaves it off by default.
Rayl can confirm that a prescription exists. It cannot confirm that it is being taken. PrEP protects against HIV and not other infections, and doxy-PEP is taken after sex, so a prescription says nothing about any particular occasion.
If someone you handshaked with reports a positive result verified by their healthcare provider, you may be notified. What you are told is that someone you exchanged a handshake with reported a result — never who, and never which condition. Rayl does not record who sent an alert.
We should be honest about a limit here. If you have handshaked with only one person, receiving an alert tells you where it came from. No design can prevent that, and public health partner notification has the same property. It is the reason the alert says as little as it does.
Alerts can only be triggered by a result from a healthcare provider or one reviewed by a clinician. Nobody can start one by claiming something about themselves.
Rayl produces counts — how many people are using it in a state, how many alerts were sent, what proportion of alerted people went on to get tested. These hold no names and no identifiers, and any group small enough that an individual could be picked out is suppressed and shown as nothing rather than as a small number.
You can switch this off in your profile at any time. If you do, your activity is excluded from every future count.
From inside the app, at any time. It removes your account, your status, your consent records, your connections, your submitted results and your provider connections.
One thing is kept: the log of who accessed health information. A record that the subject of it can erase is not a record. It contains no health information itself — only that an access happened, by whom, and when.
Deleting your Rayl account does not revoke Rayl's access at your healthcare provider. The app will tell you this when you delete, and you should also revoke access in your provider's own app or portal.
Rayl is for adults aged 18 and over. It is not directed at children and we do not knowingly collect information from them.
When these terms change materially you will be asked to accept the new version in the app. Your acceptance is recorded against a specific version, so it is always clear what you agreed to.
Questions about this policy: hello@getrayl.com