A public instrument of the OYA movement
The OYA Standard (OYA-S)
OYA-S is the draft standard being developed for any organization that collects personal information and creates a profile, inference, score, recommendation, ranking, personalization, or eligibility decision from it. In scope: AI products that build profiles, scores, or recommendations; dating and social platforms; coaching and wellness products; marketplaces; education products; and financial products and eligibility tools.
Founding status. OYA-S is a draft. It has not been ratified by an independent board, and OYA does not yet operate as a certifying body — no company has been certified against it. Full detail: Status & disclosures.
The control domains
Nine control domains.
Each domain names a specific control OYA-S asks a member to build and keep evidence for.
Data Map
A member-readable map of what is collected, inferred, retained, and why.
Algorithmic Representation
Understandable descriptions of what a profile or inference means, and how a member can contest it.
Purpose Boundaries
Documented permitted and prohibited uses for each data category — for example, never selling private reflection data undisclosed.
Sensitive Information Safeguards
Proportionate controls for sensitive data: encryption, least-privilege access, minimization, and retention rules.
Member Controls
Access, correction, deletion, export, and the ability to limit how sensitive data is used.
No Coercive Disclosure
No social, relationship, or employment pressure mechanisms that force disclosure of private records to another person.
Derived-Data Lineage
Tracking how derived data was produced, so a correction or deletion can propagate downstream.
Research and Model Improvement
Separating account-linked data from de-identified aggregate research data, with re-identification-risk controls.
Accountability and Redress
A named accountable role, a dispute and incident process, and a public change log.
The adoption ladder
Six tiers. One ladder.
Each tier is being designed to earn one specific public claim — no more.
"We support the principles."
"We are working toward the standard."
"We have declared our conformance."
"Our declared conformance has been assessed."
"Our conformance has been independently verified."
"Verified OYA Gold [version]."
The top tier
What OYA Gold requires.
The short list, as currently drafted.
- A member-visible data map.
- Functional correction and deletion controls.
- Sensitive-data classification with a restricted processing environment.
- No targeted ads or pricing manipulation drawn from sensitive data.
- No default peer or partner access to private records.
- Independent annual assessment.
Founding implementer
AlignHeart is building toward Gold.
AlignHeart — a separate, independent company and OYA's founding implementer — has stated it is building its own product toward this Gold tier. That is a fact about AlignHeart's own roadmap, not a claim about OYA's existence or operation: no company, including AlignHeart, has been certified against OYA-S, because OYA does not yet operate as a certifying body. A full worked draft of one of these standards — OYA-S 2000, covering sensitive data, encryption, member-key control, and erasure — is published in full, with every requirement in normative form, so the standard can be read rather than taken on faith.