Privacy Policy
Last updated October 1, 2026
1. Who we are
Raeya ("Raeya", "we", "us") makes the Raeya iPhone app, Raeya for Mac, and this website, raeya.app (together, "Raeya"). This policy explains what we collect, why, and the choices you have. Our Consumer Health Data Privacy Policy adds detail about health data and is part of this policy.
Raeya is in a private beta, offered to people 18 and older in the United States.
Name the legal entity (or person) that operates Raeya, with a postal address. Google's verification, Apple and several state laws expect the operator to be identified. The same name belongs in the Terms.
2. What we collect
We collect only what the features you use need. Mac activity, places and health data are each collected only after you agree on a separate screen.
Your account
Your email address, your name if you add one, how you sign in (Sign in with Apple, an emailed code, or a password, which we store only as a secure hash), your settings, and the choice you made on each permission screen, with the date. If you use Sign in with Apple and hide your email, we only see Apple's relay address.
What you enter
Projects, tasks, plans, timed sessions, notes, checklists, the rules you set for sorting time into projects, and your daily reflections, including a mood rating.
Mac activity (Raeya for Mac, only if you allow it)
When you set up Raeya for Mac you choose one of three levels, and you can change it at any time:
- Apps only: the name and identifier of the app in front, when you switched to it and away, and whether your Mac was idle.
- Apps and window titles: the same, plus the title of the front window (for example "Q1 Plan – Google Docs") and the service it names. In a web browser, the window title is usually the page's title.
- Off: nothing from that Mac.
Raeya for Mac checks about once a second and uploads about every 30 seconds. It never records keystrokes, screenshots, what's on your screen, your clipboard, your microphone or camera, or the addresses (URLs) of web pages. It records nothing while paused or while you're in an app you've excluded; common password managers are excluded from the start. If a browser window's title shows it's a private (incognito) window, it keeps only the app name.
Window titles can contain other people's names (an email sender, a chat partner). They stay in the user's own account and are used only for that user's timeline. Confirm this is acceptable for personal use and whether the policy should say more.
Places (iPhone, only if you allow it)
Places where you spend 5 minutes or more while location is on: the coordinates, address and place name, and when you arrived and left. Your iPhone also asks for its own location permission.
Health and wellbeing (only if you allow it)
If you connect an Oura Ring: your sleep (times, stages and efficiency), heart rate and heart rate variability during sleep, daily sleep and readiness scores, and workouts and sessions such as meditation or naps. Also the mood rating in your daily reflection. Our Consumer Health Data Privacy Policy covers this data in detail.
Calendars (only if you connect them)
If you connect Google Calendar or allow Apple Calendar, your iPhone reads your events and shows them on your timeline. Calendar events are not stored on our servers.
Connections
To keep bringing in data from services you connect, we keep access tokens for them: Google tokens only on your iPhone, and Oura tokens on your iPhone and on our servers.
Diagnostics
If something goes wrong, the app may send us the error message and the app version, linked to your account, so we can fix it. We don't use analytics or crash-reporting services from other companies.
This website
raeya.app sets no cookies and runs no analytics or trackers. Like any website, our host (Vercel) processes standard request data, such as your IP address and browser type, to deliver pages and keep the site secure.
What we don't collect
We don't collect advertising identifiers, your contacts or photos, or the addresses of web pages you visit, and we don't track you across other companies' apps or websites.
3. How we use it
We use your data only to run the features you use:
- to show your plans, activity, places, sleep and mood on your timeline and in your reflections;
- to sort your time into projects, using rules you set;
- to sign you in and send sign-in codes;
- to keep Raeya secure and prevent abuse;
- to find and fix problems, and to answer you when you contact us.
We don't use your data for advertising, we don't sell it, and we don't use it to make decisions about you, such as for credit, insurance or employment.
AI. Raeya doesn't send your data to AI services today. If we add AI features, we'll update this policy first and ask you before any of your data is sent to one.
Revisit before any AI feature ships: a cloud model provider becomes a processor, and the Raeya Charter promises consent and zero retention.
4. Google user data
If you connect Google Calendar, Raeya asks Google for read-only access to your calendar events. Your iPhone uses them only to show your events on your timeline. They are not stored on our servers, so no one at Raeya can read them. They are not shared with anyone, not used for advertising, and not used to develop, improve or train AI or machine-learning models.
Raeya's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar in the app, or remove Raeya's access at myaccount.google.com/permissions.
Check this section against Google's sensitive-scope verification requirements before applying for verification.
5. Who we share it with
We don't sell your personal data or share it for advertising, and we never give it to employers, insurers or data brokers. We use a few service providers that handle data only on our behalf:
| Provider | What it does for us | What it handles |
|---|---|---|
| Supabase | Database, sign-in and server functions, in the United States | Everything stored in your account |
| Resend | Sends sign-in and password emails | Your email address |
| Apple | Sign in with Apple, and TestFlight for beta builds | Your Apple sign-in; what TestFlight collects under Apple's own policy |
| Vercel | Hosts this website | Standard web request data |
Confirm a data processing agreement is in place with each provider (Supabase, Resend and Vercel offer standard ones).
When you connect Oura or Google, your data comes from them to Raeya at your request. Their own privacy policies cover what they do with it, and we don't send them your Raeya data.
We may also disclose information if the law requires it, or to protect someone's safety or Raeya's rights. If Raeya is ever sold or merged, your data would stay protected by this policy, and we'd tell you before it moved.
Wording for legal disclosures and business transfers.
6. How long we keep it
We keep your data while you have an account, so your history is there when you come back to it. You can delete individual entries in the app at any time.
When you delete your account, we delete it and all of its data from our database right away, and ask Oura to revoke Raeya's access. Copies in our database provider's backups are deleted automatically after a short time.
State the backup retention once Supabase Pro is on for production (Pro keeps daily backups for 7 days). Consider stating retention limits for raw Mac activity and diagnostics once those are built.
7. Your choices and rights
Everyone who uses Raeya has these rights, whichever state they live in:
- Say no, or change your mind. Each kind of data asks first. Turn any of them off on iPhone in Settings → Data Permissions, or in Raeya for Mac's settings. That stops new collection; to remove what was already collected, delete it or your account.
- Pause or limit your Mac. Pause for 15 minutes, an hour or until tomorrow, exclude apps, or turn window titles off.
- See and correct. Your data is in the app, where you can edit or delete it. To get a copy of everything we hold about you, email us.
- Delete. Settings → Delete Account deletes your account and all of its data. You can also ask us by email.
- Appeal. If we turn down a request, you can appeal; see the Consumer Health Data Privacy Policy.
We answer requests within 45 days, free of charge, and won't treat you differently for using these rights. To protect your account, we may ask you to write from the email address you use with Raeya.
8. How we protect it
- Your data is encrypted in transit (HTTPS) and encrypted at rest by our database provider.
- Database rules keep each account's data separate, so one account can't read another's.
- Sign-in tokens on your devices are kept in the system Keychain.
- Only the people who run Raeya can access the database, and only to keep the service working, to fix a problem you report, or when the law requires it.
No system is perfectly secure. If a breach affects your personal data, we'll tell you, and the authorities where the law requires it.
FTC Health Breach Notification Rule: does Raeya count as a vendor of personal health records, and what is the breach playbook (notify users, the FTC and possibly media within 60 days)?
9. Children
Raeya is for adults 18 and older and isn't directed at children. If you believe someone under 18 has an account, email us and we'll delete it.
18+ was chosen for the beta (the analysis allowed 13+). It must match the App Store age rating and the Terms.
10. Where your data is stored
In the United States. Raeya is offered only in the United States for now.
Before accepting EU or UK users: GDPR Article 9 consent for health data, a transfer basis, processor agreements, and possibly a DPIA.
11. Changes to this policy
We'll post any change here and update the date at the top. If a change is significant, we'll tell you in the app or by email before it takes effect, and ask for your consent again where the law requires it.
12. Contact
Email hello@raeya.app with any question or request about your data.