The policy reserves the right to de-identify any collected information and then use or disclose that de-identified data to any third party, including advertisers and sponsors, for any purpose including marketing and research, with a stated contractual prohibition on re-identification by recipients.
This analysis describes what Ro's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision grants Ro broad discretion to convert user data including sensitive health information into de-identified form and then distribute it to any third party without restriction on purpose. The practical scope of this right depends on the adequacy of the de-identification standard applied, which the document does not specify.
Interpretive note: The adequacy of the de-identification standard applied is not specified in the document; compliance with HIPAA and state law de-identification requirements cannot be confirmed from the policy text alone.
The updated policy establishes that Ro has enabled contractual settings with certain advertising partners that restrict those partners' use of data to service provision only, meaning those partners may not use the information for their own advertising or profiling purposes. The policy also expands the list of states where Ro does not sell sensitive personal information for tailored advertising, adding New Jersey, New Hampshire, Nebraska, Iowa, and Delaware. For residents of the newly added states and others covered by partner settings, default restrictions on data use may apply even without an explicit opt-out. You can manage advertising preferences through the policy's stated opt-out mechanisms, including the 'Your Privacy Choices' page and Global Privacy Control signals.
View change record →Under these terms, any information collected about you, including health and sensitive data, may be de-identified and then shared with advertisers, sponsors, and research partners for any purpose. The agreement states that Ro will not attempt to re-identify de-identified data and will contractually prohibit third-party recipients from doing so, but does not specify the technical de-identification standard applied.
Cross-platform context
See how other platforms handle Unrestricted Use and Disclosure of De-Identified Data and similar clauses.
Compare across platforms →"We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device ('Aggregate/De-Identified Information'). We may use Aggregate/De-Identified Information for any purpose, including for research and marketing purposes, and may also disclose such data to any third parties, including advertisers, promotional partners, and sponsors. Once information has been aggregated/de-identified, we have a policy of not attempting to re-identify it, and if we disclose it to third parties, we also contractually prohibit them from attempting to re-identify it.Excerpt from Ro's Privacy Policy
REGULATORY LANDSCAPE: This provision implicates HIPAA's de-identification standards under 45 CFR 164.514, which require either the Safe Harbor or Expert Determination method for health information.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision grants Ro broad discretion to convert user data including sensitive health information into de-identified form and then distribute it to any third party without restriction on purpose. The practical scope of this right depends on the adequacy of the de-identification standard applied, which the document does not specify.
Under these terms, any information collected about you, including health and sensitive data, may be de-identified and then shared with advertisers, sponsors, and research partners for any purpose. The agreement states that Ro will not attempt to re-identify de-identified data and will contractually prohibit third-party recipients from doing so, but does not specify the technical de-identification standard applied.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ro.