8 Total
2 High severity
5 Medium severity
1 Low severity
Summary

This is Oura's privacy policy, which explains how the company collects and uses the detailed health and biometric data captured by your Oura Ring, including sleep stages, heart rate, body temperature, reproductive health signals, and location. The most important thing to understand is that if you connect your Oura data to the Oura Platform and share it with an employer, coach, doctor, or researcher, that third party becomes the independent controller of your sensitive health data and Oura takes no responsibility for what they do with it. Before accepting any Oura Platform invitation from an employer or organization, carefully review that organization's own privacy policy, as your biometric and health data will fall outside Oura's protections once shared.

Technical / Legal Breakdown

This policy governs the collection, processing, and sharing of personal data by Oura Health Oy and Ouraring Inc. in connection with the Oura Ring, Oura App, Oura on the Web, and related services, with stated legal bases including contract, consent, legitimate interest, and legal obligation under GDPR and equivalent frameworks. The agreement states that Oura processes a broad range of sensitive health data including heart rate, temperature, respiration, sleep phases, reproductive health indicators, and location data, and that users who join the Oura Platform consent to sharing this data with third-party Data Recipients who then become independent data controllers responsible for their own processing. A notable provision establishes that once data is shared to the Oura Platform, Oura explicitly disclaims responsibility for the Data Recipient's processing or security of that data, which creates a meaningful accountability gap for users who share highly sensitive biometric and health data with employers, coaches, or researchers. The policy engages GDPR and UK GDPR for EEA and UK residents, CCPA and CPRA for California residents, and the policy's handling of biometric and health data may require evaluation under HIPAA in contexts where Oura services are used within covered entity or business associate relationships, though Oura does not assert HIPAA applicability. State-level biometric privacy laws including Illinois BIPA and Washington My Health MY Data Act may also be implicated depending on the nature of data collected and user location, creating jurisdictionally variable compliance exposure.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 2 provisions
Medium — 5 provisions
Low — 1 provision

Monitoring

Oura has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Cross-Border Data Transfers and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
HIPAA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:44 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000738
Version ID CA-V-001362
SHA-256 e0f258c6a5dda2714027d817b631e329268e9af241161a05b7d8f5039349cd86
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans