Privacy Policy
Last updated: September 7, 2026
1. Introduction
This Privacy Policy describes how Ring Widget ("we", "our", or "the App") collects, uses, and protects your information when you use our application and website (ringwidget.app).
2. Data Controller
The data controller responsible for your personal data is:
Bc. Aliaksandr Drankou
Nové sady 988/2
602 00 Brno - Staré Brno
Czech Republic
IČO: 11813652
3. Information We Collect
App
We do not collect your health data. Your Oura health data goes directly from Oura to your device, where it is processed and stored locally. Your health metrics do not pass through or get stored on our servers. We collect limited pseudonymous product and subscription analytics, described below, but do not send health information to PostHog or RevenueCat.
The App accesses the following data locally:
- Oura API Data: Sleep scores, activity scores, readiness scores, and related health metrics retrieved directly from Oura's servers to your device
- Authentication Tokens: Authorization tokens are stored in your device’s Keychain. Our server temporarily handles tokens during sign-in and refresh, but does not store them or use them to retrieve your health data.
- Purchase Information: Your subscription status is used to unlock premium features. Purchase transactions and subscription status are handled by Apple and RevenueCat — we do not receive payment card numbers or billing addresses
The App uses PostHog for basic product analytics to help us improve the app. Automatic screen, lifecycle, and session-replay tracking is disabled. We collect only the following allow-listed data:
- Pseudonymous identifier: The random app user ID generated by RevenueCat. We use the same identifier in PostHog so subscription status can be compared with product usage. We do not attach your name, email address, or Oura account ID
- Widget activity: Widget type and a coarse result such as successful, no data, premium locked, authentication required, or failed. Activity is limited to one event per widget type per UTC day on each device
- Widget interactions and health: Widget type and size, the action taken (for example open, unlock, or reconnect), and coarse issue codes such as network or decoding
- Subscription flow: Paywall views, offering availability, premium-access source, package category, and purchase or restore outcome
- Technical context: App version, build number, platform, TestFlight status, and analytics schema or subscription-flow version
We do not send Oura scores or measurements, raw error messages, API responses, URLs, authentication tokens, purchase transaction IDs, names, or email addresses to PostHog. The App communicates directly with Oura's API from your device. We also remove device model, locale, screen-size, and network-type properties from App analytics events and instruct PostHog not to derive geolocation from the connection IP address.
Website
Our website uses PostHog for anonymous analytics to understand how visitors interact with the site and to improve our content. By default, we use cookieless tracking which does not set any cookies or store any data on your device. This anonymous tracking does not identify you personally.
If you accept analytics cookies via our cookie banner, PostHog may store a cookie to provide enhanced analytics. You can change your preferences at any time using the "Cookie Settings" link in our website footer.
4. How We Use Your Information
Your data is used exclusively to:
- Display your Oura Ring data in widgets
- Refresh and update widget content
- Improve the app by understanding which widgets are used and diagnosing errors
- Understand whether subscription, purchase, and restore flows work as intended
- Improve our website through anonymous usage analytics (with your consent)
We process the App's limited pseudonymous analytics based on our legitimate interest in maintaining and improving Ring Widget. Optional website analytics cookies are processed based on your consent. You may object to App analytics or withdraw website consent by contacting us or using the website's Cookie Settings.
6. Data Storage and Security
- Your Oura data is stored locally on your device only
- Authentication tokens are stored securely in iOS Keychain
- We do not store your health data on external servers
- Limited pseudonymous analytics and subscription data is processed by PostHog and RevenueCat on our behalf
- Cached Oura data is automatically refreshed and not retained longer than 60 days, in compliance with Oura API requirements
- Analytics and subscription records are retained only as long as needed for the purposes described in this policy and applicable legal obligations
7. Third-Party Services
The App connects to Oura's API to retrieve your health data. Your use of Oura services is subject to Oura's Privacy Policy, Terms of Service, and API Agreement.
Oura may collect certain usage data related to API interactions for business purposes and platform improvements. Our use of the Oura API complies with the Oura API Agreement requirements.
The App uses RevenueCat to process in-app purchases and manage subscription status. RevenueCat receives your pseudonymous app user ID and purchase receipts from Apple. No personal data such as your name or email is shared with RevenueCat.
Both the app and website use PostHog for analytics. PostHog processes data on US-based servers. In the app, PostHog receives the limited pseudonymous data listed above, including the same random app user ID used by RevenueCat. This is an international transfer from the European Economic Area. We rely on our service providers' contractual and technical safeguards for these transfers. On the website, when cookieless mode is active, PostHog uses a server-side hash to anonymize visitors without storing any data on your device.
8. Data Usage Restrictions
We do not sell, license, or share your Oura data with advertisers, data brokers, or any third parties. Your health data is used solely for displaying information in the App's widgets.
9. Your Rights
Under GDPR and Czech data protection law, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Withdraw consent at any time
- Object to processing based on legitimate interests
- Lodge a complaint with the Czech Data Protection Authority
10. Data Deletion
Disconnecting Oura or uninstalling the App removes locally stored tokens and cached Oura data, but does not automatically erase historical records held by PostHog or RevenueCat. You can manage local data by:
- Disconnecting your Oura account in the app
- Uninstalling the application
- Revoking access in your Oura account settings
- Clearing cookies in your browser (for website analytics data)
To request access to or deletion of pseudonymous analytics and subscription records, email support@ringwidget.app. We may ask for the RevenueCat app user ID or other information needed to locate the correct records.
11. Children’s Privacy
The App is not intended for children under 16. We do not knowingly offer the App to or collect data from children under 16.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
13. Contact
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at support@ringwidget.app.
Ring Widget is not affiliated with or endorsed by Oura Health Oy.