The policy states that users have rights to access, rectify, erase, and port their personal data, and to object to or restrict processing, exercisable by emailing privacy@ouraring.com.
This analysis describes what Oura's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational mechanism through which users may exercise GDPR, UK GDPR, and CCPA/CPRA data subject rights, centralizing all requests through a single email address. Compliance teams should verify that response timelines meet applicable statutory deadlines (30 days under GDPR, 45 days under CCPA) and that identity verification procedures do not create unreasonable barriers to access.
The updated policy explicitly discloses that Oura uses artificial intelligence and machine learning in the service, including an AI assistant called Oura Advisor that provides personalized wellness guidance based on information you submit or that Oura collects. The revised terms state that Oura may use AI and algorithmic analysis to suggest partner services and may use personal data to develop or refine AI-powered health features. The policy establishes that you retain choice about whether to engage with these AI features or share personal data with partner services when suggestions are offered.
View change record →This addition provides users with explicit notification of their GDPR and privacy law rights and a direct mechanism to exercise them, replacing the previous version's opposition-to-legal-authority provision.
View full change record →Under this clause, users can submit requests to access, correct, delete, or export their personal data by emailing privacy@ouraring.com. The policy does not specify response timelines in this provision, though applicable law (GDPR, CCPA) imposes statutory deadlines on data subject request responses.
How other platforms handle this
You may contact our privacy team with any requests of disclosure, correction, or deletion of your personal information. You may also request suspension of use or suspension of sharing of your personal information with certain third parties.
If you're otherwise unable to access your Service Data, you can always request it here.
Request Deletion of your information, subject to certain exceptions prescribed by law.
"You have the right to request access to, rectification of, or erasure of your personal data, as well as the right to data portability and the right to object to or restrict our processing. You can exercise these rights by sending a request to privacy@ouraring.com.Excerpt from Oura's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Articles 15-22 (data subject rights), UK GDPR equivalent provisions, and CCPA/CPRA Sections 1798.100-1798.125 (consumer rights to know, delete, correct, and portability).
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the operational mechanism through which users may exercise GDPR, UK GDPR, and CCPA/CPRA data subject rights, centralizing all requests through a single email address. Compliance teams should verify that response timelines meet applicable statutory deadlines (30 days under GDPR, 45 days under CCPA) and that identity verification procedures do not create unreasonable barriers to access.
Under this clause, users can submit requests to access, correct, delete, or export their personal data by emailing privacy@ouraring.com. The policy does not specify response timelines in this provision, though applicable law (GDPR, CCPA) imposes statutory deadlines on data subject request responses.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Oura.