Privacy Policy

Version 0.3 · Draft, not yet in force

This is a draft. It describes accurately what the Rayl app does today, but it has not been reviewed by a lawyer and is not yet in force. Rayl is not open to the public. If you are reviewing this before launch, that is what it is for.

Rayl exists so you can share a verified health status with someone without handing over your medical records. This page explains what that means in practice — including the parts that are less convenient to say.

What Rayl stores

WhatWhyHow long
Your email address and passwordTo sign you inUntil you delete your account
Which version of these documents you accepted, and whenTo evidence your consentUntil you delete your account
Your status: a colour, the date of your most recent result, and how long it stays validThis is what you shareUntil you delete your account
A record of your handshakes, as opaque tokensSo an exposure alert can reach the right people, and so your connections survive if you change phones90 days, then deleted automatically
Documents you upload for reviewSo a reviewer can check themDeleted after review; the decision is kept
Whether you have a current PrEP or doxy-PEP prescription, and whether you have chosen to show eachSo a partner can verify a claim you make, if you choose to make itUntil you delete your account
Your state and the first three digits of your ZIP codeAggregate public health statisticsUntil you delete your account
A log of who accessed health informationAccountabilityRetained after account deletion — see below

What Rayl does not store

Who can see what

People you handshake with

They see a status — a colour and a date. Never a result, a condition, or a document.

Rayl reviewers

If you upload a document instead of connecting a provider, a trained reviewer reads it before your status changes. They can see that document. There is no way to have a human check something without a human seeing it. Every time a reviewer opens a document, that access is logged. Documents are deleted after review.

Rayl staff, generally

Access to health information is limited to accounts holding a reviewer role, and every such access is recorded. Rayl does not have a screen anywhere that lists who has handshaked with whom. But we should be straightforward: the 90-day record of your connections exists on Rayl's servers, and someone with direct database access could read it during that window. We keep it because losing it would silently break exposure notification for anyone who changes phones, and we limit the harm by keeping only 90 days rather than a history.

Prescription status

If you connect a healthcare provider, Rayl can see whether you have a current PrEP or doxy-PEP prescription. Rayl stores whether one exists and when it was last seen — not the prescription itself, the dose, or the prescriber.

Neither is shown to anyone unless you switch it on. Each is off by default and can be switched off again at any time. An indicator that is off means either that there is no current prescription or that you have chosen not to show it, and the two are indistinguishable to anyone you share with. That is deliberate: if off meant definitely-not-prescribed, choosing not to share would itself be a disclosure.

We should flag something about doxy-PEP specifically. It is recommended for a particular group of people who have had a bacterial infection in the past year, so showing that indicator can tell a partner more about you than you may intend. Rayl explains this before you turn it on, and leaves it off by default.

Rayl can confirm that a prescription exists. It cannot confirm that it is being taken. PrEP protects against HIV and not other infections, and doxy-PEP is taken after sex, so a prescription says nothing about any particular occasion.

Exposure notifications

If someone you handshaked with reports a positive result verified by their healthcare provider, you may be notified. What you are told is that someone you exchanged a handshake with reported a result — never who, and never which condition. Rayl does not record who sent an alert.

We should be honest about a limit here. If you have handshaked with only one person, receiving an alert tells you where it came from. No design can prevent that, and public health partner notification has the same property. It is the reason the alert says as little as it does.

Alerts can only be triggered by a result from a healthcare provider or one reviewed by a clinician. Nobody can start one by claiming something about themselves.

Aggregate statistics

Rayl produces counts — how many people are using it in a state, how many alerts were sent, what proportion of alerted people went on to get tested. These hold no names and no identifiers, and any group small enough that an individual could be picked out is suppressed and shown as nothing rather than as a small number.

You can switch this off in your profile at any time. If you do, your activity is excluded from every future count.

Deleting your account

From inside the app, at any time. It removes your account, your status, your consent records, your connections, your submitted results and your provider connections.

One thing is kept: the log of who accessed health information. A record that the subject of it can erase is not a record. It contains no health information itself — only that an access happened, by whom, and when.

Deleting your Rayl account does not revoke Rayl's access at your healthcare provider. The app will tell you this when you delete, and you should also revoke access in your provider's own app or portal.

Children

Rayl is for adults aged 18 and over. It is not directed at children and we do not knowingly collect information from them.

Changes

When these terms change materially you will be asked to accept the new version in the app. Your acceptance is recorded against a specific version, so it is always clear what you agreed to.

Contact

Questions about this policy: hello@getrayl.com