Security & Health Safety
Effective September 5, 2026
Health & safety
Ring Vitals is intended to help you understand personal wellness trends. It is not a medical device and is not intended to diagnose, treat, cure or prevent disease. It is not an emergency monitoring service. If you believe you are experiencing a medical emergency, contact local emergency services.
Language in the app is deliberately descriptive: “outside your recent usual range” rather than alarming wording. When data is uncertain, the app says so. The Vitals Score describes how today compares with your personal normal, never the chance of a disease.
Architecture
- Local first. Raw health samples never leave your device. The server has no endpoint that accepts them.
- Minimum necessary cloud data. Account, entitlement, encrypted Oura tokens, consents, lightweight report metadata.
- Encryption. TLS in transit; AES-256-GCM for Oura tokens at rest; platform Keychain / Keystore for session tokens on device.
- Signed store payloads. StoreKit 2 transactions and App Store Server Notifications V2 are verified against Apple root certificates; Google purchases are verified with the Play Developer API before entitlement is granted.
- Authentication. Sign in with Apple identity tokens (nonce-checked), Google ID tokens verified server-side, passwordless email codes with attempt limits. No custom password storage.
- OAuth hygiene. Oura authorisation uses a signed, expiring state bound to your account; secrets never ship in the mobile binaries.
- Isolation. Every API route is scoped to the authenticated user. No administrative endpoints are exposed publicly.
- Rate limiting on authentication and public endpoints.
- No advertising or analytics SDKs. Dependencies are reviewed and audited before release.
Reporting a vulnerability
Email support@ringvitals.com with “Security” in the subject. We respond to good-faith reports and will not pursue researchers who follow responsible disclosure.