Privacy
Most privacy pages are written to protect a company. This one is written so you can check our work.
The short version
Nothing you type into the self-check leaves your device. Not the answers, not the result, not the fact that you took it. It is worked out in your browser by code you can read, and there is no request in it that could send anything anywhere. Close the tab and it is gone — which is also why, if you want your result, you have to screenshot it.
The same goes for the aura demo. Moving those sliders sends nothing and stores nothing.
There are no analytics, no advertising pixels, and no session recording on this site. No Google Analytics, no Meta pixel, no Hotjar, no heatmaps. Not gated behind a consent banner — simply not here. That is why you were never asked to accept cookies: there is nothing to accept.
One thing can leave your device, and only if you choose it: the email address you type into the waitlist form, plus the optional answer to "are you asking for yourself or for someone else." Nothing else is attached to it. It is not linked to anything you did on this page, because nothing you did on this page was recorded.
How to check that, rather than trust it
- Open your browser's developer tools, go to the Network tab, and take the whole self-check. You will see no requests.
- The scoring runs in one file with no network calls in it. The questions and the rule come from a published paper, cited on the page.
- The site sends a Content-Security-Policy header that permits scripts, fonts, images and connections only from this origin. A third-party tracker could not load here even if someone added one by mistake.
- The fonts are served from this domain. Loading a page here does not tell Google, or anyone else, that you were reading about PMDD.
What the server knows
When you load any page, our host receives the request — an IP address, a timestamp, the page requested, and a user-agent string. That is how the web works, and it is true of every site you have ever visited. We do not analyse those logs, join them to anything, or keep them beyond our host's ordinary operational retention.
If you submit the waitlist form, we store the email address and the optional segment with an email provider under a signed data processing agreement. We use it to tell you when the app is available. Every message has an unsubscribe link that works, and asking us to delete your address removes it — write to hello@oriyali.com.
What this site stores in your browser
One thing: whether you have chosen light or twilight. It lives in your browser's local storage, it never leaves your device, and it is the only value we set. There are no cookies.
The app
The Oriyali iPhone app is built on the same posture, and more strictly, because it holds far more.
- Local-first. Your entries are stored on your device.
- Optional encrypted iCloud sync, in your own private iCloud database. Yours, not ours.
- Sign in with Apple only, and only if you want sync. No account is required to use the app.
- One-tap delete that actually deletes. This is a direct answer to a real, repeated complaint about the app most PMDD patients have tried.
- No third-party analytics anywhere near health data. Ever, under any commercial pressure.
- Never sold, never shared, never brokered — not to advertisers, not to data brokers, not to insurers.
Your rights
Wherever you live, you can ask what we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. Given the above, the honest answer is usually "an email address, or nothing at all." Write to hello@oriyali.com and we will answer within 30 days.
For readers in India, this is handled in line with the Digital Personal Data Protection Act, 2023. For readers in the EU and UK, in line with the GDPR: our lawful basis for the waitlist is your consent, which you can withdraw at any time.
Changes
If this ever changes, the change will be dated here, and anyone on the waitlist will be told before it takes effect — not after.
Last updated: 4 September 2026.