Privacy
Privacy

Ayra Health

What stays private,

stays private.

Ayra public proof surfaces are designed around data minimization, controlled access, and no raw patient data in public receipt paths.

Public surfaces never need raw clinical content to prove a workflow happened.

Last updated June 2026

Scope

This Privacy Policy explains how Ayra Health, Inc. handles information collected through the public website, request forms, controlled technical previews, pilot access surfaces, receipt tracker, developer materials, and related communications.

Customer production deployments, governed pilots, business associate relationships, and partner integrations may be controlled by separate written agreements. If a signed agreement conflicts with this public policy, the signed agreement controls for that relationship.

Collection

Ayra may collect information you provide directly, information generated through your use of the site or approved preview surfaces, and limited operational metadata needed to keep the service secure and reliable.

Contact and business details, including name, organization, role, work contact information, and request scope.

Access information, including pilot account identifiers, invitation status, sign-in events, role selections, session state, and access-control metadata.

Evaluation content, including request descriptions, workflow categories, pilot feedback, technical review notes, and materials you choose to submit through approved forms.

Technical metadata, including device type, browser, IP-derived security signals, timestamps, page interactions, error logs, and performance events.

Sanitized proof metadata, including receipt references, proof identifiers, batch references, event categories, and non-content status fields used to demonstrate reviewability.

Public pages and public preview surfaces are not intended for protected health information, raw claims, live credentials, secrets, or private rule tables. Do not submit those materials unless Ayra has approved the environment and written agreement for that purpose.

Use

Ayra uses information to respond to access requests, evaluate fit, operate approved pilots, provide technical review materials, secure accounts, maintain availability, diagnose issues, improve product reliability, and satisfy legal, security, contractual, and compliance obligations.

We may use aggregated, synthetic, de-identified, or sanitized information to understand product performance, improve documentation, validate proof flows, and demonstrate platform behavior. We do not sell personal information and do not use protected health information for advertising.

PHI boundary

Ayra is designed so public review surfaces can show proof posture without exposing protected health information. Where Ayra processes protected health information for a covered entity or business associate, that processing must be governed by the applicable customer agreement, business associate agreement, data-processing terms, and approved deployment scope.

Unless an approved agreement says otherwise, public site forms, public previews, public receipt views, and public developer materials should contain only business contact information, sanitized metadata, synthetic examples, or de-identified evaluation content.

Proof receipts

Ayra proof receipts are designed to support review without placing raw patient data, raw claims, production secrets, or proprietary rule tables into public receipt paths. Depending on the workflow, a public or reviewer-facing record may include salted commitments, batch roots, proof IDs, receipt references, status labels, timestamps, category names, or other sanitized metadata.

A receipt reference is evidence that a record was emitted or anchored in a particular review flow. It is not a complete medical record, claim file, clinical determination, payer decision, or warranty that a third party will accept a submission.

Sharing

Ayra shares information only as needed to operate the site, process requests, support approved evaluations, protect the service, comply with law, or complete a transaction such as financing, reorganization, merger, acquisition, or asset transfer.

Service providers may support hosting, security, analytics, communications, forms, storage, support tooling, and operational monitoring.

Pilot administrators, integration partners, and reviewers may receive information only within the approved scope for that evaluation or agreement.

Professional advisers, insurers, auditors, legal counsel, and compliance reviewers may receive information when reasonably necessary.

Government, regulatory, or legal recipients may receive information when required by law, subpoena, court order, or to protect rights, safety, and security.

Ayra does not sell personal information. Ayra does not share personal information for cross-context behavioral advertising.

Retention

Ayra retains information for as long as needed to provide the service, evaluate requests, maintain security records, support audit trails, satisfy contractual obligations, preserve evidence of access or consent, resolve disputes, comply with law, and enforce agreements.

Retention periods vary by record type. Security logs, request records, pilot records, and proof metadata may be retained longer than ordinary contact records where retention is necessary for auditability, fraud prevention, legal defense, or compliance.

Security

Ayra uses administrative, technical, and operational safeguards designed to protect information against unauthorized access, misuse, loss, alteration, and disclosure. Safeguards may include access controls, role scoping, encrypted transport, secure storage, logging, monitoring, review boundaries, data minimization, and vendor due diligence.

No internet-accessible system can be guaranteed perfectly secure. You are responsible for protecting your credentials, using approved access paths, and promptly reporting suspected unauthorized access through the request access form.

Rights and requests

Depending on your location and relationship with Ayra, you may request access, correction, deletion, restriction, portability, or objection for certain personal information. These rights may be limited by security, legal, contractual, audit, retention, or healthcare-record obligations.

If your information was provided through a clinician, payer, customer, employer, or partner, Ayra may direct your request to that organization because it may control the relevant record. Use the request access form to submit privacy requests.

Cookies and local storage

Ayra may use cookies, local storage, and similar technologies for session state, security, routing, preference storage, form functionality, fraud prevention, and basic site operations. We do not design the public site around advertising trackers.

Browser settings may allow you to block or delete cookies. Some site functions, login surfaces, pilots, or request forms may not work correctly without required session or security storage.

Children and minors

The public site, developer materials, investor pages, and access request surfaces are intended for business, clinical, payer, reviewer, and partner audiences. They are not directed to children. Do not submit information about minors through public forms unless Ayra has approved a governed environment and agreement for that purpose.

Changes and contact path

Ayra may update this policy as the product, law, security posture, or business changes. Material changes will be reflected by updating the date above or by providing additional notice where appropriate.

Use the request access form for privacy questions, data requests, security concerns, compliance review, or diligence materials. Ayra does not use a public email address as the primary intake path for privacy requests.

Ayra Health

Healthcare verification infrastructure. Starting in behavioral health.

© 2026 Ayra Health · Houston, Texas.