Privacy Policy
Effective September 5, 2026
This policy describes what the Ring Vitals apps for iPhone, iPad and Android and the ringvitals.com website (together, “Ring Vitals”) actually do with information. It is written to match the software as built. Ring Vitals is operated by Jesse Marcel (“we”). Contact: support@ringvitals.com.
1. The short version
- Your raw health data stays on your device. We do not upload Apple Health or Health Connect datasets to our servers.
- Health data is never sold, never used for advertising, and Ring Vitals contains no advertising or ad-tech SDKs.
- An account is optional for core local features. It is needed for subscriptions, the Oura connection and optional AI explanations.
- You can delete your account and cloud data in the app (Settings → Account → Delete Account) or at ringvitals.com/delete-account.
2. Information we process, and where
| Category | What | Where it lives | Why |
|---|---|---|---|
| Health data (Apple Health / Health Connect) | Heart rate, resting heart rate, heart rate variability, sleep, respiratory rate, blood oxygen, wrist or skin temperature, steps, active energy and workout context, when you grant access | Your device only (encrypted local database) | Baseline learning, Vitals Score, trends, insights, reports |
| Oura data (optional) | Sleep, heart rate, HRV, temperature deviation, oxygen and readiness source metrics from the Oura API | Fetched through our server and delivered to your device without being stored server-side; access and refresh tokens are stored encrypted on our server | Direct Oura source with accurate attribution |
| Account data | Email address, display name if provided, sign-in provider identifiers (Apple, Google or email), session tokens | Our database (Neon Postgres, US) | Authentication, account recovery, subscription restoration |
| Subscription data | Store transaction or purchase-token identifiers, product, state, expiry, environment; no payment card details | Our database, plus Apple or Google | Entitlement to Ring Vitals+ across devices |
| Consents and preferences | Your choices for AI insights, change notifications, lock-screen detail | Device and our database if signed in | Honouring your choices |
| AI insight requests (opt-in only) | De-identified derived metrics: baseline state, Vitals Score, per-metric today/baseline values, robust deviation, 7-day trend direction, deterministic insight text and optional journal tags | Sent to our server and then to Anthropic for generation; we store only token counts and status, never the text | Optional plain-language explanations |
| Report metadata | Report type, period, page count, size | Our database if signed in | Report history. The PDF itself never leaves your device unless you share it |
| Journal entries | Optional context tags and notes you enter | Your device only | Contextualising trends |
| Operational logs | Request identifiers, timestamps, error codes, OAuth and billing-webhook failure events | Vercel logs (short retention) | Reliability and security |
We do not collect location, contacts, photos, advertising identifiers, or clinical health records.
3. Apple Health and Health Connect
Ring Vitals reads only the data types listed above and only after you grant permission in the system permission screens. Version 1 is read-only: Ring Vitals does not write to Apple Health or Health Connect. Health data obtained from these platforms is used only to provide Ring Vitals features on your device. It is never used for advertising, marketing, or data-mining purposes, and is never disclosed to third parties for those purposes. Health Connect data is not transferred to any server. You can revoke access at any time in the Health app or Health Connect settings; Ring Vitals then stops reading and offers to delete its local copy.
4. Optional cloud AI explanations
AI explanations are off by default. If you turn them on in Settings, Ring Vitals sends the minimum derived information described above to Anthropic’s Claude API through our server. We never send your name, email, raw heart-rate streams, unrelated metrics, journal free text, location or device identifiers. Anthropic processes this data as our processor and does not use API inputs to train its models. You can turn AI explanations off at any time; the deterministic on-device insight engine continues to work.
5. Authentication providers
Sign in with Apple, Google sign-in and email one-time codes are supported. With Apple you may hide your email; we then receive a relay address. Provider tokens are used only to verify your identity and are stored encrypted or hashed as required for session management.
6. Subscriptions
Ring Vitals+ is purchased through the App Store or Google Play, which handle payment. We receive signed transaction information from Apple (App Store Server Notifications) and Google (Real-time Developer Notifications and the Play Developer API) to keep your entitlement current. We never see your card number.
7. Analytics, crash reporting and advertising
Ring Vitals contains no third-party analytics SDK, no advertising SDK and no third-party crash reporter in this release. Platform crash reports you opt into with Apple or Google are governed by their policies and are scrubbed of health values by design because the app never places health values in log output.
8. Processors
- Vercel (web hosting and API), United States
- Neon (Postgres database), United States
- Apple and Google (authentication, app distribution, payments)
- Oura Health (only when you connect Oura)
- Anthropic (only when you enable AI explanations)
- An email delivery provider for one-time codes when email sign-in is enabled
9. Retention
Account and subscription records are kept while your account exists. Operational logs are retained for a short period for reliability and security. When you delete your account we remove profile, connections, encrypted Oura tokens, entitlement records, consents, insight request records and report metadata, and revoke Oura access where the Oura API permits. We retain only a hashed, anonymised deletion marker (no email, no health data) as evidence that deletion occurred. Local data on your device is wiped by the app during deletion.
10. Your choices
- Use Ring Vitals without an account for local features and Demo Mode.
- Grant, limit or revoke health permissions at any time.
- Connect or disconnect Oura in Settings.
- Export your Ring Vitals data (JSON and CSV) at no charge.
- Delete local data, or delete your whole account.
- Opt in or out of AI explanations and notifications.
Deleting your Ring Vitals account does not delete records from Apple Health, Health Connect or Oura, because Ring Vitals did not create those records.
11. Security
Data in transit is protected with TLS. Session tokens are stored in the iOS Keychain or Android Keystore-backed encrypted storage. Oura tokens are encrypted at rest with AES-256-GCM. Store payloads are signature-verified. See the security overview.
12. Children
Ring Vitals is not directed to children under 13 and we do not knowingly collect their information.
13. Changes
We will update this page and the effective date when the software’s data practices change. Material changes will be announced in the app.