Privacy Policy — OpenRing
Last updated:
Effective date: July 10, 2026
This Privacy Policy explains how BabyDog Asset Management (“we,” “us,” or “our”) handles information in connection with the OpenRing mobile app for iOS and Android (the “App”). OpenRing lets you view and export your own health and wellness data from your smart ring account. By using the App, you agree to this Policy.
The short version
OpenRing has no servers of its own. We (the developer) never receive, store, or have access to your health data. Your data flows directly between your device and your ring’s cloud service, and is stored only on your device. OpenRing has no account or login of its own. The App is free and shows ads through Google AdMob, which is the only third-party data collection.
1. What data the App handles
Your ring health data
Using your own personal access token, the App retrieves your data directly from your smart ring’s cloud service — a third-party service operated by your ring’s manufacturer — over HTTPS to your device, including:
- Sleep (scores, stages, timing, efficiency) and overnight heart-rate and heart-rate-variability samples
- Readiness scores and contributors, and body-temperature trend
- Activity (steps, calories, distance, activity intensity)
- 24/7 heart rate
- Blood-oxygen (SpO₂) averages
- Basic profile fields from your ring account’s personal-info endpoint — email address, age, weight, height, and biological sex — used to validate your token and to display your account info in the App
This data is fetched directly from your ring’s cloud service to your device. It is not transmitted to us or to any third party. It is stored only on your device and is used solely to display and export your own data.
Your personal access token
The token you paste in is stored in your device’s secure storage (iOS Keychain / Android Keystore-backed encrypted storage). It is used only to authenticate requests to your ring’s cloud service and is never transmitted to us or to any third party.
No app account
OpenRing has no sign-up, login, or user account. It collects no name, password, or contact information for the App itself.
2. Where data is stored, and for how long
- Health data is stored locally in an on-device database; profile info is held in app memory; the token is in your device’s secure store.
- 24/7 heart-rate readings are kept on-device for roughly the most recent 14 days; other data is kept until you disconnect or uninstall.
- Disconnecting in the App deletes the stored token and wipes all imported data from the device. Uninstalling the App removes all local data.
3. Third-party services
Your ring’s cloud service
The source of your health data, operated by your ring’s manufacturer (a third party). You authenticate with your own token, and data flows directly between your device and that service. That company’s handling of your data is governed by its own privacy policy. OpenRing is an independent app and is not affiliated with, endorsed by, or sponsored by your ring’s manufacturer.
Google AdMob (advertising)
The free App shows banner ads through Google AdMob (the Google Mobile Ads SDK). To serve ads, Google may collect and process device identifiers (such as the advertising ID), IP address, and ad-interaction / usage data, and may use it for advertising and measurement. Google acts as an independent controller/processor under its own policies. The App does not share any of your ring health data with Google or use it for ad targeting.
- On iOS, the App uses App Tracking Transparency: personalized ads / tracking occur only if you allow it via the system prompt.
- In the EEA/UK, the App presents Google’s User Messaging Platform (UMP) consent flow; you can change your choice later in the App’s settings.
- See Google’s Privacy Policy and How Google uses information from sites or apps that use our services.
Platform providers (Apple / Google Play)
Standard app distribution and any crash / diagnostic reporting the operating systems may provide.
4. Data sharing and selling
We do not sell your data, and we do not share your health data with anyone. Your health data never leaves your device except for your own direct requests to your ring’s cloud service. The only third-party data collection is by Google AdMob for advertising, as described above.
5. Security
- All network requests use HTTPS / TLS.
- Your token is stored in your device’s secure keychain / keystore — not in plain storage or logs.
- Because your data stays on your device, there is no central database of your health data for anyone to breach.
6. Your choices and rights
- Disconnect in the App to erase the token and all local data at any time.
- Revoke the personal access token from your ring account to cut off access entirely.
- Ad choices: reset or limit your advertising ID in device settings, and change ad-personalization consent in the App (where applicable) or via Google’s controls.
- Depending on your region, you may have rights to access, delete, or restrict processing (GDPR / EEA-UK) or to opt out of “sale” / “sharing” (CCPA / US). Because we hold none of your data, most health-data requests are self-service (disconnect / uninstall); ad-data requests are handled through Google.
7. Children
OpenRing is not directed to children and is intended for adults who own a smart ring. It is rated for a general audience but is not a children’s app.
8. Permissions
- Internet access — to fetch your data from your ring’s cloud service and to load ads.
- No location, contacts, camera, microphone, or device health-sensor permissions are requested (your data comes from your ring’s cloud service, not from device sensors).
9. Changes to this policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and where required we will seek renewed consent.
10. Contact
Questions about this Policy or our data practices: support@babydogam.com. OpenRing is operated by BabyDog Asset Management.