Provision record
Ro · Ro Privacy Policy · View original document ↗

Unrestricted Use and Disclosure of De-Identified Data

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Ro and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy reserves the right to de-identify any collected information and then use or disclose that de-identified data to any third party, including advertisers and sponsors, for any purpose including marketing and research, with a stated contractual prohibition on re-identification by recipients.

ⓘ

This analysis describes what Ro's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision grants Ro broad discretion to convert user data including sensitive health information into de-identified form and then distribute it to any third party without restriction on purpose. The practical scope of this right depends on the adequacy of the de-identification standard applied, which the document does not specify.

⚠

Interpretive note: The adequacy of the de-identification standard applied is not specified in the document; compliance with HIPAA and state law de-identification requirements cannot be confirmed from the policy text alone.

Recent Activity

This document changed recently

Medium Sep 4, 2026

The updated policy establishes that Ro has enabled contractual settings with certain advertising partners that restrict those partners' use of data to service provision only, meaning those partners may not use the information for their own advertising or profiling purposes. The policy also expands the list of states where Ro does not sell sensitive personal information for tailored advertising, adding New Jersey, New Hampshire, Nebraska, Iowa, and Delaware. For residents of the newly added states and others covered by partner settings, default restrictions on data use may apply even without an explicit opt-out. You can manage advertising preferences through the policy's stated opt-out mechanisms, including the 'Your Privacy Choices' page and Global Privacy Control signals.

View change record →

Consumer impact (what this means for users)

Under these terms, any information collected about you, including health and sensitive data, may be de-identified and then shared with advertisers, sponsors, and research partners for any purpose. The agreement states that Ro will not attempt to re-identify de-identified data and will contractually prohibit third-party recipients from doing so, but does not specify the technical de-identification standard applied.

Cross-platform context

See how other platforms handle Unrestricted Use and Disclosure of De-Identified Data and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device ('Aggregate/De-Identified Information'). We may use Aggregate/De-Identified Information for any purpose, including for research and marketing purposes, and may also disclose such data to any third parties, including advertisers, promotional partners, and sponsors. Once information has been aggregated/de-identified, we have a policy of not attempting to re-identify it, and if we disclose it to third parties, we also contractually prohibit them from attempting to re-identify it.

Excerpt from Ro's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision implicates HIPAA's de-identification standards under 45 CFR 164.514, which require either the Safe Harbor or Expert Determination method for health information.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • Department Of Health & Human Services, Office For Civil Rights (hhs Ocr)
    Enforces HIPAA Privacy and Security Rules, which protect health information held by healthcare providers, health plans, and their business associates.
    Who can file: Anyone whose HIPAA rights may have been violated by a covered entity (healthcare provider, health plan, or healthcare clearinghouse)
    What you need: Name of the entity, description of the violation, date of the incident, and your contact information. Must file within 180 days of the violation.
    What to expect: HHS OCR investigates and may require the entity to take corrective action. Does not provide individual compensation. Serious violations can result in civil monetary penalties.
    File a complaint →

Provision details

Document information
Document
Ro Privacy Policy
Entity
Ro
Document last updated
July 5, 2026
Tracking information
First tracked
July 5, 2026
Last verified
July 9, 2026
Record ID
CA-P-015425
Document ID
CA-D-00905
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
fd8e38702aa47447615a3625653591159b0e77ea6255a1ce4be0d067ec9913a4
Analysis generated
July 5, 2026 02:19 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Ro
Document: Ro Privacy Policy
Record ID: CA-P-015425
Captured: 2026-07-05 02:19:53 UTC
SHA-256: fd8e38702aa47447…
URL: https://conductatlas.com/platform/ro/ro-privacy-policy/provision/CA-P-015425/unrestricted-use-and-disclosure-of-de-identified-data/
Accessed: Oct. 3, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Ro's Unrestricted Use and Disclosure of De-Identified Data clause do?

This provision grants Ro broad discretion to convert user data including sensitive health information into de-identified form and then distribute it to any third party without restriction on purpose. The practical scope of this right depends on the adequacy of the de-identification standard applied, which the document does not specify.

How does this clause affect you?

Under these terms, any information collected about you, including health and sensitive data, may be de-identified and then shared with advertisers, sponsors, and research partners for any purpose. The agreement states that Ro will not attempt to re-identify de-identified data and will contractually prohibit third-party recipients from doing so, but does not specify the technical de-identification standard applied.

Is ConductAtlas affiliated with Ro?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ro.