ALLAYRA LLC · LAST UPDATED September 19, 2026
Privacy policy
ALLAYRA LLC ("Allayra," "we," "us") provides a shared workspace for family care coordination. This policy explains the information handled through allayra.com, its uses and recipients, and your choices.
Health-related information is also covered by our Consumer Health Data Privacy Policy. Questions or requests: admin@allayra.com.
1. Information we collect
- Account and circle details: your customer sign-in identifier, email, available display name, care recipient name or nickname, relationship, time zone, member roles, and invitations.
- Content you and your circle add: tasks, appointments, medication instructions and schedules, refill tasks, notes, questions, family updates, sources, attachments, and file details. These may reveal sensitive health information.
- Activity and technical information: record timestamps, circle activity, and request or error information. Hosting and sign-in services may receive IP addresses, browser details, and security logs.
- Communications and interests: support messages and plan or pilot interests you submit, including contact information and supplied details. Organization inquiries include a business name, contact name and email, organization type, approximate family count and an optional business goal. Please do not submit family names, medical information or payment details in that form.
- Billing, when available: customer and subscription identifiers, selected plan, status, and billing dates. Stripe collects payment-method and billing information. Allayra does not store full card numbers or card security codes.
- Optional affiliate referrals: if you choose to credit a referral, we record the partner, a hashed random browser token, and referral dates. If you begin a new membership within the referral window, we associate the referral with your billing account and eligible payment amounts to account for commissions. We do not include care-circle content in this process.
Sources include you, care-circle members, your sign-in provider, and service providers. Allayra does not automatically obtain records from clinics or electronic health record systems.
2. How we use information
We use information to authenticate users, maintain circles, save and retrieve records, apply permissions, support invitations, show activity, provide exports and deletion, respond to requests, protect the service, and troubleshoot failures. Submitted commercial interests help us manage your request. Billing data supports subscriptions, payment support, and required financial records when paid service becomes available.
We do not sell personal or health data, use care records for targeted advertising, or place advertising pixels in the care workspace. We do not use care content to train our own AI models. New uses of health data require notice and consent where applicable law requires them.
Optional referral records help us attribute new subscriptions, calculate partner commissions, and review refunds or disputes. Partners see aggregate referral and payment totals, not customer names, emails, or care records. Necessary attribution and commission records are retained for financial accounting and dispute resolution.
4. Optional AI and voice
Conversational AI is currently disabled. Basic Brain Dump organization and care-record search work without an AI-provider request. Allayra does not extract uploaded PDF or image contents.
If AI is enabled, the interface asks for consent before sending a request to OpenAI. Organization requests include your note, circle time zone, and member names and identifiers. Question-answering requests include your question and relevant saved record text. Review submissions and suggestions before saving. Turning AI off stops future requests, but does not erase information already processed.
The integration requests that API responses not be stored as retrievable response objects. This is not a promise of zero provider retention; provider processing and security retention follow applicable service terms.
Optional voice input uses your browser's speech-recognition service after consent and microphone permission. It may process audio remotely. Allayra receives the resulting text and does not provide an audio archive. You can type instead and revoke microphone permission in your browser.
6. Retention, deletion, and your controls
Care records remain in active storage while their circle is maintained, until an authorized member deletes them or we act on a valid privacy request. There is no automatic expiration. Owners can delete a circle and its files; contributors can delete individual records. Settings provides record export and a separate control to remove saved commercial interests. Download files individually from Documents.
Organization inquiries submitted without an account are used to respond to that request, not to enroll the contact in marketing emails. These inquiry records are removed 365 days after submission during the next inquiry processing. To request access, correction or earlier deletion, contact us with your inquiry reference; the signed-in saved-interests control does not remove these separate inquiries. Daily hashed network and email keys help limit form abuse; the form does not store raw IP addresses. Rate counters expire within 48 hours and are removed during the next inquiry processing.
Active deletion does not instantly erase all provider logs, backups, billing records, or copies held by members. Necessary security, legal, and financial records may be retained where permitted or required. Health-data deletion follows the applicable requirements in our health-data policy, including processor and backup obligations.
For access, corrections, deletion, or withdrawal of consent beyond the app's controls, email admin@allayra.com. Care recipients without an account can also contact us. We may request minimal information to verify identity or authority. Do not send medical documents, passwords, or card details by ordinary email; ask us how to provide sensitive material. Applicable law determines additional rights and deadlines.
7. Security and care boundaries
Allayra uses HTTPS, server-side membership checks, role-based editing, and authenticated file access. It is not end-to-end encrypted: its operator and infrastructure providers can process stored information to run it. No service guarantees absolute security. Protect your sign-in account and invite only people who should see every record in a circle.
Allayra does not diagnose, prescribe, verify medication safety, monitor emergencies, or guarantee delivery of care. HIPAA compliance has not been assessed; the beta is not offered for covered-entity clinical workflows. We will provide incident notices required by applicable privacy or health-data breach laws.
Providers may process information in the United States and other locations they use. Allayra makes no promise of a particular storage region.
8. Children, changes, and contact
Accounts are intended for adults aged 18 or older. Adults may maintain a dependent's information only with necessary permission or legal authority. Contact us about information supplied without authority.
We update the date above when this policy changes and provide further notice or request consent when required. Contact ALLAYRA LLC at admin@allayra.com for privacy questions.